7.5

CVSS3.0

CVE-2024-10188 - Denial of Service in BerriAI/litellm

A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of ast.literal_eval to parse user input. This function is not safe and is prone to DoS attacks, which can crash the litellm Python server.

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: March 20, 2025, 6:16 p.m.

7.5

CVSS3.0

CVE-2024-12864 - Unauthenticated DoS by Sending Large Filename at File Upload Endpoint in netease-youdao/qanything

A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2.0.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this vulnerability by sending a large fi…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 10:51 a.m.

4.3

CVSS3.0

CVE-2024-8057 - Improper Access Control in danswer-ai/danswer

In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them to an existing connector. This issue arises because the system allows an unauthenticated attacker to sign up with a basic account and perform actions that should be restricted to a…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

8.8

CVSS3.0

CVE-2024-10954 - Prompt Injection Leading to RCE in binary-husky/gpt_academic Plugin `manim`

In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper handling of user-provided prompts. The root cause is the execution of untrusted code generated by the LLM without a proper sandbox. This allows an attacker to perform remote code ex…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

9.8

CVSS3.0

CVE-2024-11958 - SQL Injection in run-llama/llama_index

A SQL injection vulnerability exists in the `duckdb_retriever` component of the run-llama/llama_index repository, specifically in the latest version. The vulnerability arises from the construction of SQL queries without using prepared statements, allowing an attacker to inject arbitrary SQL code. T…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: July 29, 2025, 6:57 p.m.

6.5

CVSS3.0

CVE-2025-0191 - Denial of Service in gaizhenbiao/chuanhuchatgpt

A Denial of Service (DoS) vulnerability exists in the file upload feature of gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server …

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: July 9, 2025, 6:01 p.m.

8.1

CVSS3.0

CVE-2025-0628 - Improper Authorization in BerriAI/litellm

An improper authorization vulnerability exists in the main-latest version of BerriAI/litellm. When a user with the role 'internal_user_viewer' logs into the application, they are provided with an overly privileged API key. This key can be used to access all the admin functionality of the applicatio…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:16 p.m.

5.4

CVSS3.0

CVE-2024-12870 - Stored Cross-site Scripting (XSS) in infiniflow/ragflow

A stored cross-site scripting (XSS) vulnerability exists in infiniflow/ragflow, affecting the latest commit on the main branch (cec2080). The vulnerability allows an attacker to upload HTML/XML files that can host arbitrary JavaScript payloads. These files are served with the 'application/xml' cont…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: July 13, 2025, 9:07 p.m.

5.4

CVSS3.1

CVE-2025-0281 - Stored Cross-Site Scripting (XSS) in lunary-ai/lunary

A stored cross-site scripting (XSS) vulnerability exists in lunary-ai/lunary versions 1.6.7 and earlier. An attacker can inject malicious JavaScript into the SAML IdP XML metadata, which is used to generate the SAML login redirect URL. This URL is then set as the value of `window.location.href` wit…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: March 28, 2025, 2:22 p.m.

4.6

CVSS3.0

CVE-2024-10359 - Mass Assignment in Preset Creation Allows User ID Manipulation in danny-avila/librechat

In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user can manipulate the user ID field through mass assignment. This allows an attacker to inject a different user ID into the preset object, causing the preset to appear in the UI of ano…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: July 11, 2025, 8:32 p.m.
Total resulsts: 343168
Page 5673 of 34,317
Β« previous page Β» next page
Filters