4.8

CVSS3.1

CVE-2024-0640 - Stored XSS in chatwoot/chatwoot

A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerability allows an admin user to inject malicious JavaScript code via the dashboard app settings, which can then be executed by another admin user when they access the affected dashboard…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 28, 2025, 6:15 p.m.

5.3

CVSS3.0

CVE-2024-6844 - Inconsistent CORS Matching Due to Handling of '+' in URL Path in corydolphin/flask-cors

A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inconsistent CORS matching due to the handling of the '+' character in URL paths. The request.path is passed through the unquote_plus function, which converts the '+' character to a space ' '. This behavior leads to incorrect path n…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

9.1

CVSS3.0

CVE-2024-6829 - Arbitrary File Overwrite through tarfile-extraction in aimhubio/aim

A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extract the contents of a maliciously crafted tarfile to arbitrary locations on the host server. The attacker can control `repo.path` and `run_hash` to bypass directory existence chec…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: July 23, 2025, 8:57 p.m.

7.5

CVSS3.1

CVE-2025-1451 - Insufficient Patch Leading to DoS in parisneo/lollms-webui

A vulnerability in parisneo/lollms-webui v13 arises from the server's handling of multipart boundaries in file uploads. The server does not limit or validate the length of the boundary or the characters appended to it, allowing an attacker to craft requests with excessively long boundaries, leading…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:16 p.m.

7.2

CVSS3.1

CVE-2024-7034 - Remote Code Execution due to Arbitrary File Write in open-webui/open-webui

In open-webui version 0.3.8, the endpoint `/models/upload` is vulnerable to arbitrary file write due to improper handling of user-supplied filenames. The vulnerability arises from the usage of `file_path = f"{UPLOAD_DIR}/{file.filename}"` without proper input validation or sanitization. An attacker…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: July 29, 2025, 6:06 p.m.

7.5

CVSS3.0

CVE-2024-7768 - Denial of Service in h2oai/h2o-3

A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of service. The endpoint takes a single GET parameter, `path`, which can be recursively set to reference itself. This leads the server to repeatedly call its own endpoint, eventually …

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.0

CVE-2024-10188 - Denial of Service in BerriAI/litellm

A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of ast.literal_eval to parse user input. This function is not safe and is prone to DoS attacks, which can crash the litellm Python server.

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: March 20, 2025, 6:16 p.m.

7.5

CVSS3.0

CVE-2024-12864 - Unauthenticated DoS by Sending Large Filename at File Upload Endpoint in netease-youdao/qanything

A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2.0.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this vulnerability by sending a large fi…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 10:51 a.m.

4.3

CVSS3.0

CVE-2024-8057 - Improper Access Control in danswer-ai/danswer

In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them to an existing connector. This issue arises because the system allows an unauthenticated attacker to sign up with a basic account and perform actions that should be restricted to a…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

8.8

CVSS3.0

CVE-2024-10954 - Prompt Injection Leading to RCE in binary-husky/gpt_academic Plugin `manim`

In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper handling of user-provided prompts. The root cause is the execution of untrusted code generated by the LLM without a proper sandbox. This allows an attacker to perform remote code ex…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.
Total resulsts: 343194
Page 5675 of 34,320
Β« previous page Β» next page
Filters