7.5

CVSS3.0

CVE-2024-12063 - Denial of Service in imartinez/privategpt

A Denial of Service (DoS) vulnerability exists in the file upload feature of imartinez/privategpt version v0.6.2. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this by sending a payload with an excessively large …

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: July 17, 2025, 4:02 p.m.

7.5

CVSS3.0

CVE-2024-10549 - Denial of Service by ReDOS in h2oai/h2o-3

A vulnerability in the `/3/Parse` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint uses a user-specified string to construct a regular expression, which is then applied to another user-specified string. By sending multiple simultaneous requests, an …

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.2

CVSS3.0

CVE-2024-8248 - Path Traversal in mintplex-labs/anything-llm

A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversal, leading to arbitrary file read and write in the storage directory. This can result in privilege escalation from manager to admin. The issue is fixed in version 1.2.2.

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: July 15, 2025, 3:16 p.m.

7.5

CVSS3.1

CVE-2024-12866 - Local File Inclusion in netease-youdao/qanything

A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an attacker to read arbitrary files on the file system, which can lead to remote code execution by retrieving private SSH keys, reading private files, source code, and configuration fil…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 1:14 a.m.

9

CVSS3.0

CVE-2024-8017 - Cross-site Scripting (XSS) in open-webui/open-webui

An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the HTML for tooltips. This vulnerability allows attackers to perform operations with the victim's privileges, such as stealing chat history, deleting chats, and escalating their own…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: July 21, 2025, 8:08 p.m.

5.9

CVSS3.0

CVE-2025-0508 - MD5 Hash Collision in SageMaker Workflow in aws/sagemaker-python-sdk

A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from different configurations that produce the same MD5 hash. This i…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-0454 - SSRF Check Bypass in Requests Utility in significant-gravitas/autogpt

A Server-Side Request Forgery (SSRF) vulnerability was identified in the Requests utility of significant-gravitas/autogpt versions prior to v0.4.0. The vulnerability arises due to a hostname confusion between the `urlparse` function from the `urllib.parse` library and the `requests` library. A mali…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 5:04 p.m.

6.1

CVSS3.1

CVE-2024-8101 - Stored XSS in aimhubio/aim

A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. The vulnerability arises due to the use of `dangerouslySetInnerHTML` without proper sanitization, allowing arbitrary JavaScript execution when rendering tracked texts. This can be…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 1, 2025, 8:32 p.m.

7.5

CVSS3.0

CVE-2024-10650 - Denial of Service (DoS) in gaizhenbiao/chuanhuchatgpt

An unauthenticated Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT version 20240918, which could be exploited by sending large data payloads using a multipart boundary. Although a patch was applied for CVE-2024-7807, the issue can still be exploited by sending data in groups …

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.1

CVE-2024-12779 - SSRF in infiniflow/ragflow

A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. The vulnerability is present in the `POST /v1/llm/add_llm` and `POST /v1/conversation/tts` endpoints. Attackers can specify an arbitrary URL as the `api_base` when adding an `OPENAITTS` model, and subseq…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 1, 2025, 8:34 p.m.
Total resulsts: 349182
Page 6266 of 34,919
Β« previous page Β» next page
Filters