8.8

CVSS3.0

CVE-2024-12048 - IDOR Vulnerability in transformeroptimus/superagi

An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly check authorization for multiple API endpoints, allowing attackers to view, edit, and delete other users' information without proper authorization. Affec…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: July 18, 2025, 7:58 p.m.

9.8

CVSS3.1

CVE-2024-8487 - CORS Vulnerability in modelscope/agentscope

A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing any external domain to make requests to the API. This can lead to unauthorized dat…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 1, 2025, 8:32 p.m.

9.1

CVSS3.1

CVE-2024-8769 - Arbitrary File Deletion via Relative Path Traversal in aimhubio/aim

A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path traversal. The `run_hash` parameter, which is user-controllable, is concatenated without normalization as part of a path used to specify file deletio…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

6.1

CVSS3.1

CVE-2024-8556 - Stored XSS in modelscope/agentscope

A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for inspecting detailed run information, where a user-controllable string (run ID) is appended and rendered as HTML. This allow…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 1, 2025, 8:31 p.m.

6.5

CVSS3.0

CVE-2024-12387 - Improper Input Validation in binary-husky/gpt_academic

A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the server by uploading a specially crafted zip bomb. The server decompresses the uploaded file and attempts to load it into memory, which can lead to an out-of-memory crash. This issu…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.0

CVE-2024-12766 - SSRF in parisneo/lollms-webui

parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST /api/proxy` REST API. Attackers can exploit this vulnerability to abuse the victim server's credentials to access unauthorized web resources by specifying the JSON parameter `{"u…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: July 8, 2025, 4:24 p.m.

8.1

CVSS3.1

CVE-2024-7767 - Improper Access Control in danswer-ai/danswer

An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system to view, modify, and delete chats created by an Admin. This can lead to unauthorized access to sensitive information, loss of data integrity, and pot…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

4.3

CVSS3.1

CVE-2024-12869 - Improper Authentication in infiniflow/ragflow

In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a privacy breach where users' personal or private information, such as email addresses or usernames in the invite list, could be exposed w…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

6.5

CVSS3.1

CVE-2024-11300 - Improper Access Control in lunary-ai/lunary

In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The vulnerability allows unauthorized users to view sensitive prompt data by accessing specific URLs, …

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

8.2

CVSS3.0

CVE-2024-10830 - Path Traversal in eosphoros-ai/db-gpt

A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/delete`. This vulnerability allows an attacker to delete any file on the server by manipulating the `file_key` parameter. The `file_key` parameter is not properly sanitized, enablin…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: July 17, 2025, 1:37 p.m.
Total resulsts: 349182
Page 6267 of 34,919
Β« previous page Β» next page
Filters