7.5

CVSS3.1

CVE-2024-8524 - Directory Traversal in modelscope/agentscope

A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted POST request to the /read-examples endpoint.

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

9.1

CVSS3.0

CVE-2024-5752 - Path Traversal in stitionai/devika

A path traversal vulnerability exists in stitionai/devika, specifically in the project creation functionality. In the affected version beacf6edaa205a5a5370525407a6db45137873b3, the project name is not validated, allowing an attacker to create a project with a crafted name that traverses directories…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-8736 - Denial of Service (DoS) via Multipart Boundary in parisneo/lollms-webui

A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). The vulnerability can be exploited remotely via Cross-Site Request Forgery (CSRF). Despite CSRF protection preventing file uploads, the application still processes mul…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 4, 2025, 9:15 a.m.

7.5

CVSS3.0

CVE-2024-12070 - Denial of Service in haotian-liu/llava

A Denial of Service (DoS) vulnerability exists in the file upload feature of haotian-liu/llava, specifically in Release v1.2.0 (LLaVA-1.6). The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large fil…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: July 14, 2025, 5:45 p.m.

9.8

CVSS3.1

CVE-2024-8958 - Unrestricted File Write and Read in composiohq/composio

In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially leading to privilege escalation or remote code execution.

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 1, 2025, 8:30 p.m.

9.0

CVSS3.1

CVE-2024-7053 - Session Fixation in open-webui/open-webui

A vulnerability in open-webui/open-webui version 0.3.8 allows an attacker with a user-level account to perform a session fixation attack. The session cookie for all users is set with the default `SameSite=Lax` and does not have the `Secure` flag enabled, allowing the session cookie to be sent over …

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 1, 2025, 8:33 p.m.

7.5

CVSS3.1

CVE-2024-11030 - SSRF in binary-husky/gpt_academic

GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plugin function, which calls the crazy_utils.get_files_from_everything() API without proper sanitization. This allows attackers to exploit the vulnerability to abuse the victim GPT Ac…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: July 14, 2025, 4:40 p.m.

7.5

CVSS3.1

CVE-2024-12720 - Regular Expression Denial of Service (ReDoS) in huggingface/transformers

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file tokenization_nougat_fast.py. The vulnerability occurs in the post_process_single() function, where a regular expression processes specially crafted input. Th…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 9:11 p.m.

5.9

CVSS3.0

CVE-2024-12777 - Denial of Service in aimhubio/aim

A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is single-threaded, can be made unresponsive by requesting it to connect to an unresponsive socket via sshfs. The lack of an additional timeout setting in…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: July 18, 2025, 8:01 p.m.

9.1

CVSS3.1

CVE-2024-4990 - Unsafe Reflection in base Component class in yiisoft/yii2

In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that the value passed is a valid Behavior class name or configuration. This allows an attacker to instantiate arbitrary classes, passing parameters to their construct…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 1, 2025, 8:34 p.m.
Total resulsts: 349182
Page 6268 of 34,919
Β« previous page Β» next page
Filters