7.5

CVSS3.0

CVE-2024-11043 - Denial of Service (DoS) via Large Payload in Board Name Field in invoke-ai/invokeai

A Denial of Service (DoS) vulnerability was discovered in the /api/v1/boards/{board_id} endpoint of invoke-ai/invokeai version v5.0.2. This vulnerability occurs when an excessively large payload is sent in the board_name field during a PATCH request. By sending a large payload, the UI becomes unres…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2024-8053 - Improper Authentication in open-webui/open-webui

In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This vulnerability can be exploited by sending a POST request with an excessively large payload, potentially leading…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: March 27, 2025, 11:15 a.m.

6.1

CVSS3.1

CVE-2024-8021 - Open Redirect in gradio-app/gradio

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect to an attacker-cont…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: March 26, 2025, 4:39 p.m.

0.0

CVE-2025-0655 -

** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-55890. Notes: All CVE users should reference CVE-2024-55890 instead of this CVE Record. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 15, 2025, 4:15 p.m.

5.4

CVSS3.1

CVE-2024-8400 - Stored XSS in gaizhenbiao/chuanhuchatgpt

A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability allows an attacker to upload a malicious HTML file containing JavaScript code, which is then executed when the file is accessed. This can lead to the execution of arbitrar…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 1, 2025, 8:32 p.m.

8.2

CVSS3.0

CVE-2024-10648 - Path Traversal in gradio-app/gradio

A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an attacker to control the format of the audio file, leading to arbitrary file content deletion. By manipulating the output format, an attacker can reset an…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 6:52 p.m.

7.5

CVSS3.0

CVE-2025-0313 - ollama: Improper Validation of Array Index in ollama/ollama

** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-12055. Notes: All CVE users should reference CVE-2024-12055 instead of this CVE Record. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 15, 2025, 4:15 p.m.

7.6

CVSS3.0

CVE-2024-8183 - CORS Misconfiguration in prefecthq/prefect

A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains to access sensitive data. This vulnerability can lead to unauthorized access to the database, resulting in potential data leaks, loss of confidentiality, service disruption, and d…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.0

CVE-2024-12074 - Denial of Service in automatic1111/stable-diffusion-webui

A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webui version 1.10.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filen…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 4:21 p.m.

8.1

CVSS3.1

CVE-2024-8238 - Unrestricted Code Execution in aimhubio/aim

In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function from RestrictedPython. This version does not protect against the str.format_map() method, allowing an attacker to leak server-side secrets or potentially gain unrestricted code execu…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.
Total resulsts: 349182
Page 6269 of 34,919
Β« previous page Β» next page
Filters