7.5

CVSS3.1

CVE-2024-6866 - Case-Insensitive Path Matching in corydolphin/flask-cors

corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to the use of the `try_match` function, which is originally intended for matching hosts. This results in a mismatch because paths in URLs are case-sensitive, but the regex matching t…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

7.5

CVSS3.1

CVE-2024-8952 - SSRF in composiohq/composio

A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCRAPE_WEBSITE_CONTENT endpoint. This vulnerability allows an attacker to read files, access AWS metadata, and interact with local services on the system.

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 1, 2025, 8:30 p.m.

9.1

CVSS3.1

CVE-2024-7776 - Arbitrary File Overwrite in onnx/onnx

A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability can be exploited by an attacker to overwrite files …

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: March 26, 2025, 5:20 p.m.

6.1

CVSS3.1

CVE-2024-10727 - Cross-Site Scripting (XSS) in phpipam/phpipam

A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnerability arises when the application receives data in an HTTP request and includes that data within the immediate response in an unsafe manner. This allows an attacker to execute ar…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 1, 2025, 8:35 p.m.

9.8

CVSS3.1

CVE-2024-8898 - Path Traversal in parisneo/lollms-webui

A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete directories with arbitrary paths on the system. The issue arises due to insufficient sanitization of user-s…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 1, 2025, 8:30 p.m.

7.5

CVSS3.0

CVE-2024-10569 - Zip Bomb Vulnerability in gradio-app/gradio

A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which can accept compressed files. An attacker can exploit this by uploading a maliciously crafted zip bomb, leading to a serve…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 7, 2025, 8:58 p.m.

0.0

CVE-2024-12759 -

** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-8966. Notes: All CVE users should reference CVE-2024-8966 instead of this CVE Record. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 15, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2024-8953 - Unsafe eval usage in composiohq/composio

In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted input is passed to the eval() function.

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 1, 2025, 8:30 p.m.

7.5

CVSS3.1

CVE-2024-8063 - Divide by Zero in ollama/ollama

A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a denial of service (DoS) condition when the server processes the model, causing it to crash.

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: May 13, 2025, 1:28 p.m.

5.4

CVSS3.1

CVE-2024-11850 - Stored XSS in langgenius/dify

A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is due to improper validation and sanitization of user input in SVG markdown support within the chatbot feature. An attacker can exploit this vulnerability by injecting malicious SVG…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: July 15, 2025, 4 p.m.
Total resulsts: 349182
Page 6272 of 34,919
Β« previous page Β» next page
Filters