6.1

CVSS3.0

CVE-2024-8027 - Stored Cross-Site Scripting (XSS) in netease-youdao/QAnything

A stored Cross-Site Scripting (XSS) vulnerability exists in netease-youdao/QAnything. Attackers can upload malicious knowledge files to the knowledge base, which can trigger XSS attacks during user chats. This vulnerability affects all versions prior to the fix.

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 1:46 a.m.

6.5

CVSS3.0

CVE-2024-6863 - Encryption of Arbitrary Files with Attacker-Controlled Key in h2oai/h2o-3

In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on the target server with a key of their choosing. The chosen key can also be overwritten, resulting in ransomware-like behavior. This vulnerability makes it possible for an attacker …

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 12:50 p.m.

5.4

CVSS3.1

CVE-2024-10722 - Stored Cross-site Scripting (XSS) in phpipam/phpipam

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows attackers to inject malicious scripts into the 'Description' field of custom fields in the 'IP RELATED MANAGEMENT' section. This can lead to data theft, account compromise, distributi…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: May 28, 2025, 8:35 p.m.

7.5

CVSS3.0

CVE-2024-12376 - Server Side Request Forgery in lm-sys/fastchat

A Server-Side Request Forgery (SSRF) vulnerability was identified in the lm-sys/fastchat web server, specifically in the affected version git 2c68a13. This vulnerability allows an attacker to access internal server resources and data that are otherwise inaccessible, such as AWS metadata credentials.

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: July 31, 2025, 2:37 p.m.

6.5

CVSS3.0

CVE-2024-10330 - Improper Access Control in lunary-ai/lunary

In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associated with a project to fetch all evaluator data regardless of their role. This vulnerability permits low-privilege users to access potentially sensitive evaluation data.

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.0

CVE-2024-8789 - Regular Expression Denial of Service (ReDoS) in lunary-ai/lunary

Lunary-ai/lunary version git 105a3f6 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. The application allows users to upload their own regular expressions, which are then executed on the server side. Certain regular expressions can have exponential runtime complexity relative…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.0

CVE-2024-12886 - Out-Of-Memory (OOM) Vulnerability in ollama/ollama

An Out-Of-Memory (OOM) vulnerability exists in the `ollama` server version 0.3.14. This vulnerability can be triggered when a malicious API server responds with a gzip bomb HTTP response, leading to the `ollama` server crashing. The vulnerability is present in the `makeRequestWithRetry` and `getAut…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.0

CVE-2024-6842 - Exposure of Sensitive Information in mintplex-labs/anything-llm

In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive information such as API keys for search engines, which can be exploited by attacke…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

8.8

CVSS3.1

CVE-2024-10819 - CSRF to XSS in binary-husky/gpt_academic

A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to trick a user into uploading files without their consent, exploiting their session. This can lead to unauthorized file uploads and potential system compromise. The uploaded file can c…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 12:50 p.m.

6.5

CVSS3.0

CVE-2024-9617 - IDOR in danswer-ai/danswer

An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the GET /api/chat/file/{file_id} interface to view any user's file.

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6278 of 34,919
Β« previous page Β» next page
Filters