6.2

CVSS3.0

CVE-2024-8982 - Local File Inclusion in bentoml/openllm

A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local server through the web application. This flaw could expose internal server files and potentially sensitive information such as configuration files, passwords, and other critical dat…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.0

CVE-2025-0183 - Stored XSS in binary-husky/gpt_academic

A stored cross-site scripting (XSS) vulnerability exists in the Latex Proof-Reading Module of binary-husky/gpt_academic version 3.9.0. This vulnerability allows an attacker to inject malicious scripts into the `debug_log.html` file generated by the module. When an admin visits this debug report, th…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 1:53 a.m.

6.1

CVSS3.1

CVE-2024-9311 - Cross-Site Request Forgery to XSS in haotian-liu/llava

A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload files with malicious content without authentication or user interaction. The uploaded file is stored in a predictable path, enabling the attacker to execute arbitrary JavaScript co…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 12:50 p.m.

8.9

CVSS3.1

CVE-2024-7044 - Stored XSS in open-webui/open-webui

A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui version 0.3.8. An attacker can inject malicious content into a file, which, when accessed by a victim through a URL or shared chat, executes JavaScript in the victim's browser. Th…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: July 29, 2025, 6:05 p.m.

4.3

CVSS3.0

CVE-2024-6583 - Path Traversal in stangirard/quivr

A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker to upload files to arbitrary paths in an S3 bucket by manipulating the file path in the upload request.

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: July 15, 2025, 3:55 p.m.

0.0

CVE-2024-12868 -

** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-47874. Notes: All CVE users should reference CVE-2024-47874 instead of this CVE Record. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 15, 2025, 4:15 p.m.

5.4

CVSS3.0

CVE-2025-0192 - Stored Cross-site Scripting (XSS) in wandb/openui

A stored Cross-site Scripting (XSS) vulnerability exists in the latest version of wandb/openui. The vulnerability is present in the edit HTML functionality, where an attacker can inject malicious scripts. When the modified HTML is shared with another user, the XSS payload executes, potentially lead…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.0

CVE-2024-7957 - Arbitrary File Overwrite in danswer-ai/danswer

An arbitrary file overwrite vulnerability exists in the ZulipConnector of danswer-ai/danswer, affecting the latest version. The vulnerability arises from the load_credentials method, where user-controlled input for realm_name and zuliprc_content is used to construct file paths and write file conten…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-8551 - Path Traversal in modelscope/agentscope

A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacker to read and write arbitrary JSON files on the filesystem, potentially leading to the exposure or modification of sensi…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 12:50 p.m.

5.5

CVSS3.1

CVE-2025-1474 - Weak Password Requirements in mlflow/mlflow

In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: March 27, 2025, 3:36 p.m.
Total resulsts: 349182
Page 6279 of 34,919
Β« previous page Β» next page
Filters