9.8

CVSS3.0

CVE-2024-9070 - Deserialization Vulnerability in BentoML's Runner Server in bentoml/bentoml

A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting specific parameters, an attacker can execute unauthorized arbitrary code on the server, causing severe harm. The vulnerability is triggered when the args-number parameter is great…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.0

CVE-2024-6841 - CSRF in vanna-ai/vanna

A Cross-Site Request Forgery (CSRF) vulnerability exists in the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502) of the vanna-ai/vanna repository. Two endpoints in the built-in web app that provide SQL functionality are implemented as simple GET requests, making them susceptible to CSRF att…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.0

CVE-2024-10907 - Denial of Service (DoS) via Multipart Boundary in lm-sys/fastchat

In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary. Each extra character is processed in an infinite …

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

6.5

CVSS3.0

CVE-2024-9159 - Incorrect Authorization in gaizhenbiao/chuanhuchatgpt

An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the server at will, leading to a complete loss of availability. The issue arises because the function responsible for restarting the server is not properly…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 6:19 p.m.

5.4

CVSS3.1

CVE-2024-9107 - Stored XSS in gaizhenbiao/chuanhuchatgpt

A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version git 20b2e02. The vulnerability arises from improper sanitization of HTML tags in chat history uploads. Specifically, the sanitization logic fails to handle HTML tags within code …

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 6:25 p.m.

9.6

CVSS3.0

CVE-2024-11045 - Cross-Site WebSocket Hijacking (CSWSH) in automatic1111/stable-diffusion-webui

A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability arises from the lack of proper validation on WebSocket connections at ws://127.0.0.1:786…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 4:26 p.m.

7.5

CVSS3.0

CVE-2024-9056 - Denial of Service in bentoml/bentoml

BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. This causes the server to continuously process each character, leading to excessive r…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.0

CVE-2024-10550 - Denial of Service by ReDOS in h2oai/h2o-3

A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a user-specified regular expression to a user-controllable string. This can be exploited by an attacker to cause inefficient regular expression complexit…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: July 14, 2025, 1:49 p.m.

6.5

CVSS3.0

CVE-2024-9447 - Exposure of Sensitive Information in transformeroptimus/superagi

An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisation/` endpoint does not verify the user's organization, allowing any authenticated user to retrieve sensitive configuration details, including API keys, of any organization. This …

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: July 29, 2025, 7:04 p.m.

7.5

CVSS3.0

CVE-2024-12778 - Denial of Service in aimhubio/aim

A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a large number of tracked metrics are retrieved simultaneously from the Aim web API, causing the web server to become unresponsive. The root cause is the lack of a limit on the number o…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.
Total resulsts: 349182
Page 6281 of 34,919
Β« previous page Β» next page
Filters