8.1

CVSS3.0

CVE-2024-8065 - CSRF in danswer-ai/danswer

A Cross-Site Request Forgery (CSRF) vulnerability in version v1.4.1 of danswer-ai/danswer allows attackers to perform unauthorized actions in the context of the victim's browser. This includes connecting the victim's application with a malicious Slack Bot, inviting users, and deleting chats, among …

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-10264 - HTTP Request Smuggling in netease-youdao/qanything

HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistencies in the interpretation of HTTP requests between a proxy and a server. This can lead to unauthorized access, bypassing security controls, session hijacking, data leakage, and pot…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 10:51 a.m.

6.9

CVSS3.0

CVE-2024-7035 - Cross-Site Request Forgery (CSRF) in open-webui/open-webui

In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability allows an attacker to perform Cross-Site Request Forgery (CSRF) attacks, where an unaware user can unintentionally perform sensitive actions by simply …

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: July 29, 2025, 6:06 p.m.

9.8

CVSS3.0

CVE-2024-12044 - Remote Code Execution by Pickle Deserialization in open-mmlab/mmdetection

A remote code execution vulnerability exists in open-mmlab/mmdetection version v3.3.0. The vulnerability is due to the use of the `pickle.loads()` function in the `all_reduce_dict()` distributed training API without proper sanitization. This allows an attacker to execute arbitrary code by broadcast…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.0

CVE-2024-12375 - Local File Inclusion in automatic1111/stable-diffusion-webui

A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a973c. This vulnerability allows an attacker to read arbitrary files on the system by sending a specially crafted request to the application.

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: Oct. 30, 2025, 3:21 p.m.

7.5

CVSS3.0

CVE-2024-11603 - Server-Side Request Forgery in lm-sys/fastchat

A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is present in the `/queue/join?` endpoint, where insufficient validation of the path parameter allows an attacker to send crafted requests. This can lead to unauthorized access to internal…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: July 29, 2025, 7:36 p.m.

7.5

CVSS3.1

CVE-2025-0317 - Divide By Zero in ollama/ollama

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by zero error in the ggufPadding function, causing the server to crash and resulting in a Denial of Service (DoS) attack.

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 2, 2025, 4:07 p.m.

7.5

CVSS3.0

CVE-2025-0182 - Denial of Service in danswer-ai/danswer

A vulnerability in danswer-ai/danswer version 0.9.0 allows for denial of service through memory exhaustion. The issue arises from the use of a vulnerable version of the starlette package (<=0.49) via fastapi, which was patched in fastapi version 0.115.3. The vulnerability can be exploited by sendin…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.0

CVE-2024-11301 - Improper Enforcement of Unique Constraint in lunary-ai/lunary

In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique constraint on the combination of projectId and slug. This allows an attacker to overwrite existing data by submitting a POST request with the same slug as an existing evaluator. Th…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: July 2, 2025, 7:48 p.m.

4.3

CVSS3.0

CVE-2024-7476 - Broken Access Control in lunary-ai/lunary

A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows an authenticated attacker to modify any user's templates by sending a crafted HTTP POST request to the /v1/templates/{id}/versions endpoint. This issue is resolved in version 1.4.…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.
Total resulsts: 349182
Page 6283 of 34,919
Β« previous page Β» next page
Filters