7.5

CVSS3.0

CVE-2024-11169 - Unhandled Exception Leading to Server Crash in danny-avila/librechat

An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs module throws an exception while handling file uploads. An unauthenticated user can trigger this exception by sending a specially crafted request, causing the server to crash. Th…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 15, 2025, 4:45 p.m.

8.8

CVSS3.0

CVE-2024-11039 - Deserialization of Untrusted Data in binary-husky/gpt_academic

A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt_academic versions up to and including 3.83. This vulnerability allows attackers to achieve remote command execution by deserializing untrusted data. The issue arises from the inc…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 14, 2025, 2:24 p.m.

6.1

CVSS3.0

CVE-2024-10908 - Open Redirect in lm-sys/fastchat

An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 31, 2025, 3:35 p.m.

7.5

CVSS3.1

CVE-2024-7036 - Denial of Service in open-webui/open-webui

A vulnerability in open-webui/open-webui v0.3.8 allows an unauthenticated attacker to sign up with excessively large text in the 'name' field, causing the Admin panel to become unresponsive. This prevents administrators from performing essential user management actions such as deleting, editing, or…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 18, 2025, 7:54 p.m.

7.1

CVSS3.0

CVE-2024-6854 - Arbitrary File Overwrite in h2oai/h2o-3

In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an attacker to export a model to any file in the server's file structure, thereby overwriting it. This vulnerability can be exploited to overwrite any file on the target server with a tr…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 15, 2025, 3:55 p.m.

6.5

CVSS3.0

CVE-2024-10707 - Local File Inclusion in gaizhenbiao/chuanhuchatgpt

gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the gradio component gr.JSON, which has a known issue (CVE-2024-4941). This vulnerability allows unauthenticated users to access arbitrary files on the server by uploading a speciall…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

8.4

CVSS3.0

CVE-2024-9919 - Missing Authentication Check in parisneo/lollms-webui

A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access() function to verify the client_id, enabling attackers to delete directories with…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.0

CVE-2024-6851 - Arbitrary File Deletion in aimhubio/aim

In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by LocalFileManager, allowing a maliciously crafted glo…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 23, 2025, 8:57 p.m.

7.5

CVSS3.0

CVE-2024-6827 - HTTP Request Smuggling in benoitc/gunicorn

Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exp…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.0

CVE-2024-4023 - Stored XSS in flatpressblog/flatpress

A stored cross-site scripting (XSS) vulnerability exists in flatpressblog/flatpress version 1.3. When a user uploads a file with a `.xsig` extension and directly accesses this file, the server responds with a Content-type of application/octet-stream, leading to the file being processed as an HTML f…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: June 23, 2025, 8:46 p.m.
Total resulsts: 349182
Page 6284 of 34,919
Β« previous page Β» next page
Filters