8.1

CVSS3.0

CVE-2024-8060 - Remote Code Execution in OpenWebUI via Arbitrary File Upload

OpenWebUI version 0.3.0 contains a vulnerability in the audio API endpoint `/audio/api/v1/transcriptions` that allows for arbitrary file upload. The application performs insufficient validation on the `file.content_type` and allows user-controlled filenames, leading to a path traversal vulnerabilit…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.0

CVE-2024-9362 - Directory Traversal in polyaxon/polyaxon

An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version. This vulnerability allows an attacker to retrieve directory information and file contents from the server without proper authorization, leading to sensitive information disclosure. The issue enabl…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-0315 - Allocation of Resources Without Limits or Throttling in ollama/ollama

A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create it. This can cause the server to allocate unlimited memory, leading to a Denial of Service (DoS) attack.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: April 2, 2025, 4:02 p.m.

8.3

CVSS3.0

CVE-2024-8099 - Server-Side Request Forgery (SSRF) in vanna-ai/vanna

A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of vanna-ai/vanna when using DuckDB as the database. An attacker can exploit this vulnerability by submitting crafted SQL queries that leverage DuckDB's default features, such as `read_csv`, `read_csv_auto`, `read_text`…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-9699 - Cross-Site Scripting (XSS) in flatpressblog/flatpress

A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to upload a file with a JavaScript payload disguised as a filename. This can lead to a Cross-Site Scripting (XSS) attack if the uploaded file is accessed by other users. The issue i…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: June 24, 2025, 2:37 p.m.

8.8

CVSS3.1

CVE-2024-9431 - Improper Privilege Management in transformeroptimus/superagi

In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After logging into the system, users can change the passwords of other users, leading to potential account takeover.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

4.4

CVSS3.0

CVE-2024-7058 - Relative Path Traversal in parisneo/lollms-webui

A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization by using relative paths such as './'. This can lead to unauthorized access to directories within the personality_folder on the victim's computer.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 8, 2025, 4:10 p.m.

4.9

CVSS3.0

CVE-2024-7040 - Improper Access Control in open-webui/open-webui

In version v0.3.8 of open-webui/open-webui, there is an improper access control vulnerability. On the frontend admin page, administrators are intended to view only the chats of non-admin members. However, by modifying the user_id parameter, it is possible to view the chats of any administrator, inc…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

0.0

CVE-2024-12760 -

** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-4940. Notes: All CVE users should reference CVE-2024-4940 instead of this CVE Record. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: April 15, 2025, 4:15 p.m.

7.1

CVSS3.0

CVE-2024-12911 - SQL Injection in run-llama/llama_index

A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.
Total resulsts: 349182
Page 6286 of 34,919
Β« previous page Β» next page
Filters