6.5

CVSS3.1

CVE-2024-10366 - IDOR in delete attachments in danny-avila/librechat

An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment ID belongs to the current user, allowing any authenticated user to delete attachments of other use…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 15, 2025, 11:15 a.m.

7.5

CVSS3.0

CVE-2024-8764 - Improper Authorization in lunary-ai/lunary

A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute arbitrary regular expressions on the server side. This can lead to a Denial of Service (DoS) condition, as certain regular expressions can cause excessive resource consumption, blocking the server from pro…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

5.3

CVSS3.0

CVE-2024-6483 - Arbitrary File/Directory Deletion in aimhubio/aim

A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or directory deletion through path traversal. The endpoint does not mitigate path traversal when handling user-specified run-names, which are used to specify log/metadata files for deletion.…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 23, 2025, 8:57 p.m.

5.3

CVSS3.0

CVE-2024-10047 - Directory Listing Vulnerability in parisneo/lollms-webui

parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on a Windows system by sending a specially crafted HTTP request to the /open_file endpoint.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 8, 2025, 4:28 p.m.

8.1

CVSS3.0

CVE-2024-10762 - Missing Authorization in lunary-ai/lunary

In lunary-ai/lunary before version 1.5.9, the /v1/evaluators/ endpoint allows users to delete evaluators of a project by sending a DELETE request. However, the route lacks proper access control, such as middleware to ensure that only users with appropriate roles can delete evaluator data. This vuln…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 2, 2025, 7:47 p.m.

0.0

CVE-2024-9016 -

** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-45595. Notes: All CVE users should reference CVE-2024-45595 instead of this CVE Record. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: April 15, 2025, 4:15 p.m.

7.5

CVSS3.0

CVE-2025-0330 - Exposure of Sensitive Information in berriai/litellm

In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfuse_secret and langfuse_public_key, which can provide full access to the Langfus…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 1:58 p.m.

8.1

CVSS3.1

CVE-2024-12039 - Improper Restriction of Excessive Authentication Attempts in langgenius/dify

langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess attempts for password reset. This allows an unauthenticated attacker to reset owner, admin, or other user passwords within a few hours by guessing the six-digit code, resulting in …

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 15, 2025, 3:59 p.m.

9.8

CVSS3.1

CVE-2024-9053 - Remote Code Execution in vllm-project/vllm

vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core functionality run_server_loop() calls the function _make_handler_coro(), which directly uses cloudpickle.loads() on received messages without any sanitization. This can result in …

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.1

CVSS3.0

CVE-2024-9597 - Path Traversal in parisneo/lollms

A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attacker to delete any directory on the system. The vulnerability arises from improper validation of the `key` parameter, which is used to construct file paths. An attacker can exploit…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6288 of 34,919
Β« previous page Β» next page
Filters