9.8

CVSS3.1

CVE-2024-10835 - Arbitrary File Write via SQL Injection in eosphoros-ai/db-gpt

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform Arbitrary File Write using DuckDB SQL, enabling them to write arbitrary files to the vic…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 17, 2025, 1:39 p.m.

6.1

CVSS3.0

CVE-2024-11044 - Open Redirect in automatic1111/stable-diffusion-webui

An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user cre…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 4:40 p.m.

2.6

CVSS3.0

CVE-2024-9052 - vllm: Remote Code Execution by Pickle Deserialization in vllm-project/vllm

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: April 10, 2025, 4:17 p.m.

5.4

CVSS3.1

CVE-2024-10724 - Stored XSS in IPV6 Section in phpipam/phpipam

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when editing the Destination address. This vulnerability allows an attacker to execute malicious code. The issue is fixed in version 1.7.0.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: May 28, 2025, 8:34 p.m.

7.1

CVSS3.0

CVE-2024-12216 - Arbitrary File Write via TarSlip in dmlc/gluon-cv

A vulnerability in the `ImageClassificationDataset.from_csv()` API of the `dmlc/gluon-cv` repository, version 0.10.0, allows for arbitrary file write. The function downloads and extracts `tar.gz` files from URLs without proper sanitization, making it susceptible to a TarSlip vulnerability. Attacker…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-7999 -

** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-53981. Notes: All CVE users should reference CVE-2024-53981 instead of this CVE Record. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: April 15, 2025, 4:15 p.m.

7.5

CVSS3.0

CVE-2024-10572 - Denial of Service and Arbitrary File Write in h2oai/h2o-3

In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` parser. This includes the `XGBoostLibExtractTool` class, which can be exploited to shut down the server and write large files to arbitrary directories, leading to a denial of servi…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.1

CVE-2024-8955 - SSRF in composiohq/composio

A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the contents of any file in the system by exploiting the BROWSERTOOL_GOTO_PAGE and BROWSERTOOL_GET_PAGE_DETAILS actions.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

8.3

CVSS3.0

CVE-2024-10109 - Incorrect Authorization in mintplex-labs/anything-llm

A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "/api/system/custom-models". This access enables them to modify the model's API key and base path, leading to potential API key leakage and denial of s…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 11, 2025, 8:43 p.m.

8.8

CVSS3.0

CVE-2024-8489 - CSRF due to overly permissive CORS headers in modelscope/agentscope

A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to overly permissive CORS headers. This issue affects the latest commit on the main branch (21161fe). The vulnerability permits an attacker to access all …

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6289 of 34,919
Β« previous page Β» next page
Filters