9.8

CVSS3.1

CVE-2024-12909 - SQL Injection to RCE in run-llama/llama_index

A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql_query` function of the `database_agent`. This vulnerability can be exploited by an attacker to inject arbitrary SQL queries, leading to remote code e…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: July 30, 2025, 1 a.m.

7.5

CVSS3.0

CVE-2024-9363 - Unauthorized File Deletion in polyaxon/polyaxon

An unauthorized file deletion vulnerability exists in the latest version of the Polyaxon platform, which can lead to denial of service by terminating critical containers. An attacker can delete important files within the containers, such as `polyaxon.sock`, causing the API container to exit unexpec…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8

CVSS3.0

CVE-2024-9847 - Cross-Site Request Forgery (CSRF) in flatpressblog/flatpress

FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable or disable plugins on behalf of a victim user. The attacker can craft a malicious link or script that, when clicked by an authenticated user, will send a request to the FlatPress…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: June 24, 2025, 2:38 p.m.

7.5

CVSS3.0

CVE-2024-8984 - Denial of Service (DoS) in berriai/litellm

A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to excessive resource …

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: Oct. 15, 2025, 1:15 p.m.

9.8

CVSS3.1

CVE-2024-10902 - Arbitrary File Upload with Path Traversal in eosphoros-ai/db-gpt

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This vulnerability allows unauthorized attackers to upload arbitrary files to the victim's file system at any location. The impact of this vulnerability in…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.0

CVE-2024-10821 - Denial of Service (DoS) in invoke-ai/invokeai

A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of the Invoke-AI server (version v5.0.1) allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundari…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-12580 - Logs Debug Injection in danny-avila/librechat

A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionId, fileId, userId, and file_id in the /code/download/:sessionId/:fileId and /download/:userId/:file_id APIs are not validated or filtered, leading to potential log injection attac…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: July 14, 2025, 5:56 p.m.

7.5

CVSS3.1

CVE-2024-11031 - SSRF in binary-husky/gpt_academic

In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerability is exploited through the HotReload(Markdown翻译中) plugin function, which allows downloading arbitrary web hosts by only…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: July 15, 2025, 11:15 a.m.

5.4

CVSS3.1

CVE-2024-10725 - Stored Cross-site Scripting (XSS) in phpipam/phpipam

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which are then executed in the context of other users who view the affected pages. The issue occurs when editing the NAT…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: May 28, 2025, 8:34 p.m.

7.3

CVSS3.0

CVE-2024-10275 - Improper Role Modification by Admins for Billing Permissions in lunary-ai/lunary

In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access billing resources, can change the permissions of existing users to include billing permissions. This can lead to a privilege escalation scenario where an administrator can manage …

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: Oct. 15, 2025, 1:15 p.m.
Total resulsts: 349182
Page 6291 of 34,919
« previous page » next page
Filters