7.6

CVSS3.1

CVE-2024-11824 - Stored XSS in langgenius/dify

A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log functionality. The vulnerability arises because certain HTML tags like <input> and <form> are not disallowed, allowing an attacker to inject malicious HTML into the log via prompโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: July 14, 2025, 5:42 p.m.

9.1

CVSS3.0

CVE-2024-10831 - Arbitrary File Write through Absolute Path Traversal in eosphoros-ai/db-gpt

In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the `file_key` and `doc_file.filename` parameters arโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: July 17, 2025, 1:38 p.m.

7.1

CVSS3.0

CVE-2024-2292 - Access Control Vulnerabilities lead to Violation of Privacy and Modification of Personal Data

Due to a lack of access control, unauthorized users are able to view and modify information pertaining to other users.

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.0

CVE-2024-10096 - github.com/dask/dask: Remote Unauthorized Pickle Deserialization Command Execution in dask/dask

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: March 26, 2025, 5:15 p.m.

8.8

CVSS3.0

CVE-2024-9415 - Path Traversal in transformeroptimus/superagi

A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. This vulnerability allows an attacker to upload an arbitrary file to the server, potentially leading to remote code execution or overwriting any file on the server.

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: July 29, 2025, 7:18 p.m.

7.5

CVSS3.0

CVE-2024-12704 - Denial of Service (DoS) in run-llama/llama_index

A vulnerability in the LangChainLLM class of the run-llama/llama_index repository, version v0.12.5, allows for a Denial of Service (DoS) attack. The stream_complete method executes the llm using a thread and retrieves the result via the get_response_gen method of the StreamingGeneratorCallbackHandlโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

6.5

CVSS3.0

CVE-2024-10274 - Improper Authorization in lunary-ai/lunary

An improper authorization vulnerability exists in lunary-ai/lunary version 1.5.5. The /users/me/org endpoint lacks adequate access control mechanisms, allowing unauthorized users to access sensitive information about all team members in the current organization. This vulnerability can lead to the dโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

9.8

CVSS3.0

CVE-2024-10553 - Jdbc Deserialization in h2oai/h2o-3

A vulnerability in the h2oai/h2o-3 REST API versions 3.46.0.4 allows unauthenticated remote attackers to execute arbitrary code via deserialization of untrusted data. The vulnerability exists in the endpoints POST /99/ImportSQLTable and POST /3/SaveToHiveTable, where user-controlled JDBC URLs are pโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: July 14, 2025, 1:43 p.m.

0.0

CVE-2024-9840 -

** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-53981. Notes: All CVE users should reference CVE-2024-53981 instead of this CVE Record. All references and descriptions in this candidate have been removed to prevent accidental usage.

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: April 15, 2025, 4:15 p.m.

9.6

CVSS3.1

CVE-2024-7760 - CSRF in aimhubio/aim

aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all origins. This enables CSRF attacks on all endpoints of the tracking server, which can bโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: July 21, 2025, 7:47 p.m.
Total resulsts: 349182
Page 6293 of 34,919
ยซ previous page ยป next page
Filters