8.4

CVSS3.0

CVE-2024-7990 - Stored Cross-Site Scripting in open-webui/open-webui

A stored cross-site scripting (XSS) vulnerability exists in open-webui/open-webui version 0.3.8. The vulnerability is present in the `/api/v1/models/add` endpoint, where the model description field is improperly sanitized before being rendered in chat. This allows an attacker to inject malicious sc…

📅 Published: March 20, 2025, 10:08 a.m. 🔄 Last Modified: July 21, 2025, 8:07 p.m.

7.5

CVSS3.0

CVE-2024-12761 - Denial of Service in brycedrennan/imaginairy

A Denial of Service (DoS) vulnerability exists in the brycedrennan/imaginairy repository, version 15.0.0. The vulnerability is present in the `/api/stablestudio/generate` endpoint, which can be exploited by sending an invalid request. This causes the server process to terminate abruptly, outputting…

📅 Published: March 20, 2025, 10:08 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.0

CVE-2024-10225 - Denial of Service in haotian-liu/llava

A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large number of characters to the end of a multipart boundary in a file upload request. This causes the server to continuously process each character, rendering the application inaccessi…

📅 Published: March 20, 2025, 10:08 a.m. 🔄 Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.0

CVE-2024-11449 - Server-Side Request Forgery in haotian-liu/llava

A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the /run/predict endpoint. An attacker can gain unauthorized access to internal networks or the AWS metadata endpoint by sending crafted requests that exploit insufficient validation…

📅 Published: March 20, 2025, 10:08 a.m. 🔄 Last Modified: July 14, 2025, 5:36 p.m.

7.5

CVSS3.0

CVE-2024-7779 - ReDoS (Regular Expression Denial of Service) in danswer-ai/danswer

A vulnerability in danswer-ai/danswer version 1 allows an attacker to perform a Regular Expression Denial of Service (ReDoS) by manipulating regular expressions. This can significantly slow down the application's response time and potentially render it completely unusable.

📅 Published: March 20, 2025, 10:08 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.0

CVE-2024-11042 - Arbitrary File Delete in invoke-ai/invokeai

In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion. This vulnerability allows unauthorized attackers to delete arbitrary files on the server, potentially including critical or sensitive system files such as SSH keys, SQLite databa…

📅 Published: March 20, 2025, 10:08 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.0

CVE-2025-0452 - Arbitrary File Deletion in eosphoros-ai/DB-GPT

eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems via the '/v1/agent/hub/update' endpoint. The application fails to properly filter the '\' character, which is commonly used as a separator in Windows paths. This vulnerability allows attackers to delete a…

📅 Published: March 20, 2025, 10:08 a.m. 🔄 Last Modified: July 17, 2025, 3:56 p.m.

7.5

CVSS3.1

CVE-2024-8999 - Improper Access Control in lunary-ai/lunary

lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bigquery endpoint. This vulnerability allows any user to export the entire database data by creating a stream to Google BigQuery without proper authentication or authorization. The …

📅 Published: March 20, 2025, 10:08 a.m. 🔄 Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.0

CVE-2024-9340 - Denial of Service (DoS) via Multipart Boundary in zenml-io/zenml

A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause excessive resource consumption by sending malformed multipart requests with arbitrary characters appended to the end of multipart boundaries. This flaw in the multipart request boundar…

📅 Published: March 20, 2025, 10:08 a.m. 🔄 Last Modified: July 15, 2025, 11:15 a.m.

8

CVSS3.0

CVE-2024-11302 - Missing check_access in lollms_binding_infos in parisneo/lollms

A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, allows attackers to add, modify, and remove bindings arbitrarily. This vulnerability affects the /install_binding and /reinstall_binding endpoints, among others, enabling unauthorize…

📅 Published: March 20, 2025, 10:08 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6295 of 34,919
« previous page » next page
Filters