6.1

CVSS3.1

CVE-2024-12374 - Stored XSS in automatic1111/stable-diffusion-webui

A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An attacker can upload an HTML file, which the application interprets as content-type application/html. If a victim accesses the malicious link, it will execute arbitrary JavaScriptโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: Oct. 30, 2025, 3:29 p.m.

6.5

CVSS3.0

CVE-2024-7771 - Denial of Service in mintplex-labs/anything-llm

A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denial of service. Uploading an audio file with a very low sample rate causes the functionality responsible for transcribing it to crash the entire site instance. The issue arises fromโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: July 15, 2025, 3:12 p.m.

9.1

CVSS3.1

CVE-2024-8019 - Arbitrary File Write/Overwrite in lightning-ai/pytorch-lightning

In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead toโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 1:42 a.m.

5.3

CVSS3.0

CVE-2024-8251 - Prisma Injection in mintplex-labs/anything-llm

A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in the API endpoint "/embed/:embedId/stream-chat" where user-provided JSON is directly taken to the Prisma library's where clause. An attacker can exploit this by providing a speciallyโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

6.5

CVSS3.0

CVE-2024-10273 - Improper Privilege Management in lunary-ai/lunary

In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify models owned by others. The PATCH endpoint for models does not have appropriate privilege checks, enabling low-privilege users to update models they should not have access to modโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.1

CVE-2025-0190 - Denial of Service in aimhubio/aim

In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists. By tracking a large number of `Text` objects and then querying them simultaneously through the web API, the Aim web server becomes unresponsive to other requests for an extended period while processing and returning these โ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: March 28, 2025, 2:28 p.m.

5.3

CVSS3.0

CVE-2024-10940 - Exposure of Sensitive System Information via ImagePromptTemplate in langchain-ai/langchain

A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized users to read arbitrary files from the host file system. The issue arises from the ability to create langchain_core.prompts.ImagePromptTemplate's (and by extension langchain_core.prโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-9095 - Improper Authorization in lunary-ai/lunary

In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to create a Datastream to Google BigQuery and export the entire database. This includes sensitive data such as password hashes and secret API keys. The route is protected by a confiโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.0

CVE-2024-10713 - Denial of Service (DoS) via Multipart Request in szad670401/hyperlpr

A vulnerability in szad670401/hyperlpr v3.0 allows for a Denial of Service (DoS) attack. The server fails to handle excessive characters appended to the end of multipart boundaries, regardless of the character used. This flaw can be exploited by sending malformed multipart requests with arbitrary cโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-12055 - DoS using malicious gguf model file in ollama/ollama

A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be uploaded to the public Ollama server. When the server processes this malicious model, it crashes, leading to a Denial of Service (DoS) attack. The root cause of the issue is an outโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: May 13, 2025, 1:28 p.m.
Total resulsts: 349182
Page 6296 of 34,919
ยซ previous page ยป next page
Filters