6.1

CVSS3.1

CVE-2024-49634 - WordPress BP Member Type Manager plugin <= 1.01 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rimon Habib BP Member Type Manager bp-member-type-manager allows Reflected XSS.This issue affects BP Member Type Manager: from n/a through <= 1.01.

πŸ“… Published: Oct. 29, 2024, 1:05 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

6.1

CVSS3.1

CVE-2024-49635 - WordPress Banner Slider plugin <= 2.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in manjurul.cis Banner Slider banner-slider allows Reflected XSS.This issue affects Banner Slider: from n/a through <= 2.1.

πŸ“… Published: Oct. 29, 2024, 1:04 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

6.5

CVSS3.1

CVE-2024-6673 - CSRF Vulnerability in parisneo/lollms-webui

A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-webui repository, versions v9.9 to the latest. The endpoint uses the GET method without requiring a client ID, allowing an attacker to trick a victim int…

πŸ“… Published: Oct. 29, 2024, 12:50 p.m. πŸ”„ Last Modified: Nov. 1, 2024, 8:37 p.m.

9.8

CVSS3.1

CVE-2024-8309 - SQL Injection in langchain-ai/langchain

A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant securit…

πŸ“… Published: Oct. 29, 2024, 12:50 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 12:50 p.m.

9.8

CVSS3.1

CVE-2024-7042 - Prompt Injection in langchain-ai/langchainjs Leading to SQL Injection

A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This vulnerability permits unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all da…

πŸ“… Published: Oct. 29, 2024, 12:50 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 12:50 p.m.

6.5

CVSS3.1

CVE-2024-7472 - Email Injection Vulnerability in lunary-ai/lunary

lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup). An unauthenticated attacker can inject data into outgoing emails by bypassing the extractFirstName function using a different whitespac…

πŸ“… Published: Oct. 29, 2024, 12:49 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

6.1

CVSS3.1

CVE-2024-49636 - WordPress Agile Video Player Lite plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woracal Agile Video Player Lite agile-video-player allows Reflected XSS.This issue affects Agile Video Player Lite: from n/a through <= 1.0.

πŸ“… Published: Oct. 29, 2024, 12:49 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

7.5

CVSS3.1

CVE-2024-7783 - Improper Storage of Sensitive Information in Bearer Token in mintplex-labs/anything-llm

mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the password in plaintext. This improper storage of s…

πŸ“… Published: Oct. 29, 2024, 12:49 p.m. πŸ”„ Last Modified: Oct. 31, 2024, 3:49 p.m.

9.1

CVSS3.1

CVE-2024-7774 - Path Traversal in langchain-ai/langchainjs

A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite existing text files, read `.txt` files, and delete files. The vulnerability is exploited through the `…

πŸ“… Published: Oct. 29, 2024, 12:49 p.m. πŸ”„ Last Modified: May 28, 2025, 3:21 p.m.

4.3

CVSS3.1

CVE-2024-8143 - Unauthorized Access to User Chat History in gaizhenbiao/chuanhuchatgpt

In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the user's name. By manipulating the /file endpoint…

πŸ“… Published: Oct. 29, 2024, 12:49 p.m. πŸ”„ Last Modified: Oct. 31, 2024, 4:23 p.m.
Total resulsts: 343948
Page 7572 of 34,395
Β« previous page Β» next page
Filters