6.5

CVSS3.1

CVE-2024-7473 - IDOR Vulnerability in lunary-ai/lunary

An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update other users' prompts by manipulating the 'id' parameter in the request. The issue is fixed in version 1.4.3.

πŸ“… Published: Oct. 29, 2024, 12:48 p.m. πŸ”„ Last Modified: Nov. 3, 2024, 6:27 p.m.

5.9

CVSS3.1

CVE-2024-7010 - Timing Attack in mudler/localai

mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic algorithms. Specifically, in the context of password handling, an attacker can determine valid logi…

πŸ“… Published: Oct. 29, 2024, 12:48 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.1

CVE-2024-7807 - Denial of Service (DOS) in gaizhenbiao/chuanhuchatgpt

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process each character, rendering ChuanhuChatGPT in…

πŸ“… Published: Oct. 29, 2024, 12:48 p.m. πŸ”„ Last Modified: Jan. 9, 2025, 6:15 p.m.

6.1

CVSS3.1

CVE-2024-49637 - WordPress Bet WC 2018 Russia plugin <= 2.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foxskav Bet WC 2018 Russia bet-wc-2018-russia allows Reflected XSS.This issue affects Bet WC 2018 Russia: from n/a through <= 2.1.

πŸ“… Published: Oct. 29, 2024, 12:48 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

7.5

CVSS3.1

CVE-2024-7962 - Arbitrary File Read via Insufficient Validation in gaizhenbiao/chuanhuchatgpt

An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read any file that matches specific criteria using an absolute path. The file must not have a .json extension and, except for…

πŸ“… Published: Oct. 29, 2024, 12:47 p.m. πŸ”„ Last Modified: Nov. 1, 2024, 2:19 p.m.

9.8

CVSS3.1

CVE-2024-6868 - Arbitrary File Write in mudler/LocalAI

mudler/LocalAI version 2.17.1 allows for arbitrary file write due to improper handling of automatic archive extraction. When model configurations specify additional files as archives (e.g., .tar), these archives are automatically extracted after downloading. This behavior can be exploited to perfor…

πŸ“… Published: Oct. 29, 2024, 12:46 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.1

CVSS3.1

CVE-2024-6674 - Data Leak through CORS Misconfiguration in parisneo/lollms-webui

A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, suc…

πŸ“… Published: Oct. 29, 2024, 12:46 p.m. πŸ”„ Last Modified: Nov. 1, 2024, 8:34 p.m.

8.1

CVSS3.1

CVE-2024-7474 - IDOR in lunary-ai/lunary

In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view or delete external users by manipulating the 'id' parameter in the request URL. The application does not perform adequate checks on the 'id' parameter, allowing unauthorized access…

πŸ“… Published: Oct. 29, 2024, 12:46 p.m. πŸ”„ Last Modified: Jan. 9, 2025, 6:15 p.m.

9.1

CVSS3.1

CVE-2024-5982 - Path Traversal in gaizhenbiao/chuanhuchatgpt

A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from unsanitized input handling in multiple features, including user upload, directory creation, and template loading. Specifically, the load_chat_history function in modules/models/b…

πŸ“… Published: Oct. 29, 2024, 12:46 p.m. πŸ”„ Last Modified: Nov. 14, 2024, 6:52 p.m.

9.1

CVSS3.1

CVE-2024-7475 - Improper Access Control in lunary-ai/lunary

An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation of authentication processes, fraudulent login requests, and theft of user information. Appropriate access…

πŸ“… Published: Oct. 29, 2024, 12:45 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 2:10 p.m.
Total resulsts: 343946
Page 7573 of 34,395
Β« previous page Β» next page
Filters