7.5

CVSS3.1

CVE-2024-52383 - WordPress Ai Auto Tool Content Writing Assistant plugin <= 2.1.2 - Broken Access Control vulnerabilโ€ฆ

Missing Authorization vulnerability in aitool Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One ai-auto-tool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in Oโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 5:36 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:21 p.m.

7.3

CVSS3.1

CVE-2024-5125 - XSS and Open Redirect via SVG File Upload in parisneo/lollms-webui

parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input validation and processing of SVG files during the upload process. The XSS vulnerability allows attackers to embed malicious JavaScript code within SVG files, which is executed upoโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 5:36 p.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 8:15 p.m.

5.4

CVSS3.1

CVE-2024-4311 - Lack of login attempt rate-limiting in zenml-io/zenml

zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password change function. An attacker can brute-force the current password in the 'Update Password' function, allowing them to take over the user's account. This vulnerability is due to the abโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 5:35 p.m. ๐Ÿ”„ Last Modified: May 7, 2025, 1:48 p.m.

9.9

CVSS3.1

CVE-2024-52384 - WordPress Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation plugin <= 2.4.9 -โ€ฆ

Unrestricted Upload of File with Dangerous Type vulnerability in wpmonks Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation ai-content-generator allows Upload a Web Shell to a Web Server.This issue affects Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation:โ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 5:35 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:21 p.m.

9.1

CVSS3.1

CVE-2024-3502 - Exposure of Sensitive Information in lunary-ai/lunary

In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists where account recovery hashes of users are inadvertently exposed to unauthorized actors. This issue occurs when authenticated users inspect responses from `GET /v1/users/me` and `GET /v1/users/me/โ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 5:34 p.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

9.1

CVSS3.1

CVE-2024-3501 - Exposure of Sensitive Information in lunary-ai/lunary

In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclusion of single-use tokens in the responses of `GET /v1/users/me` and `GET /v1/users/me/org` API endpoints. These tokens, intended for sensitive operations such as password resets oโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 5:34 p.m. ๐Ÿ”„ Last Modified: Jan. 30, 2025, 1:15 p.m.

9.6

CVSS3.1

CVE-2024-3379 - Incorrect Authorization in lunary-ai/lunary

In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key for projects they do not have access to. Specifically, a user with a 'Member' role can issue a request to regenerate the private key of a project withoโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 5:34 p.m. ๐Ÿ”„ Last Modified: Nov. 18, 2024, 9:30 p.m.

8.1

CVSS3.1

CVE-2024-52381 - WordPress ZIJ KART plugin <= 1.1 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Shoaib Rehmat ZIJ KART zij-kart allows PHP Local File Inclusion.This issue affects ZIJ KART: from n/a through <= 1.1.

๐Ÿ“… Published: Nov. 14, 2024, 5:33 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:21 p.m.

9.8

CVSS3.1

CVE-2024-4343 - Python Command Injection in imartinez/privategpt

A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/components/llm/custom/sagemaker.py` of the imartinez/privategpt application, versions up to and including 0.3.0. The vulnerability arises due to the use of the `eval()` function tโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 5:32 p.m. ๐Ÿ”„ Last Modified: July 17, 2025, 1:33 a.m.

4.3

CVSS3.1

CVE-2024-1682 - Unclaimed S3 Bucket Reference in psf/requests Documentation

An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This bucket has been claimed by an external party. The use of this unclaimed S3 bucket could lead to data integrity issues, data leakage, availability problems, loss of trustworthinessโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 5:32 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7875 of 34,919
ยซ previous page ยป next page
Filters