7.5

CVSS3.1

CVE-2024-39722 -

An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in the api/push route.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: May 13, 2025, 2:24 p.m.

9.8

CVSS3.1

CVE-2024-51260 -

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_process function.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: April 10, 2025, 3:50 p.m.

9.1

CVSS3.1

CVE-2024-51060 -

Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: May 6, 2025, 8:15 p.m.

8.2

CVSS3.1

CVE-2024-39720 -

An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starting with the GGUF custom magic header. By leveraging a custom Modelfile that includes a FROM statement pointing to the attacker-controlled blob file, tโ€ฆ

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: May 13, 2025, 1:28 p.m.

7.5

CVSS3.1

CVE-2024-39719 -

An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path parameter that does not exist, it reflects the "File does not exist" error message to the attacker, providing a primitive for file existence on the seโ€ฆ

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: May 13, 2025, 1:32 p.m.

9.1

CVSS3.1

CVE-2024-51063 -

Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile number or email parameter.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: March 31, 2025, 7:26 p.m.

7.5

CVSS3.1

CVE-2024-39721 -

An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter is user-controlled and can be set to /dev/random, which is blocking, causing the goroutine to run infinitely (even after the HTTP request is aborted โ€ฆ

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: May 13, 2025, 12:53 p.m.

7.5

CVSS3.1

CVE-2024-48360 -

Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: July 1, 2025, 8:36 p.m.

9.8

CVSS3.1

CVE-2024-51259 -

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cacertificate function.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: April 10, 2025, 3:51 p.m.

9.8

CVSS3.1

CVE-2023-52044 -

Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 7:11 p.m.
Total resulsts: 349182
Page 8078 of 34,919
ยซ previous page ยป next page
Filters