7.5

CVSS3.1

CVE-2024-7783 - Improper Storage of Sensitive Information in Bearer Token in mintplex-labs/anything-llm

mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the password in plaintext. This improper storage of s…

πŸ“… Published: Oct. 29, 2024, 12:49 p.m. πŸ”„ Last Modified: Oct. 31, 2024, 3:49 p.m.

9.1

CVSS3.1

CVE-2024-7774 - Path Traversal in langchain-ai/langchainjs

A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite existing text files, read `.txt` files, and delete files. The vulnerability is exploited through the `…

πŸ“… Published: Oct. 29, 2024, 12:49 p.m. πŸ”„ Last Modified: May 28, 2025, 3:21 p.m.

4.3

CVSS3.1

CVE-2024-8143 - Unauthorized Access to User Chat History in gaizhenbiao/chuanhuchatgpt

In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the user's name. By manipulating the /file endpoint…

πŸ“… Published: Oct. 29, 2024, 12:49 p.m. πŸ”„ Last Modified: Oct. 31, 2024, 4:23 p.m.

9.0

CVSS3.1

CVE-2024-6581 - Remote Code Execution due to Stored XSS in parisneo/lollms

A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploading of SVG files. Due to incomplete filtering in the sanitize_svg function, this can lead to cross-site scripting (XSS) vulnerabilities, which in turn pose a risk of remote code exe…

πŸ“… Published: Oct. 29, 2024, 12:49 p.m. πŸ”„ Last Modified: Nov. 1, 2024, 7:38 p.m.

9.1

CVSS3.1

CVE-2024-5823 - File Overwrite Vulnerability in gaizhenbiao/chuanhuchatgpt

A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files within the system. Exploiting this vulnerability can lead to unauthorized changes in system behavior …

πŸ“… Published: Oct. 29, 2024, 12:48 p.m. πŸ”„ Last Modified: Oct. 31, 2024, 6:05 p.m.

6.5

CVSS3.1

CVE-2024-7473 - IDOR Vulnerability in lunary-ai/lunary

An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update other users' prompts by manipulating the 'id' parameter in the request. The issue is fixed in version 1.4.3.

πŸ“… Published: Oct. 29, 2024, 12:48 p.m. πŸ”„ Last Modified: Nov. 3, 2024, 6:27 p.m.

5.9

CVSS3.1

CVE-2024-7010 - Timing Attack in mudler/localai

mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic algorithms. Specifically, in the context of password handling, an attacker can determine valid logi…

πŸ“… Published: Oct. 29, 2024, 12:48 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.1

CVE-2024-7807 - Denial of Service (DOS) in gaizhenbiao/chuanhuchatgpt

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process each character, rendering ChuanhuChatGPT in…

πŸ“… Published: Oct. 29, 2024, 12:48 p.m. πŸ”„ Last Modified: Jan. 9, 2025, 6:15 p.m.

7.1

CVSS3.1

CVE-2024-49637 - WordPress Bet WC 2018 Russia plugin <= 2.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foxskav Bet WC 2018 Russia bet-wc-2018-russia allows Reflected XSS.This issue affects Bet WC 2018 Russia: from n/a through <= 2.1.

πŸ“… Published: Oct. 29, 2024, 12:48 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

7.5

CVSS3.1

CVE-2024-7962 - Arbitrary File Read via Insufficient Validation in gaizhenbiao/chuanhuchatgpt

An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read any file that matches specific criteria using an absolute path. The file must not have a .json extension and, except for…

πŸ“… Published: Oct. 29, 2024, 12:47 p.m. πŸ”„ Last Modified: Nov. 1, 2024, 2:19 p.m.
Total resulsts: 349182
Page 8096 of 34,919
Β« previous page Β» next page
Filters