8.6

CVSS3.1

CVE-2024-5885 - Server-Side Request Forgery (SSRF) in stangirard/quivr

stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not provide sufficient controls when crawling a website, allowing an attacker to access applications on the local network. This vulnerability could allow a malicious user to gain acces…

πŸ“… Published: June 27, 2024, 6:45 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

8.6

CVSS3.0

CVE-2024-6085 - Path Traversal in parisneo/lollms

A path traversal vulnerability exists in the XTTS server included in the lollms package, version v9.6. This vulnerability arises from the ability to perform an unauthenticated root folder settings change. Although the read file endpoint is protected against path traversals, this protection can be b…

πŸ“… Published: June 27, 2024, 6:45 p.m. πŸ”„ Last Modified: July 12, 2025, 10:24 p.m.

9.8

CVSS3.1

CVE-2024-5822 - Server-Side Request Forgery (SSRF) in gaizhenbiao/ChuanhuChatGPT

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT-20240410-git.zip. This vulnerability allows attackers to send crafted requests from the vulnerable server to internal or external resources, potentia…

πŸ“… Published: June 27, 2024, 6:44 p.m. πŸ”„ Last Modified: July 15, 2025, 3:34 p.m.

6.8

CVSS3.1

CVE-2024-5714 - Improper Access Control in lunary-ai/lunary

In lunary-ai/lunary version 1.2.4, an improper access control vulnerability allows members with team management permissions to manipulate project identifiers in requests, enabling them to invite users to projects in other organizations, change members to projects in other organizations with escalat…

πŸ“… Published: June 27, 2024, 6:42 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.0

CVE-2024-6038 - ReDoS Vulnerability in gaizhenbiao/chuanhuchatgpt

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the utils.py module. This function takes a user-provided keyword and attempts to match it against chat history …

πŸ“… Published: June 27, 2024, 6:41 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.0

CVE-2024-6250 - Absolute Path Traversal in parisneo/lollms-webui

An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint of `lollms_advanced.py`. The `sanitize_path` function with `allow_absolute_path=True` allows an attacker to access arbitrary files and directories on a Windows system. This vulner…

πŸ“… Published: June 27, 2024, 6:41 p.m. πŸ”„ Last Modified: July 9, 2025, 2:23 p.m.

6.5

CVSS3.1

CVE-2024-5710 - Improper Access Control in Team Management in berriai/litellm

berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vulnerability allows attackers to perform unauthorized actions such as creating, updating, viewing, deleting, blocking, and unblocking any teams, as well as adding or deleting any mem…

πŸ“… Published: June 27, 2024, 6:41 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

8.8

CVSS3.1

CVE-2024-5820 - Unprotected WebSocket in stitionai/devika

An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious website to connect to the backend and issue commands on behalf of the user. The backend serves all listeners on the given socket, enabling any such malicious website to intercept all co…

πŸ“… Published: June 27, 2024, 6:40 p.m. πŸ”„ Last Modified: July 15, 2025, 3:36 p.m.

7.5

CVSS3.0

CVE-2024-6090 - Path Traversal Vulnerability in gaizhenbiao/chuanhuchatgpt

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target system, leading to a denial of service as users are unable to a…

πŸ“… Published: June 27, 2024, 6:40 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

9.8

CVSS3.1

CVE-2024-5751 - Remote Code Execution in BerriAI/litellm

BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_deployment` function, which decodes and decrypts environment variables from base64 and assigns them to `os.environ`. An attacker can exploit this by sen…

πŸ“… Published: June 27, 2024, 6:40 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 12:50 p.m.
Total resulsts: 342654
Page 8660 of 34,266
Β« previous page Β» next page
Filters