9.8

CVSS3.1

CVE-2024-36736 -

An issue in the oneflow.permute component of OneFlow-Inc. Oneflow v0.9.1 causes an incorrect calculation when the same dimension operation is performed.

πŸ“… Published: June 6, 2024, 5:47 p.m. πŸ”„ Last Modified: March 25, 2025, 5:15 p.m.

7.5

CVSS3.1

CVE-2024-5277 - Weak Password Recovery Mechanism in lunary-ai/lunary

In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after use. This allows an attacker who compromises the recovery token to repeatedly change the password of a victim's account. The issue lies in the backend…

πŸ“… Published: June 6, 2024, 5:46 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.

7.5

CVSS3.1

CVE-2024-36737 -

Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the oneflow.full parameter.

πŸ“… Published: June 6, 2024, 5:43 p.m. πŸ”„ Last Modified: May 2, 2025, 1:02 p.m.

9.4

CVSS3.1

CVE-2024-3033 - Improper Authorization in mintplex-labs/anything-llm

An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-routes. This flaw allows unauthenticated users to perform destructive actions on the VectorDB, including resetting the database and deleting specific …

πŸ“… Published: June 6, 2024, 5:32 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:28 a.m.

5.4

CVSS3.1

CVE-2024-5127 - Improper Access Control in lunary-ai/lunary

In lunary-ai/lunary versions 1.2.2 through 1.2.25, an improper access control vulnerability allows users on the Free plan to invite other members and assign them any role, including those intended for Paid and Enterprise plans only. This issue arises due to insufficient backend validation of roles …

πŸ“… Published: June 6, 2024, 5:26 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.

8.8

CVSS3.1

CVE-2024-3152 - Privilege Escalation and Local File Inclusion in mintplex-labs/anything-llm

mintplex-labs/anything-llm is vulnerable to multiple security issues due to improper input validation in several endpoints. An attacker can exploit these vulnerabilities to escalate privileges from a default user role to an admin role, read and delete arbitrary files on the system, and perform Serv…

πŸ“… Published: June 6, 2024, 5:19 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.1

CVE-2024-36745 -

An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the oneflow.index_select parameter.

πŸ“… Published: June 6, 2024, 5:16 p.m. πŸ”„ Last Modified: March 25, 2025, 6:15 p.m.

7.5

CVSS3.1

CVE-2024-36743 -

An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.dot.

πŸ“… Published: June 6, 2024, 5:12 p.m. πŸ”„ Last Modified: May 2, 2025, 12:53 p.m.

7.5

CVSS3.1

CVE-2024-36742 -

An issue in the oneflow.scatter_nd parameter OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index parameter exceeds the range of shape.

πŸ“… Published: June 6, 2024, 5:10 p.m. πŸ”„ Last Modified: May 2, 2025, 1:17 p.m.

6.1

CVSS3.1

CVE-2024-37156 - TokenController formName not sanitized in hidden input

The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is not sanitized in the returned input field which leads to XSS. This vulnerability is fixed in 2.5.3.

πŸ“… Published: June 6, 2024, 4:03 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:23 a.m.
Total resulsts: 345151
Page 9164 of 34,516
Β« previous page Β» next page
Filters