9.8

CVSS3.1

CVE-2024-5980 - Arbitrary File Write via /v1/runs API endpoint in lightning-ai/pytorch-lightning

A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path โ€ฆ

๐Ÿ“… Published: June 27, 2024, 6:46 p.m. ๐Ÿ”„ Last Modified: Oct. 21, 2025, 2:13 p.m.

5.4

CVSS3.1

CVE-2024-5933 - Cross-site Scripting (XSS) in parisneo/lollms-webui

A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest version. This vulnerability allows an attacker to inject malicious scripts via chat messages, which are then executed in the context of the user's browser.

๐Ÿ“… Published: June 27, 2024, 6:46 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2025, 3:43 p.m.

4.3

CVSS3.1

CVE-2024-6086 - Improper Access Control in lunary-ai/lunary

In version 1.2.7 of lunary-ai/lunary, any authenticated user, regardless of their role, can change the name of an organization due to improper access control. The function checkAccess() is not implemented, allowing users with the lowest privileges, such as the 'Prompt Editor' role, to modify organiโ€ฆ

๐Ÿ“… Published: June 27, 2024, 6:46 p.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.3

CVSS3.0

CVE-2024-6139 - Path Traversal in parisneo/lollms

A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to arbitrary locations on the system and enumerate file paths. The issue arises from improper validation of user-provided file paths in thโ€ฆ

๐Ÿ“… Published: June 27, 2024, 6:45 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-5935 - CSRF Vulnerability in imartinez/privategpt

A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete all uploaded files on the server. This can lead to data loss and service disruption for the application's users.

๐Ÿ“… Published: June 27, 2024, 6:45 p.m. ๐Ÿ”„ Last Modified: May 19, 2025, 4:50 p.m.

5.3

CVSS3.1

CVE-2024-5755 - Email Validation Bypass in lunary-ai/lunary

In lunary-ai/lunary versions <=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the email address. This allows the creation of multiple accounts with essentially the same email address (e.g., '[email protected]' and '[email protected]'), leading to incorreโ€ฆ

๐Ÿ“… Published: June 27, 2024, 6:45 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

6.1

CVSS3.1

CVE-2024-5936 - Open Redirect in imartinez/privategpt

An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allows attackers to redirect users to a URL specified by user-controlled input without proper validation or sanitization. The impact of this vulnerabilityโ€ฆ

๐Ÿ“… Published: June 27, 2024, 6:45 p.m. ๐Ÿ”„ Last Modified: July 17, 2025, 1:43 a.m.

7.4

CVSS3.0

CVE-2024-5824 - Path Traversal in parisneo/lollms

A path traversal vulnerability in the `/set_personality_config` endpoint of parisneo/lollms version 9.4.0 allows an attacker to overwrite the `configs/config.yaml` file. This can lead to remote code execution by changing server configuration properties such as `force_accept_remote_access` and `turnโ€ฆ

๐Ÿ“… Published: June 27, 2024, 6:45 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2024-5885 - Server-Side Request Forgery (SSRF) in stangirard/quivr

stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not provide sufficient controls when crawling a website, allowing an attacker to access applications on the local network. This vulnerability could allow a malicious user to gain accesโ€ฆ

๐Ÿ“… Published: June 27, 2024, 6:45 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

8.6

CVSS3.0

CVE-2024-6085 - Path Traversal in parisneo/lollms

A path traversal vulnerability exists in the XTTS server included in the lollms package, version v9.6. This vulnerability arises from the ability to perform an unauthenticated root folder settings change. Although the read file endpoint is protected against path traversals, this protection can be bโ€ฆ

๐Ÿ“… Published: June 27, 2024, 6:45 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9312 of 34,919
ยซ previous page ยป next page
Filters