8.4

CVSS3.0

CVE-2024-3126 - Command Injection in parisneo/lollms-webui

A command injection vulnerability exists in the 'run_xtts_api_server' function of the parisneo/lollms-webui application, specifically within the 'lollms_xtts.py' script. The vulnerability arises due to the improper neutralization of special elements used in an OS command. The affected function util…

πŸ“… Published: May 16, 2024, 9:03 a.m. πŸ”„ Last Modified: July 9, 2025, 2:36 p.m.

7.5

CVSS3.0

CVE-2024-3403 - Local File Inclusion in imartinez/privategpt

imartinez/privategpt version 0.2.0 is vulnerable to a local file inclusion vulnerability that allows attackers to read arbitrary files from the filesystem. By manipulating file upload functionality to ingest arbitrary local files, attackers can exploit the 'Search in Docs' feature or query the AI t…

πŸ“… Published: May 16, 2024, 9:03 a.m. πŸ”„ Last Modified: July 17, 2025, 8:01 p.m.

8.8

CVSS3.0

CVE-2024-4181 - Command Injection in run-llama/llama_index

A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI to connect to Language Learning Models (LLMs). The vulnerability arises from the improper use of the eval function, allowing a malicious or compromise…

πŸ“… Published: May 16, 2024, 9:03 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 11:36 a.m.

9.8

CVSS3.0

CVE-2024-4326 - Remote Code Execution via `/apply_settings` and `/execute_code` in parisneo/lollms-webui

A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the `/apply_settings` and `/execute_code` endpoints. Attackers can bypass protections by setting the host to localhost, enabling cod…

πŸ“… Published: May 16, 2024, 9:03 a.m. πŸ”„ Last Modified: July 9, 2025, 2:29 p.m.

7.5

CVSS3.1

CVE-2024-3848 - Path Traversal Bypass in mlflow/mlflow

A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the application's handling of artifact URLs, where a '#' character can be used to insert a path into the fragment, effectively skip…

πŸ“… Published: May 16, 2024, 9:03 a.m. πŸ”„ Last Modified: Jan. 24, 2025, 5:28 p.m.

7.5

CVSS3.0

CVE-2024-4321 - Local File Inclusion (LFI) in gaizhenbiao/chuanhuchatgpt

A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the functionality for uploading chat history. The vulnerability arises due to improper input validation when handling file paths during the chat history upload process. An attacker c…

πŸ“… Published: May 16, 2024, 9:03 a.m. πŸ”„ Last Modified: July 10, 2025, 4:21 p.m.

7.5

CVSS3.0

CVE-2024-4322 - Path Traversal in parisneo/lollms-webui

A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personalities` endpoint. By manipulating the `category` parameter, an attacker can traverse the directory structure and list any directory on the system. This issue affects the latest vers…

πŸ“… Published: May 16, 2024, 9:03 a.m. πŸ”„ Last Modified: July 9, 2025, 2:32 p.m.

9.8

CVSS3.0

CVE-2024-2358 - Path Traversal leading to Remote Code Execution in parisneo/lollms-webui

A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary code. The vulnerability arises due to insufficient sanitization of user-supplied input in the configuration settings, specifically within the 'extensions' parameter. Attac…

πŸ“… Published: May 16, 2024, 9:03 a.m. πŸ”„ Last Modified: July 9, 2025, 2:39 p.m.

5.4

CVSS3.1

CVE-2024-3851 - Unrestricted File Upload Leading to XSS in imartinez/privategpt

A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper validation of file uploads. Attackers can exploit this vulnerability by uploading malicious HTML files, such as those containing JavaScript payloads, which are then executed in the cont…

πŸ“… Published: May 16, 2024, 9:03 a.m. πŸ”„ Last Modified: May 19, 2025, 4:13 p.m.

5.3

CVSS4.0

CVE-2024-4972 - code-projects Simple Chat System login.php sql injection

A vulnerability classified as critical has been found in code-projects Simple Chat System 1.0. This affects an unknown part of the file /login.php. The manipulation of the argument email/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed …

πŸ“… Published: May 16, 2024, 9 a.m. πŸ”„ Last Modified: Feb. 18, 2025, 6:38 p.m.
Total resulsts: 344980
Page 9416 of 34,498
Β« previous page Β» next page
Filters