7.5

CVSS3.1

CVE-2024-5124 - Timing Attack Vulnerability in gaizhenbiao/chuanhuchatgpt

A timing attack vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, specifically within the password comparison logic. The vulnerability is present in version 20240310 of the software, where passwords are compared using the '=' operator in Python. This method of comparison allows an …

πŸ“… Published: June 6, 2024, 6:54 p.m. πŸ”„ Last Modified: May 20, 2025, 2:04 p.m.

9.3

CVSS3.1

CVE-2024-5328 - SSRF Vulnerability in lunary-ai/lunary

A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the endpoint '/auth/saml/tto/download-idp-xml'. The vulnerability arises due to the application's failure to validate user-supplied URLs before using them in server-side requests. An a…

πŸ“… Published: June 6, 2024, 6:53 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.

8.8

CVSS3.1

CVE-2024-3150 - Privilege Escalation in mintplex-labs/anything-llm

In mintplex-labs/anything-llm, a vulnerability exists in the thread update process that allows users with Default or Manager roles to escalate their privileges to Administrator. The issue arises from improper input validation when handling HTTP POST requests to the endpoint `/workspace/:slug/thread…

πŸ“… Published: June 6, 2024, 6:53 p.m. πŸ”„ Last Modified: Jan. 9, 2025, 9:47 p.m.

7.5

CVSS3.1

CVE-2024-36732 -

An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.tensordot.

πŸ“… Published: June 6, 2024, 6:51 p.m. πŸ”„ Last Modified: May 2, 2025, 12:50 p.m.

7.5

CVSS3.1

CVE-2024-37153 - Evmos's contract balance not updating correctly after interchain transaction

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. There is an issue with how to liquid stake using Safe which itself is a contract. The bug only appears when there is a local state change together with an ICS20 transfer in the same function and uses the contract's balance, that…

πŸ“… Published: June 6, 2024, 6:51 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:23 a.m.

6.5

CVSS3.1

CVE-2024-5248 - Improper Access Control in lunary-ai/lunary

In lunary-ai/lunary version 1.2.5, an improper access control vulnerability exists due to a missing permission check in the `GET /v1/users/me/org` endpoint. The platform's role definitions restrict the `Prompt Editor` role to prompt management and project viewing/listing capabilities, explicitly ex…

πŸ“… Published: June 6, 2024, 6:49 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.

3.1

CVSS3.1

CVE-2024-2032 - Race Condition Vulnerability in zenml-io/zenml

A race condition vulnerability exists in zenml-io/zenml versions up to and including 0.55.3, which allows for the creation of multiple users with the same username when requests are sent in parallel. This issue was fixed in version 0.55.5. The vulnerability arises due to insufficient handling of co…

πŸ“… Published: June 6, 2024, 6:49 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:08 a.m.

8.2

CVSS3.1

CVE-2023-45192 - IBM Engineering Requirements Management DOORS Next XML external entity injection

IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 268758.

πŸ“… Published: June 6, 2024, 6:49 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:26 a.m.

8.8

CVSS3.1

CVE-2024-5187 - Arbitrary File Overwrite in download_model_with_test_data in onnx/onnx

A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability enables attackers to overwrite any file on the system, po…

πŸ“… Published: June 6, 2024, 6:45 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.

6.5

CVSS3.1

CVE-2024-3404 - Improper Access Control in gaizhenbiao/chuanhuchatgpt

In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. This flaw allows an authenticated attacker to bypass intended access restrictions and read the `history` files of other users, potentially leading to u…

πŸ“… Published: June 6, 2024, 6:45 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.
Total resulsts: 348200
Page 9460 of 34,820
Β« previous page Β» next page
Filters