7.5

CVSS3.1

CVE-2024-36734 -

Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the dim parameter.

πŸ“… Published: June 6, 2024, 6:44 p.m. πŸ”„ Last Modified: May 2, 2025, 12:49 p.m.

8.8

CVSS3.1

CVE-2024-3149 - SSRF in mintplex-labs/anything-llm

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex-labs/anything-llm. This feature, intended for users with manager or admin roles, processes uploaded links through an internal Collector API using a headless browser. An attacker can exploit this by host…

πŸ“… Published: June 6, 2024, 6:43 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:29 a.m.

7.5

CVSS3.1

CVE-2024-5130 - Incorrect Authorization in lunary-ai/lunary

An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete any dataset. The vulnerability is due to the lack of proper authorization checks in the dataset deletion endpoint. Specifically, the endpoint does not…

πŸ“… Published: June 6, 2024, 6:43 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

5.3

CVSS3.1

CVE-2024-36735 -

OneFlow-Inc. Oneflow v0.9.1 does not display an error or warning when the oneflow.eye parameter is floating.

πŸ“… Published: June 6, 2024, 6:41 p.m. πŸ”„ Last Modified: March 27, 2025, 7:15 p.m.

6.5

CVSS3.1

CVE-2024-3153 - Uncontrolled Resource Consumption in mintplex-labs/anything-llm

mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of service (DOS) condition. Specifically, the server can be shut down by sending an invalid upload request. An attacker with the ability to upload documents …

πŸ“… Published: June 6, 2024, 6:40 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:29 a.m.

9.8

CVSS3.1

CVE-2024-3322 - Path Traversal in parisneo/lollms-webui

A path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui, affecting versions up to 9.5. The vulnerability arises from the improper limitation of a pathname to a restricted directory in the 'process_folder' function within 'lollms-webui/…

πŸ“… Published: June 6, 2024, 6:40 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:29 a.m.

7.5

CVSS3.1

CVE-2024-36740 -

An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index as a negative number exceeds the range of size.

πŸ“… Published: June 6, 2024, 6:40 p.m. πŸ”„ Last Modified: May 1, 2025, 7:51 p.m.

9.1

CVSS3.1

CVE-2024-1873 - Path Traversal and Denial of Service in parisneo/lollms-webui

parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database` endpoint in version a9d16b0. The endpoint improperly handles file paths, allowing attackers to specify absolute paths when interacting with the `DiscussionsDB` instance. This fla…

πŸ“… Published: June 6, 2024, 6:40 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.7

CVSS3.1

CVE-2024-4851 - SSRF Vulnerability in stangirard/quivr

A Server-Side Request Forgery (SSRF) vulnerability exists in the stangirard/quivr application, version 0.0.204, which allows attackers to access internal networks. The vulnerability is present in the crawl endpoint where the 'url' parameter can be manipulated to send HTTP requests to arbitrary URLs…

πŸ“… Published: June 6, 2024, 6:39 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:43 a.m.

7.8

CVSS3.1

CVE-2024-1880 - OS Command Injection in MacOS Text-To-Speech Class in significant-gravitas/autogpt

An OS command injection vulnerability exists in the MacOS Text-To-Speech class MacOSTTS of the significant-gravitas/autogpt project, affecting versions up to v0.5.0. The vulnerability arises from the improper neutralization of special elements used in an OS command within the `_speech` method of th…

πŸ“… Published: June 6, 2024, 6:39 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 3:35 p.m.
Total resulsts: 348208
Page 9462 of 34,821
Β« previous page Β» next page
Filters