7.5

CVSS3.1

CVE-2024-36740 -

An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index as a negative number exceeds the range of size.

πŸ“… Published: June 6, 2024, 6:40 p.m. πŸ”„ Last Modified: May 1, 2025, 7:51 p.m.

9.1

CVSS3.1

CVE-2024-1873 - Path Traversal and Denial of Service in parisneo/lollms-webui

parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database` endpoint in version a9d16b0. The endpoint improperly handles file paths, allowing attackers to specify absolute paths when interacting with the `DiscussionsDB` instance. This fla…

πŸ“… Published: June 6, 2024, 6:40 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.7

CVSS3.1

CVE-2024-4851 - SSRF Vulnerability in stangirard/quivr

A Server-Side Request Forgery (SSRF) vulnerability exists in the stangirard/quivr application, version 0.0.204, which allows attackers to access internal networks. The vulnerability is present in the crawl endpoint where the 'url' parameter can be manipulated to send HTTP requests to arbitrary URLs…

πŸ“… Published: June 6, 2024, 6:39 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:43 a.m.

7.8

CVSS3.1

CVE-2024-1880 - OS Command Injection in MacOS Text-To-Speech Class in significant-gravitas/autogpt

An OS command injection vulnerability exists in the MacOS Text-To-Speech class MacOSTTS of the significant-gravitas/autogpt project, affecting versions up to v0.5.0. The vulnerability arises from the improper neutralization of special elements used in an OS command within the `_speech` method of th…

πŸ“… Published: June 6, 2024, 6:39 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 3:35 p.m.

6.5

CVSS3.1

CVE-2024-5131 - Improper Access Control in lunary-ai/lunary

An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and including 1.2.2. The vulnerability allows unauthorized users to view any prompts in any projects by supplying a specific prompt ID to an endpoint that does not adequately verify the owne…

πŸ“… Published: June 6, 2024, 6:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.

8.1

CVSS3.1

CVE-2024-4888 - Arbitrary File Deletion in BerriAI/litellm

BerriAI's litellm, in its latest version, is vulnerable to arbitrary file deletion due to improper input validation on the `/audio/transcriptions` endpoint. An attacker can exploit this vulnerability by sending a specially crafted request that includes a file path to the server, which then deletes …

πŸ“… Published: June 6, 2024, 6:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:43 a.m.

0.0

CVE-2024-5132 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: June 6, 2024, 6:30 p.m. πŸ”„ Last Modified: June 7, 2024, 5:15 p.m.

7.5

CVSS3.1

CVE-2024-2928 - Local File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflow

A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../'. An attacker can …

πŸ“… Published: June 6, 2024, 6:29 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:10 a.m.

7.7

CVSS3.1

CVE-2024-3095 - SSRF in Langchain Web Research Retriever in langchain-ai/langchain

A Server-Side Request Forgery (SSRF) vulnerability exists in the Web Research Retriever component of langchain-ai/langchain version 0.1.5. The vulnerability arises because the Web Research Retriever does not restrict requests to remote internet addresses, allowing it to reach local addresses. This …

πŸ“… Published: June 6, 2024, 6:28 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:28 a.m.

8.2

CVSS3.1

CVE-2024-5129 - Privilege Escalation Vulnerability in lunary-ai/lunary

A Privilege Escalation Vulnerability exists in lunary-ai/lunary version 1.2.2, where any user can delete any datasets due to missing authorization checks. The vulnerability is present in the dataset deletion functionality, where the application fails to verify if the user requesting the deletion ha…

πŸ“… Published: June 6, 2024, 6:28 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.
Total resulsts: 349182
Page 9560 of 34,919
Β« previous page Β» next page
Filters