6.5

CVSS3.1

CVE-2024-2035 - Improper Authorization in zenml-io/zenml

An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1/users/id endpoint. This vulnerability allows any authenticated user to modify the information of other users, including changing the `active` status of user accounts to false, ef…

πŸ“… Published: June 6, 2024, 6:25 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 2:13 p.m.

8.3

CVSS3.1

CVE-2024-2288 - CSRF File Upload Vulnerability in parisneo/lollms-webui

A Cross-Site Request Forgery (CSRF) vulnerability exists in the profile picture upload functionality of the Lollms application, specifically in the parisneo/lollms-webui repository, affecting versions up to 7.3.0. This vulnerability allows attackers to change a victim's profile picture without thei…

πŸ“… Published: June 6, 2024, 6:24 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 12:50 p.m.

5.4

CVSS3.1

CVE-2024-3402 - Stored XSS vulnerability in gaizhenbiao/chuanhuchatgpt

A stored Cross-Site Scripting (XSS) vulnerability existed in version (20240121) of gaizhenbiao/chuanhuchatgpt due to inadequate sanitization and validation of model output data. Despite user-input validation efforts, the application fails to properly sanitize or validate the output from the model, …

πŸ“… Published: June 6, 2024, 6:24 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:29 a.m.

4.9

CVSS3.1

CVE-2024-4890 - Blind SQL Injection in berriai/litellm

A blind SQL injection vulnerability exists in the berriai/litellm application, specifically within the '/team/update' process. The vulnerability arises due to the improper handling of the 'user_id' parameter in the raw SQL query used for deleting users. An attacker can exploit this vulnerability by…

πŸ“… Published: June 6, 2024, 6:23 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:43 a.m.

9.6

CVSS3.1

CVE-2024-3166 - Cross-Site Scripting (XSS) Vulnerability in mintplex-labs/anything-llm

A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest version of the web application. The vulnerability arises from the application's feature to fetch and embed content from websites into workspaces, whic…

πŸ“… Published: June 6, 2024, 6:23 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:29 a.m.

9.8

CVSS3.1

CVE-2024-4320 - Remote Code Execution due to LFI in '/install_extension' in parisneo/lollms-webui

A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_extension")` route handler. The vulnerability arises due to improper handling of the `name` parameter in the `ExtensionBu…

πŸ“… Published: June 6, 2024, 6:22 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:42 a.m.

4.8

CVSS3.1

CVE-2024-2171 - Stored XSS in zenml-io/zenml

A stored Cross-Site Scripting (XSS) vulnerability was identified in the zenml-io/zenml repository, specifically within the 'logo_url' field. By injecting malicious payloads into this field, an attacker could send harmful messages to other users, potentially compromising their accounts. The vulnerab…

πŸ“… Published: June 6, 2024, 6:22 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:09 a.m.

8.1

CVSS3.1

CVE-2024-5133 - Account Takeover via Exposed Recovery Token in lunary-ai/lunary

In lunary-ai/lunary version 1.2.4, an account takeover vulnerability exists due to the exposure of password recovery tokens in API responses. Specifically, when a user initiates the password reset process, the recovery token is included in the response of the `GET /v1/users/me/org` endpoint, which …

πŸ“… Published: June 6, 2024, 6:21 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 12:49 p.m.

7.8

CVSS3.1

CVE-2024-30373 - Kofax Power PDF JPF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Kofax Power PDF JPF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a mal…

πŸ“… Published: June 6, 2024, 6:20 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:11 a.m.

9.8

CVSS3.1

CVE-2024-3234 - Path Traversal in gaizhenbiao/chuanhuchatgpt

The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The application is designed to restrict user access to resources within the `web_assets` folder. However, the outdated version of gradio it employs is susceptible to p…

πŸ“… Published: June 6, 2024, 6:20 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:29 a.m.
Total resulsts: 349182
Page 9561 of 34,919
Β« previous page Β» next page
Filters