5.3

CVSS3.1

CVE-2024-5550 - Exposure of Sensitive Information via Arbitrary System Path Lookup in h2oai/h2o-3

In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system path lookup feature. This vulnerability allows any remote user to view full paths in the entire file system where h2o-3 is hosted. Specifically, the issue resides in the Typeahead A…

πŸ“… Published: June 6, 2024, 6:18 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

6.1

CVSS3.1

CVE-2024-2383 - Clickjacking Vulnerability in zenml-io/zenml

A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. This vulnerability allows an attacker to embed the application UI within an iframe on a malicious pa…

πŸ“… Published: June 6, 2024, 6:18 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:09 a.m.

7.5

CVSS3.1

CVE-2024-4881 - Path Traversal in parisneo/lollms

A path traversal vulnerability exists in the parisneo/lollms application, affecting version 9.4.0 and potentially earlier versions, but fixed in version 5.9.0. The vulnerability arises due to improper validation of file paths between Windows and Linux environments, allowing attackers to traverse be…

πŸ“… Published: June 6, 2024, 6:17 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:43 a.m.

6.8

CVSS3.1

CVE-2024-37364 -

Ariane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attackers to obtain sensitive information (such as hotel invoice content with PII), and potentially create unauthorized room keys, by entering a guest-search quote character and then a…

πŸ“… Published: June 6, 2024, 6:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2024-32873 - evmos allows transferring unvested tokens after delegations

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly when delegating vested tokens. The issue allows a clawback vesting account to anticipate the release of unvested tokens. This vulnerability is fixed in 18.0.0.

πŸ“… Published: June 6, 2024, 6:13 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:15 a.m.

9.8

CVSS3.1

CVE-2024-2624 - Path Traversal and Arbitrary File Upload Vulnerability in parisneo/lollms-webui

A path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically within the `@router.get("/switch_personal_path")` endpoint in `./lollms-webui/lollms_core/lollms/server/endpoints/lollms_user.py`. The vulnerability arises due to insufficient sani…

πŸ“… Published: June 6, 2024, 6:11 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:10 a.m.

8.7

CVSS3.1

CVE-2024-3110 - Stored XSS leading to admin account takeover in mintplex-labs/anything-llm

A stored Cross-Site Scripting (XSS) vulnerability exists in the mintplex-labs/anything-llm application, affecting versions up to and including the latest before 1.0.0. The vulnerability arises from the application's failure to properly sanitize and validate user-supplied URLs before embedding them …

πŸ“… Published: June 6, 2024, 6:11 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:28 a.m.

6.5

CVSS3.1

CVE-2024-5126 - Improper Access Control in lunary-ai/lunary

An improper access control vulnerability exists in the lunary-ai/lunary repository, specifically within the versions.patch functionality for updating prompts. Affected versions include 1.2.2 up to but not including 1.2.25. The vulnerability allows unauthorized users to update prompt details due to …

πŸ“… Published: June 6, 2024, 6:11 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.1

CVE-2024-5552 - ReDoS in kubeflow/kubeflow

kubeflow/kubeflow is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to inefficient regular expression complexity in its email validation mechanism. An attacker can remotely exploit this vulnerability without authentication by providing specially crafted input that causes th…

πŸ“… Published: June 6, 2024, 6:09 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.

8.8

CVSS3.1

CVE-2024-5128 - IDOR Vulnerability in lunary-ai/lunary

An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2. This vulnerability allows unauthorized users to view, update, or delete any dataset_prompt or dataset_prompt_variation within any dataset or project. The issue …

πŸ“… Published: June 6, 2024, 6:08 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.
Total resulsts: 349182
Page 9563 of 34,919
Β« previous page Β» next page
Filters