7.5

CVSS3.0

CVE-2024-12766 - SSRF in parisneo/lollms-webui

parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST /api/proxy` REST API. Attackers can exploit this vulnerability to abuse the victim server's credentials to access unauthorized web resources by specifying the JSON parameter `{"u…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: July 8, 2025, 4:24 p.m.

8.1

CVSS3.1

CVE-2024-7767 - Improper Access Control in danswer-ai/danswer

An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system to view, modify, and delete chats created by an Admin. This can lead to unauthorized access to sensitive information, loss of data integrity, and pot…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

4.3

CVSS3.1

CVE-2024-12869 - Improper Authentication in infiniflow/ragflow

In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a privacy breach where users' personal or private information, such as email addresses or usernames in the invite list, could be exposed w…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

6.5

CVSS3.1

CVE-2024-11300 - Improper Access Control in lunary-ai/lunary

In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The vulnerability allows unauthorized users to view sensitive prompt data by accessing specific URLs, …

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

8.2

CVSS3.0

CVE-2024-10830 - Path Traversal in eosphoros-ai/db-gpt

A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/delete`. This vulnerability allows an attacker to delete any file on the server by manipulating the `file_key` parameter. The `file_key` parameter is not properly sanitized, enablin…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: July 17, 2025, 1:37 p.m.

7.5

CVSS3.1

CVE-2024-8524 - Directory Traversal in modelscope/agentscope

A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted POST request to the /read-examples endpoint.

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

9.1

CVSS3.0

CVE-2024-5752 - Path Traversal in stitionai/devika

A path traversal vulnerability exists in stitionai/devika, specifically in the project creation functionality. In the affected version beacf6edaa205a5a5370525407a6db45137873b3, the project name is not validated, allowing an attacker to create a project with a crafted name that traverses directories…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-8736 - Denial of Service (DoS) via Multipart Boundary in parisneo/lollms-webui

A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). The vulnerability can be exploited remotely via Cross-Site Request Forgery (CSRF). Despite CSRF protection preventing file uploads, the application still processes mul…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 4, 2025, 9:15 a.m.

7.5

CVSS3.0

CVE-2024-12070 - Denial of Service in haotian-liu/llava

A Denial of Service (DoS) vulnerability exists in the file upload feature of haotian-liu/llava, specifically in Release v1.2.0 (LLaVA-1.6). The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large fil…

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: July 14, 2025, 5:45 p.m.

9.8

CVSS3.1

CVE-2024-8958 - Unrestricted File Write and Read in composiohq/composio

In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially leading to privilege escalation or remote code execution.

πŸ“… Published: March 20, 2025, 10:11 a.m. πŸ”„ Last Modified: April 1, 2025, 8:30 p.m.
Total resulsts: 348147
Page 6164 of 34,815
Β« previous page Β» next page
Filters