9.0

CVSS3.1

CVE-2024-7053 - Session Fixation in open-webui/open-webui

A vulnerability in open-webui/open-webui version 0.3.8 allows an attacker with a user-level account to perform a session fixation attack. The session cookie for all users is set with the default `SameSite=Lax` and does not have the `Secure` flag enabled, allowing the session cookie to be sent over โ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:11 a.m. ๐Ÿ”„ Last Modified: April 1, 2025, 8:33 p.m.

7.5

CVSS3.1

CVE-2024-11030 - SSRF in binary-husky/gpt_academic

GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plugin function, which calls the crazy_utils.get_files_from_everything() API without proper sanitization. This allows attackers to exploit the vulnerability to abuse the victim GPT Acโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:11 a.m. ๐Ÿ”„ Last Modified: July 14, 2025, 4:40 p.m.

7.5

CVSS3.1

CVE-2024-12720 - Regular Expression Denial of Service (ReDoS) in huggingface/transformers

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file tokenization_nougat_fast.py. The vulnerability occurs in the post_process_single() function, where a regular expression processes specially crafted input. Thโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:11 a.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 9:11 p.m.

5.9

CVSS3.0

CVE-2024-12777 - Denial of Service in aimhubio/aim

A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is single-threaded, can be made unresponsive by requesting it to connect to an unresponsive socket via sshfs. The lack of an additional timeout setting inโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:11 a.m. ๐Ÿ”„ Last Modified: July 18, 2025, 8:01 p.m.

9.1

CVSS3.1

CVE-2024-4990 - Unsafe Reflection in base Component class in yiisoft/yii2

In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that the value passed is a valid Behavior class name or configuration. This allows an attacker to instantiate arbitrary classes, passing parameters to their constructโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:11 a.m. ๐Ÿ”„ Last Modified: April 1, 2025, 8:34 p.m.

7.5

CVSS3.0

CVE-2024-11043 - Denial of Service (DoS) via Large Payload in Board Name Field in invoke-ai/invokeai

A Denial of Service (DoS) vulnerability was discovered in the /api/v1/boards/{board_id} endpoint of invoke-ai/invokeai version v5.0.2. This vulnerability occurs when an excessively large payload is sent in the board_name field during a PATCH request. By sending a large payload, the UI becomes unresโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:11 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2024-8053 - Improper Authentication in open-webui/open-webui

In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This vulnerability can be exploited by sending a POST request with an excessively large payload, potentially leadingโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:11 a.m. ๐Ÿ”„ Last Modified: March 27, 2025, 11:15 a.m.

6.1

CVSS3.1

CVE-2024-8021 - Open Redirect in gradio-app/gradio

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect to an attacker-contโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:11 a.m. ๐Ÿ”„ Last Modified: March 26, 2025, 4:39 p.m.

0.0

CVE-2025-0655 -

** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-55890. Notes: All CVE users should reference CVE-2024-55890 instead of this CVE Record. All references and descriptions in this candidate have been removed to prevent accidental usage.

๐Ÿ“… Published: March 20, 2025, 10:11 a.m. ๐Ÿ”„ Last Modified: April 15, 2025, 4:15 p.m.

5.4

CVSS3.1

CVE-2024-8400 - Stored XSS in gaizhenbiao/chuanhuchatgpt

A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability allows an attacker to upload a malicious HTML file containing JavaScript code, which is then executed when the file is accessed. This can lead to the execution of arbitrarโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:11 a.m. ๐Ÿ”„ Last Modified: April 1, 2025, 8:32 p.m.
Total resulsts: 348147
Page 6165 of 34,815
ยซ previous page ยป next page
Filters