7.5

CVSS3.1

CVE-2024-7962 - Arbitrary File Read via Insufficient Validation in gaizhenbiao/chuanhuchatgpt

An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read any file that matches specific criteria using an absolute path. The file must not have a .json extension and, except for…

πŸ“… Published: Oct. 29, 2024, 12:47 p.m. πŸ”„ Last Modified: Nov. 1, 2024, 2:19 p.m.

9.8

CVSS3.1

CVE-2024-6868 - Arbitrary File Write in mudler/LocalAI

mudler/LocalAI version 2.17.1 allows for arbitrary file write due to improper handling of automatic archive extraction. When model configurations specify additional files as archives (e.g., .tar), these archives are automatically extracted after downloading. This behavior can be exploited to perfor…

πŸ“… Published: Oct. 29, 2024, 12:46 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.1

CVSS3.1

CVE-2024-6674 - Data Leak through CORS Misconfiguration in parisneo/lollms-webui

A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, suc…

πŸ“… Published: Oct. 29, 2024, 12:46 p.m. πŸ”„ Last Modified: Nov. 1, 2024, 8:34 p.m.

8.1

CVSS3.1

CVE-2024-7474 - IDOR in lunary-ai/lunary

In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view or delete external users by manipulating the 'id' parameter in the request URL. The application does not perform adequate checks on the 'id' parameter, allowing unauthorized access…

πŸ“… Published: Oct. 29, 2024, 12:46 p.m. πŸ”„ Last Modified: Jan. 9, 2025, 6:15 p.m.

9.1

CVSS3.1

CVE-2024-5982 - Path Traversal in gaizhenbiao/chuanhuchatgpt

A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from unsanitized input handling in multiple features, including user upload, directory creation, and template loading. Specifically, the load_chat_history function in modules/models/b…

πŸ“… Published: Oct. 29, 2024, 12:46 p.m. πŸ”„ Last Modified: Nov. 14, 2024, 6:52 p.m.

9.1

CVSS3.1

CVE-2024-7475 - Improper Access Control in lunary-ai/lunary

An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation of authentication processes, fraudulent login requests, and theft of user information. Appropriate access…

πŸ“… Published: Oct. 29, 2024, 12:45 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 2:10 p.m.

2.7

CVSS3.1

CVE-2024-41156 -

Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers valuable configuration information about the Tropos network. Profiles can only be exported by authenticated users with higher privilege of write access.

πŸ“… Published: Oct. 29, 2024, 12:44 p.m. πŸ”„ Last Modified: Jan. 9, 2025, 5:15 p.m.

6.1

CVSS3.1

CVE-2024-49638 - WordPress Risk Warning Bar plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ventureharbour Risk Warning Bar risk-warning-bar allows Reflected XSS.This issue affects Risk Warning Bar: from n/a through <= 1.0.

πŸ“… Published: Oct. 29, 2024, 12:42 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

6.1

CVSS3.1

CVE-2024-49639 - WordPress Monitor.chat plugin <= 1.1.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Stoever Monitor.chat monitor-chat allows Reflected XSS.This issue affects Monitor.chat: from n/a through <= 1.1.1.

πŸ“… Published: Oct. 29, 2024, 12:40 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

6.1

CVSS3.1

CVE-2024-49640 - WordPress ACL Floating Cart for WooCommerce plugin <= 0.9 - Reflected Cross Site Scripting (XSS) vu…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AmaderCode Lab ACL Floating Cart for WooCommerce acl-floating-cart-for-woocommerce allows Reflected XSS.This issue affects ACL Floating Cart for WooCommerce: from n/a through <= 0.9.

πŸ“… Published: Oct. 29, 2024, 12:39 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.
Total resulsts: 344072
Page 7586 of 34,408
Β« previous page Β» next page
Filters