CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9437
7.5 HIGH

SuperAGI version v0.0.14 is vulnerable to an unauthenticated Denial of Service (DoS) attack. The vulnerability exists in the resource upload request, where appending characters, such …

Mar 20, 2025
CVE-2024-9431
8.8 HIGH

In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After logging into the system, users can change the passwords of other users, …

Mar 20, 2025
CVE-2024-9418
6.5 MEDIUM

In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns the user's password in plaintext. This vulnerability allows an attacker to retrieve the password of …

Mar 20, 2025
CVE-2024-9415
8.8 HIGH

A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. This vulnerability allows an attacker to upload an arbitrary file to …

Mar 20, 2025
CVE-2024-9365
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability in polyaxon/polyaxon v2.4.0 allows attackers to perform unauthorized actions in the context of the victim's browser. This includes creating …

Mar 20, 2025
CVE-2024-9363
7.5 HIGH

An unauthorized file deletion vulnerability exists in the latest version of the Polyaxon platform, which can lead to denial of service by terminating critical containers. …

Mar 20, 2025
CVE-2024-9362
7.5 HIGH

An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version. This vulnerability allows an attacker to retrieve directory information and file contents from …

Mar 20, 2025
CVE-2024-9340
7.5 HIGH

A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause excessive resource consumption by sending malformed multipart requests with arbitrary …

Mar 20, 2025
CVE-2024-9311
6.1 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload files with malicious content without authentication or user interaction. The …

Mar 20, 2025
CVE-2024-9309
9.3 CRITICAL

A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in haotian-liu/llava version v1.2.0 (LLaVA-1.6). This vulnerability …

Mar 20, 2025
CVE-2024-9308
6.1 MEDIUM

An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. …

Mar 20, 2025
CVE-2024-9229
7.5 HIGH

A Denial of Service (DoS) vulnerability in the file upload feature of stangirard/quivr v0.0.298 allows unauthenticated attackers to cause excessive resource consumption by appending characters …

Mar 20, 2025
CVE-2024-9216
8.1 HIGH

An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to read and delete other users' chat history. The vulnerability arises …

Mar 20, 2025
CVE-2024-9159
6.5 MEDIUM

An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the server at will, leading to a complete …

Mar 20, 2025
CVE-2024-9107
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version git 20b2e02. The vulnerability arises from improper sanitization of HTML tags in …

Mar 20, 2025
CVE-2024-9099
8.1 HIGH

In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all projects to users with minimal permissions, such …

Mar 20, 2025
CVE-2024-9098
6.1 MEDIUM

In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new members with billing permissions, thereby gaining unauthorized access to billing …

Mar 20, 2025
CVE-2024-9096
7.1 HIGH

In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending a PATCH request. The route lacks proper access control, such …

Mar 20, 2025
CVE-2024-9095
9.8 CRITICAL

In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to create a Datastream to Google BigQuery and export …

Mar 20, 2025
CVE-2024-9070
9.8 CRITICAL

A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting specific parameters, an attacker can execute unauthorized arbitrary code on the …

Mar 20, 2025
CVE-2024-9056
7.5 HIGH

BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by appending characters, such as dashes (-), to …

Mar 20, 2025
CVE-2024-9053
9.8 CRITICAL

vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core functionality run_server_loop() calls the function _make_handler_coro(), which directly uses cloudpickle.loads() …

Mar 20, 2025
CVE-2024-9052

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 20, 2025
CVE-2024-9000
6.5 MEDIUM

In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists without validating whether the user has proper permissions. This missing …

Mar 20, 2025
CVE-2024-8999
7.5 HIGH

lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bigquery endpoint. This vulnerability allows any user to export the entire database data …

Mar 20, 2025
CVE-2024-8998
7.5 HIGH

A Regular Expression Denial of Service (ReDoS) vulnerability exists in lunary-ai/lunary version git f07a845. The server uses the regex /{.*?}/ to match user-controlled strings. In …

Mar 20, 2025
CVE-2024-8984
7.5 HIGH

A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited by appending characters, such as dashes (-), to the …

Mar 20, 2025
CVE-2024-8982
6.2 MEDIUM

A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local server through the web application. This flaw …

Mar 20, 2025
CVE-2024-8966
7.5 HIGH

A vulnerability in the file upload process of gradio-app/gradio version @gradio/[email protected] allows for a Denial of Service (DoS) attack. An attacker can append a large …

Mar 20, 2025
CVE-2024-8958
9.8 CRITICAL

In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an …

Mar 20, 2025
CVE-2024-8955
7.5 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the contents of any file in the …

Mar 20, 2025
CVE-2024-8954
9.8 CRITICAL

In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authentication step. This vulnerability allows an attacker to bypass authentication …

Mar 20, 2025
CVE-2024-8953
9.8 CRITICAL

In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted …

Mar 20, 2025
CVE-2024-8952
7.5 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCRAPE_WEBSITE_CONTENT endpoint. This vulnerability allows an attacker to read files, access …

Mar 20, 2025
CVE-2024-8898
9.8 CRITICAL

A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete …

Mar 20, 2025
CVE-2024-8859
7.5 HIGH

A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol …

Mar 20, 2025
CVE-2024-8789
7.5 HIGH

Lunary-ai/lunary version git 105a3f6 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. The application allows users to upload their own regular expressions, …

Mar 20, 2025
CVE-2024-8769
9.1 CRITICAL

A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path traversal. The `run_hash` parameter, which is user-controllable, …

Mar 20, 2025
CVE-2024-8765
7.3 HIGH

In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies certain endpoints as public if the path contains '/auth/' …

Mar 20, 2025
CVE-2024-8764
7.5 HIGH

A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute arbitrary regular expressions on the server side. This can lead to …

Mar 20, 2025
CVE-2024-8763
7.5 HIGH

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary repository, specifically in the compileTextTemplate function. The affected version is git be54057. An …

Mar 20, 2025
CVE-2024-8736
6.5 MEDIUM

A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). The vulnerability can be exploited remotely via Cross-Site …

Mar 20, 2025
CVE-2024-8616
8.2 HIGH

In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target server. The vulnerability arises from the `exportModelDetails` function in `ModelsHandler.java`, …

Mar 20, 2025
CVE-2024-8613
8.8 HIGH

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling of …

Mar 20, 2025
CVE-2024-8581
9.1 CRITICAL

A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the system. The function does …

Mar 20, 2025
CVE-2024-8556
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view …

Mar 20, 2025
CVE-2024-8551
9.1 CRITICAL

A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacker to read …

Mar 20, 2025
CVE-2024-8537
9.1 CRITICAL

A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete …

Mar 20, 2025
CVE-2024-8524
7.5 HIGH

A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted …

Mar 20, 2025
CVE-2024-8502
9.8 CRITICAL

A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (RCE) via deserialization of untrusted data using the dill library. The …

Mar 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.