CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8501
8.8 HIGH

An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0.4. This vulnerability allows any user to download any file from the …

Mar 20, 2025
CVE-2024-8489
8.8 HIGH

A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to overly permissive CORS headers. This issue …

Mar 20, 2025
CVE-2024-8487
9.8 CRITICAL

A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configuration on the agentscope server does not properly restrict access to only …

Mar 20, 2025
CVE-2024-8438
7.5 HIGH

A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not properly sanitize the `path` parameter, allowing an attacker to read …

Mar 20, 2025
CVE-2024-8400
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability allows an attacker to upload a malicious HTML file containing …

Mar 20, 2025
CVE-2024-8251
5.3 MEDIUM

A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in the API endpoint "/embed/:embedId/stream-chat" where user-provided JSON is directly …

Mar 20, 2025
CVE-2024-8249
7.5 HIGH

mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the API for the embeddable chat functionality. An attacker can exploit this …

Mar 20, 2025
CVE-2024-8248
7.2 HIGH

A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversal, leading to arbitrary file read and write in the storage …

Mar 20, 2025
CVE-2024-8238
8.1 HIGH

In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function from RestrictedPython. This version does not protect against …

Mar 20, 2025
CVE-2024-8196
9.8 CRITICAL

In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker …

Mar 20, 2025
CVE-2024-8183
7.6 HIGH

A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains to access sensitive data. This vulnerability can lead to unauthorized access to …

Mar 20, 2025
CVE-2024-8156
9.8 CRITICAL

A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt. The untrusted user input `github.head.ref` is used insecurely, allowing an attacker to inject arbitrary …

Mar 20, 2025
CVE-2024-8101
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. The vulnerability arises due to the use of `dangerouslySetInnerHTML` …

Mar 20, 2025
CVE-2024-8099
8.3 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of vanna-ai/vanna when using DuckDB as the database. An attacker can exploit this vulnerability …

Mar 20, 2025
CVE-2024-8065
8.1 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability in version v1.4.1 of danswer-ai/danswer allows attackers to perform unauthorized actions in the context of the victim's browser. This …

Mar 20, 2025
CVE-2024-8063
7.5 HIGH

A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the …

Mar 20, 2025
CVE-2024-8062
7.5 HIGH

A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a `HEAD` request to verify the …

Mar 20, 2025
CVE-2024-8061
7.5 HIGH

In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indefinitely for …

Mar 20, 2025
CVE-2024-8060
8.1 HIGH

OpenWebUI version 0.3.0 contains a vulnerability in the audio API endpoint `/audio/api/v1/transcriptions` that allows for arbitrary file upload. The application performs insufficient validation on the …

Mar 20, 2025
CVE-2024-8057
4.3 MEDIUM

In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them to an existing connector. This issue arises …

Mar 20, 2025
CVE-2024-8055
7.5 HIGH

Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations using the `PUT` and `COPY` commands. This vulnerability allows unauthenticated …

Mar 20, 2025
CVE-2024-8053
8.2 HIGH

In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This vulnerability can be exploited …

Mar 20, 2025
CVE-2024-8029
6.1 MEDIUM

An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims click …

Mar 20, 2025
CVE-2024-8028
7.5 HIGH

A vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to cause a Denial of Service (DoS) by uploading a file with a malformed multipart boundary. By …

Mar 20, 2025
CVE-2024-8027
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability exists in netease-youdao/QAnything. Attackers can upload malicious knowledge files to the knowledge base, which can trigger XSS attacks during …

Mar 20, 2025
CVE-2024-8026
8.1 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The backend server has overly permissive CORS headers, …

Mar 20, 2025
CVE-2024-8024
7.5 HIGH

A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an attacker to bypass the Same-Origin Policy, potentially leading to sensitive information exposure. …

Mar 20, 2025
CVE-2024-8021
6.1 MEDIUM

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL …

Mar 20, 2025
CVE-2024-8020
7.5 HIGH

A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoint …

Mar 20, 2025
CVE-2024-8019
9.1 CRITICAL

In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an …

Mar 20, 2025
CVE-2024-8018
7.5 HIGH

A vulnerability in imartinez/privategpt version 0.5.0 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number …

Mar 20, 2025
CVE-2024-8017
9.0 CRITICAL

An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the HTML for tooltips. This vulnerability allows attackers to perform …

Mar 20, 2025
CVE-2024-7990
8.4 HIGH

A stored cross-site scripting (XSS) vulnerability exists in open-webui/open-webui version 0.3.8. The vulnerability is present in the `/api/v1/models/add` endpoint, where the model description field is …

Mar 20, 2025
CVE-2024-7983
7.5 HIGH

In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A maliciously crafted markdown payload can cause the server …

Mar 20, 2025
CVE-2024-7959
7.7 HIGH

The `/openai/models` endpoint in open-webui/open-webui version 0.3.8 is vulnerable to Server-Side Request Forgery (SSRF). An attacker can change the OpenAI URL to any URL without …

Mar 20, 2025
CVE-2024-7957
9.1 CRITICAL

An arbitrary file overwrite vulnerability exists in the ZulipConnector of danswer-ai/danswer, affecting the latest version. The vulnerability arises from the load_credentials method, where user-controlled input …

Mar 20, 2025
CVE-2024-7819
7.4 HIGH

A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive information such as chat contents, API keys, and other data. This vulnerability occurs due …

Mar 20, 2025
CVE-2024-7806
8.8 HIGH

A vulnerability in open-webui/open-webui versions <= 0.3.8 allows remote code execution by non-admin users via Cross-Site Request Forgery (CSRF). The application uses cookies with the …

Mar 20, 2025
CVE-2024-7804

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 20, 2025
CVE-2024-7779
7.5 HIGH

A vulnerability in danswer-ai/danswer version 1 allows an attacker to perform a Regular Expression Denial of Service (ReDoS) by manipulating regular expressions. This can significantly …

Mar 20, 2025
CVE-2024-7776
9.1 CRITICAL

A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite due to inadequate prevention of …

Mar 20, 2025
CVE-2024-7771
6.5 MEDIUM

A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denial of service. Uploading an audio file with a very low …

Mar 20, 2025
CVE-2024-7768
7.5 HIGH

A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of service. The endpoint takes a single GET …

Mar 20, 2025
CVE-2024-7767
8.1 HIGH

An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system to view, modify, and delete …

Mar 20, 2025
CVE-2024-7765
7.5 HIGH

In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cause a denial of service. The server becomes …

Mar 20, 2025
CVE-2024-7764
8.1 HIGH

Vanna-ai v0.6.2 is vulnerable to SQL Injection due to insufficient protection against injecting additional SQL commands from user requests. The vulnerability occurs when the `generate_sql` …

Mar 20, 2025
CVE-2024-7760
9.6 CRITICAL

aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin …

Mar 20, 2025
CVE-2024-7476
4.3 MEDIUM

A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows an authenticated attacker to modify any user's templates by sending …

Mar 20, 2025
CVE-2024-7058
4.4 MEDIUM

A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization by using relative paths such as './'. …

Mar 20, 2025
CVE-2024-7053
9.0 CRITICAL

A vulnerability in open-webui/open-webui version 0.3.8 allows an attacker with a user-level account to perform a session fixation attack. The session cookie for all users …

Mar 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.