CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12720
7.5 HIGH

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file tokenization_nougat_fast.py. The vulnerability occurs in the post_process_single() …

Mar 20, 2025
CVE-2024-12704
7.5 HIGH

A vulnerability in the LangChainLLM class of the run-llama/llama_index repository, version v0.12.5, allows for a Denial of Service (DoS) attack. The stream_complete method executes the …

Mar 20, 2025
CVE-2024-12580
5.3 MEDIUM

A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionId, fileId, userId, and file_id in the /code/download/:sessionId/:fileId and /download/:userId/:file_id …

Mar 20, 2025
CVE-2024-12537
7.5 HIGH

In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the `api/v1/utils/code/format` endpoint. If a malicious actor sends a …

Mar 20, 2025
CVE-2024-12534
7.5 HIGH

In version v0.3.32 of open-webui/open-webui, the application allows users to submit large payloads in the email and password fields during the sign-in process due to …

Mar 20, 2025
CVE-2024-12450
9.8 CRITICAL

In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter URL parameters, allowing attackers to exploit Full Read …

Mar 20, 2025
CVE-2024-12433
9.8 CRITICAL

A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses a hard-coded AuthKey 'authkey=b'infiniflow-token4kevinhu'' which can be easily …

Mar 20, 2025
CVE-2024-12392
6.5 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to download papers from arxiv.org, but the URL …

Mar 20, 2025
CVE-2024-12391
6.5 MEDIUM

A vulnerability in binary-husky/gpt_academic, as of commit 310122f, allows for a Regular Expression Denial of Service (ReDoS) attack. The function '解析项目源码(手动指定和筛选源码文件类型)' permits the execution of …

Mar 20, 2025
CVE-2024-12390
8.8 HIGH

A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application supports the extraction of user-provided RAR files without proper validation. The …

Mar 20, 2025
CVE-2024-12389
8.8 HIGH

A path traversal vulnerability exists in binary-husky/gpt_academic version git 310122f. The application supports the extraction of user-provided 7z files without proper validation. The Python py7zr …

Mar 20, 2025
CVE-2024-12388
6.5 MEDIUM

A vulnerability in binary-husky/gpt_academic version 310122f allows for a Regular Expression Denial of Service (ReDoS) attack. The application uses a regular expression to parse user …

Mar 20, 2025
CVE-2024-12387
6.5 MEDIUM

A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the server by uploading a specially crafted zip bomb. …

Mar 20, 2025
CVE-2024-12376
7.5 HIGH

A Server-Side Request Forgery (SSRF) vulnerability was identified in the lm-sys/fastchat web server, specifically in the affected version git 2c68a13. This vulnerability allows an attacker …

Mar 20, 2025
CVE-2024-12375
6.5 MEDIUM

A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a973c. This vulnerability allows an attacker to read arbitrary files on the system …

Mar 20, 2025
CVE-2024-12374
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An attacker can upload an HTML file, which the application interprets as content-type …

Mar 20, 2025
CVE-2024-12217
5.3 MEDIUM

A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The implementation of the blocked_path functionality, which is intended …

Mar 20, 2025
CVE-2024-12216
7.1 HIGH

A vulnerability in the `ImageClassificationDataset.from_csv()` API of the `dmlc/gluon-cv` repository, version 0.10.0, allows for arbitrary file write. The function downloads and extracts `tar.gz` files from …

Mar 20, 2025
CVE-2024-12215
8.8 HIGH

In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages from the Internet. However, the function `project_wheel_metadata()` within the …

Mar 20, 2025
CVE-2024-12074
6.5 MEDIUM

A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webui version 1.10.0. The vulnerability is due to improper handling of …

Mar 20, 2025
CVE-2024-12070
7.5 HIGH

A Denial of Service (DoS) vulnerability exists in the file upload feature of haotian-liu/llava, specifically in Release v1.2.0 (LLaVA-1.6). The vulnerability is due to improper …

Mar 20, 2025
CVE-2024-12068
7.5 HIGH

A Server-Side Request Forgery (SSRF) vulnerability was discovered in haotian-liu/llava, affecting version git c121f04. This vulnerability allows an attacker to make the server perform HTTP …

Mar 20, 2025
CVE-2024-12065
7.5 HIGH

A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacker to access any file on the system by sending …

Mar 20, 2025
CVE-2024-12063
7.5 HIGH

A Denial of Service (DoS) vulnerability exists in the file upload feature of imartinez/privategpt version v0.6.2. The vulnerability is due to improper handling of form-data …

Mar 20, 2025
CVE-2024-12055
7.5 HIGH

A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be uploaded to the public Ollama …

Mar 20, 2025
CVE-2024-12048
8.8 HIGH

An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly check authorization for multiple API endpoints, allowing attackers …

Mar 20, 2025
CVE-2024-12044
9.8 CRITICAL

A remote code execution vulnerability exists in open-mmlab/mmdetection version v3.3.0. The vulnerability is due to the use of the `pickle.loads()` function in the `all_reduce_dict()` distributed …

Mar 20, 2025
CVE-2024-12039
8.1 HIGH

langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess attempts for password reset. This allows an …

Mar 20, 2025
CVE-2024-12029
9.8 CRITICAL

A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability arises from unsafe deserialization of model files …

Mar 20, 2025
CVE-2024-11958
9.8 CRITICAL

A SQL injection vulnerability exists in the `duckdb_retriever` component of the run-llama/llama_index repository, specifically in the latest version. The vulnerability arises from the construction of …

Mar 20, 2025
CVE-2024-11850
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is due to improper validation and sanitization of user input …

Mar 20, 2025
CVE-2024-11824
7.6 HIGH

A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log functionality. The vulnerability arises because certain HTML tags like …

Mar 20, 2025
CVE-2024-11822
7.5 HIGH

langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due to improper handling of the api_endpoint parameter, allowing an attacker to …

Mar 20, 2025
CVE-2024-11821
4.3 MEDIUM

A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to modify Orchestrate instructions for a chatbot created by an …

Mar 20, 2025
CVE-2024-11603
7.5 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is present in the `/queue/join?` endpoint, where insufficient validation of the path …

Mar 20, 2025
CVE-2024-11602
7.4 HIGH

A Cross-Origin Resource Sharing (CORS) vulnerability exists in feast-dev/feast version 0.40.0. The CORS configuration on the agentscope server does not properly restrict access to only …

Mar 20, 2025
CVE-2024-11449
7.5 HIGH

A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the /run/predict endpoint. An attacker can gain unauthorized access to internal …

Mar 20, 2025
CVE-2024-11441
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in Serge version 0.9.0. The vulnerability is due to improper neutralization of input during web page generation in …

Mar 20, 2025
CVE-2024-11302
8.0 HIGH

A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, allows attackers to add, modify, and remove bindings arbitrarily. This vulnerability …

Mar 20, 2025
CVE-2024-11301
6.5 MEDIUM

In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique constraint on the combination of projectId and slug. This …

Mar 20, 2025
CVE-2024-11300
6.5 MEDIUM

In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version …

Mar 20, 2025
CVE-2024-11173
6.5 MEDIUM

An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, leading to a full denial of service. This issue …

Mar 20, 2025
CVE-2024-11172
7.5 HIGH

A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of service by sending a crafted payload to the server. …

Mar 20, 2025
CVE-2024-11171
7.5 HIGH

In danny-avila/librechat version git 0c2a583, there is an improper input validation vulnerability. The application uses multer middleware for handling multipart file uploads. When using in-memory …

Mar 20, 2025
CVE-2024-11170
8.8 HIGH

A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middleware. This can lead …

Mar 20, 2025
CVE-2024-11169
7.5 HIGH

An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs module throws an exception while handling …

Mar 20, 2025
CVE-2024-11167
5.3 MEDIUM

An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue …

Mar 20, 2025
CVE-2024-11137
7.5 HIGH

An Insecure Direct Object Reference (IDOR) vulnerability exists in the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/lunary version 1.6.0. This vulnerability allows an attacker to update the …

Mar 20, 2025
CVE-2024-11045
9.6 CRITICAL

A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability …

Mar 20, 2025
CVE-2024-11044
6.1 MEDIUM

An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This …

Mar 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.