CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9418
6.5 MEDIUM

In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns the user's password in plaintext. This vulnerability allows an attacker to retrieve the password of …

Mar 20, 2025
CVE-2024-9365
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability in polyaxon/polyaxon v2.4.0 allows attackers to perform unauthorized actions in the context of the victim's browser. This includes creating …

Mar 20, 2025
CVE-2024-9311
6.1 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload files with malicious content without authentication or user interaction. The …

Mar 20, 2025
CVE-2024-9308
6.1 MEDIUM

An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. …

Mar 20, 2025
CVE-2024-9159
6.5 MEDIUM

An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the server at will, leading to a complete …

Mar 20, 2025
CVE-2024-9107
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version git 20b2e02. The vulnerability arises from improper sanitization of HTML tags in …

Mar 20, 2025
CVE-2024-9098
6.1 MEDIUM

In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new members with billing permissions, thereby gaining unauthorized access to billing …

Mar 20, 2025
CVE-2024-9000
6.5 MEDIUM

In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists without validating whether the user has proper permissions. This missing …

Mar 20, 2025
CVE-2024-8982
6.2 MEDIUM

A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local server through the web application. This flaw …

Mar 20, 2025
CVE-2024-8736
6.5 MEDIUM

A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). The vulnerability can be exploited remotely via Cross-Site …

Mar 20, 2025
CVE-2024-8556
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view …

Mar 20, 2025
CVE-2024-8400
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability allows an attacker to upload a malicious HTML file containing …

Mar 20, 2025
CVE-2024-8251
5.3 MEDIUM

A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in the API endpoint "/embed/:embedId/stream-chat" where user-provided JSON is directly …

Mar 20, 2025
CVE-2024-8101
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. The vulnerability arises due to the use of `dangerouslySetInnerHTML` …

Mar 20, 2025
CVE-2024-8057
4.3 MEDIUM

In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them to an existing connector. This issue arises …

Mar 20, 2025
CVE-2024-8029
6.1 MEDIUM

An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims click …

Mar 20, 2025
CVE-2024-8027
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability exists in netease-youdao/QAnything. Attackers can upload malicious knowledge files to the knowledge base, which can trigger XSS attacks during …

Mar 20, 2025
CVE-2024-8021
6.1 MEDIUM

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL …

Mar 20, 2025
CVE-2024-7771
6.5 MEDIUM

A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denial of service. Uploading an audio file with a very low …

Mar 20, 2025
CVE-2024-7476
4.3 MEDIUM

A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows an authenticated attacker to modify any user's templates by sending …

Mar 20, 2025
CVE-2024-7058
4.4 MEDIUM

A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization by using relative paths such as './'. …

Mar 20, 2025
CVE-2024-7046
4.3 MEDIUM

An improper access control vulnerability in open-webui/open-webui v0.3.8 allows an attacker to view admin details. The application does not verify whether the attacker is an …

Mar 20, 2025
CVE-2024-7045
4.3 MEDIUM

In version v0.3.8 of open-webui/open-webui, improper access control vulnerabilities allow an attacker to view any prompts. The application does not verify whether the attacker is …

Mar 20, 2025
CVE-2024-7040
4.9 MEDIUM

In version v0.3.8 of open-webui/open-webui, there is an improper access control vulnerability. On the frontend admin page, administrators are intended to view only the chats …

Mar 20, 2025
CVE-2024-7039
6.7 MEDIUM

In open-webui/open-webui version v0.3.8, there is an improper privilege management vulnerability. The application allows an attacker, acting as an admin, to delete other administrators via …

Mar 20, 2025
CVE-2024-7035
6.9 MEDIUM

In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability allows an attacker to perform …

Mar 20, 2025
CVE-2024-6986
5.4 MEDIUM

A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is due to the improper use of the 'v-html' …

Mar 20, 2025
CVE-2024-6863
6.5 MEDIUM

In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on the target server with a key of …

Mar 20, 2025
CVE-2024-6844
5.3 MEDIUM

A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inconsistent CORS matching due to the handling of the '+' character in URL paths. The request.path is …

Mar 20, 2025
CVE-2024-6841
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability exists in the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502) of the vanna-ai/vanna repository. Two endpoints in the built-in web app that provide …

Mar 20, 2025
CVE-2024-6839
5.3 MEDIUM

corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes longer regex patterns over more specific ones when matching paths, which can …

Mar 20, 2025
CVE-2024-6838
5.3 MEDIUM

In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its name …

Mar 20, 2025
CVE-2024-6583
4.3 MEDIUM

A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker to upload files to arbitrary paths in an S3 …

Mar 20, 2025
CVE-2024-6577
6.3 MEDIUM

In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metrics-prod' without ensuring its ownership or confirming its accessibility. This could lead …

Mar 20, 2025
CVE-2024-6483
5.3 MEDIUM

A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or directory deletion through path traversal. The endpoint does not mitigate …

Mar 20, 2025
CVE-2024-13060
4.3 MEDIUM

A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the …

Mar 20, 2025
CVE-2024-12910
5.9 MEDIUM

A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling a …

Mar 20, 2025
CVE-2024-12880
6.5 MEDIUM

A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data querying. The issue arises from the way tenant IDs are handled …

Mar 20, 2025
CVE-2024-12871
5.4 MEDIUM

An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowledge base. When the file is viewed …

Mar 20, 2025
CVE-2024-12870
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in infiniflow/ragflow, affecting the latest commit on the main branch (cec2080). The vulnerability allows an attacker to upload …

Mar 20, 2025
CVE-2024-12869
4.3 MEDIUM

In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a …

Mar 20, 2025
CVE-2024-12777
5.9 MEDIUM

A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is single-threaded, can …

Mar 20, 2025
CVE-2024-12775
6.5 MEDIUM

langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool option via the REST API `POST …

Mar 20, 2025
CVE-2024-12580
5.3 MEDIUM

A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionId, fileId, userId, and file_id in the /code/download/:sessionId/:fileId and /download/:userId/:file_id …

Mar 20, 2025
CVE-2024-12392
6.5 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to download papers from arxiv.org, but the URL …

Mar 20, 2025
CVE-2024-12391
6.5 MEDIUM

A vulnerability in binary-husky/gpt_academic, as of commit 310122f, allows for a Regular Expression Denial of Service (ReDoS) attack. The function '解析项目源码(手动指定和筛选源码文件类型)' permits the execution of …

Mar 20, 2025
CVE-2024-12388
6.5 MEDIUM

A vulnerability in binary-husky/gpt_academic version 310122f allows for a Regular Expression Denial of Service (ReDoS) attack. The application uses a regular expression to parse user …

Mar 20, 2025
CVE-2024-12387
6.5 MEDIUM

A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the server by uploading a specially crafted zip bomb. …

Mar 20, 2025
CVE-2024-12375
6.5 MEDIUM

A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a973c. This vulnerability allows an attacker to read arbitrary files on the system …

Mar 20, 2025
CVE-2024-12374
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An attacker can upload an HTML file, which the application interprets as content-type …

Mar 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.