CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5248
6.5 MEDIUM

In lunary-ai/lunary version 1.2.5, an improper access control vulnerability exists due to a missing permission check in the `GET /v1/users/me/org` endpoint. The platform's role definitions …

Jun 6, 2024
CVE-2024-5225
7.2 HIGH

An SQL Injection vulnerability exists in the berriai/litellm repository, specifically within the `/global/spend/logs` endpoint. The vulnerability arises due to improper neutralization of special elements used …

Jun 6, 2024
CVE-2024-5206
4.7 MEDIUM

A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to and including 1.4.1.post1, which was fixed in version 1.5.0. The …

Jun 6, 2024
CVE-2024-5187
8.8 HIGH

A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks …

Jun 6, 2024
CVE-2024-5186
7.2 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of imartinez/privategpt version 0.5.0. This vulnerability allows attackers to send crafted requests that …

Jun 6, 2024
CVE-2024-5133
8.1 HIGH

In lunary-ai/lunary version 1.2.4, an account takeover vulnerability exists due to the exposure of password recovery tokens in API responses. Specifically, when a user initiates …

Jun 6, 2024
CVE-2024-5132

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 6, 2024
CVE-2024-5131
6.5 MEDIUM

An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and including 1.2.2. The vulnerability allows unauthorized users to view any …

Jun 6, 2024
CVE-2024-5130
7.5 HIGH

An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete any dataset. The vulnerability is due …

Jun 6, 2024
CVE-2024-5129
8.2 HIGH

A Privilege Escalation Vulnerability exists in lunary-ai/lunary version 1.2.2, where any user can delete any datasets due to missing authorization checks. The vulnerability is present …

Jun 6, 2024
CVE-2024-5128
8.8 HIGH

An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2. This vulnerability allows unauthorized users to view, …

Jun 6, 2024
CVE-2024-5126
6.5 MEDIUM

An improper access control vulnerability exists in the lunary-ai/lunary repository, specifically within the versions.patch functionality for updating prompts. Affected versions include 1.2.2 up to but …

Jun 6, 2024
CVE-2024-5124
7.5 HIGH

A timing attack vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, specifically within the password comparison logic. The vulnerability is present in version 20240310 of the software, …

Jun 6, 2024
CVE-2024-4890
4.9 MEDIUM

A blind SQL injection vulnerability exists in the berriai/litellm application, specifically within the '/team/update' process. The vulnerability arises due to the improper handling of the …

Jun 6, 2024
CVE-2024-4888
8.1 HIGH

BerriAI's litellm, in its latest version, is vulnerable to arbitrary file deletion due to improper input validation on the `/audio/transcriptions` endpoint. An attacker can exploit …

Jun 6, 2024
CVE-2024-4881
7.5 HIGH

A path traversal vulnerability exists in the parisneo/lollms application, affecting version 9.4.0 and potentially earlier versions, but fixed in version 5.9.0. The vulnerability arises due …

Jun 6, 2024
CVE-2024-4851
7.7 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in the stangirard/quivr application, version 0.0.204, which allows attackers to access internal networks. The vulnerability is present in …

Jun 6, 2024
CVE-2024-4320
9.8 CRITICAL

A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_extension")` route handler. The vulnerability arises due …

Jun 6, 2024
CVE-2024-3429
9.8 CRITICAL

A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` functions in `lollms_core\lollms\security.py`. This vulnerability allows for arbitrary file reading …

Jun 6, 2024
CVE-2024-3408
9.8 CRITICAL

man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded …

Jun 6, 2024
CVE-2024-3404
6.5 MEDIUM

In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. This flaw allows an authenticated attacker to …

Jun 6, 2024
CVE-2024-3402
5.4 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability existed in version (20240121) of gaizhenbiao/chuanhuchatgpt due to inadequate sanitization and validation of model output data. Despite user-input validation …

Jun 6, 2024
CVE-2024-3322
9.8 CRITICAL

A path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui, affecting versions up to 9.5. The vulnerability arises from the improper limitation …

Jun 6, 2024
CVE-2024-3234
9.8 CRITICAL

The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The application is designed to restrict …

Jun 6, 2024
CVE-2024-3166
9.6 CRITICAL

A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest version of the web application. The vulnerability …

Jun 6, 2024
CVE-2024-3153
6.5 MEDIUM

mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of service (DOS) condition. Specifically, the server …

Jun 6, 2024
CVE-2024-3150
8.8 HIGH

In mintplex-labs/anything-llm, a vulnerability exists in the thread update process that allows users with Default or Manager roles to escalate their privileges to Administrator. The …

Jun 6, 2024
CVE-2024-3149
8.8 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex-labs/anything-llm. This feature, intended for users with manager or admin roles, processes …

Jun 6, 2024
CVE-2024-3110
8.7 HIGH

A stored Cross-Site Scripting (XSS) vulnerability exists in the mintplex-labs/anything-llm application, affecting versions up to and including the latest before 1.0.0. The vulnerability arises from …

Jun 6, 2024
CVE-2024-3102
5.3 MEDIUM

A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username parameter during the login process at the `/api/request-token` endpoint. The vulnerability arises …

Jun 6, 2024
CVE-2024-3099
5.4 MEDIUM

A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw can lead to …

Jun 6, 2024
CVE-2024-3095
7.7 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in the Web Research Retriever component of langchain-ai/langchain version 0.1.5. The vulnerability arises because the Web Research Retriever …

Jun 6, 2024
CVE-2024-37364
6.8 MEDIUM

Ariane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attackers to obtain sensitive information (such as hotel invoice …

Jun 6, 2024
CVE-2024-37154
5.3 MEDIUM

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This …

Jun 6, 2024
CVE-2024-37153
7.5 HIGH

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. There is an issue with how to liquid stake using Safe which itself …

Jun 6, 2024
CVE-2024-36740
7.5 HIGH

An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index as a negative number exceeds the range of …

Jun 6, 2024
CVE-2024-36735
5.3 MEDIUM

OneFlow-Inc. Oneflow v0.9.1 does not display an error or warning when the oneflow.eye parameter is floating.

Jun 6, 2024
CVE-2024-36734
7.5 HIGH

Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the dim parameter.

Jun 6, 2024
CVE-2024-36732
7.5 HIGH

An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.tensordot.

Jun 6, 2024
CVE-2024-36730
7.5 HIGH

Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting negative values into the oneflow.zeros/ones parameter.

Jun 6, 2024
CVE-2024-32873
3.5 LOW

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly when delegating vested tokens. The issue …

Jun 6, 2024
CVE-2024-30373
7.8 HIGH

Kofax Power PDF JPF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jun 6, 2024
CVE-2024-2965
4.7 MEDIUM

A Denial-of-Service (DoS) vulnerability exists in the `SitemapLoader` class of the `langchain-ai/langchain` repository, affecting all versions. The `parse_sitemap` method, responsible for parsing sitemaps and extracting …

Jun 6, 2024
CVE-2024-2928
7.5 HIGH

A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vulnerability arises from the …

Jun 6, 2024
CVE-2024-2624
9.8 CRITICAL

A path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically within the `@router.get("/switch_personal_path")` endpoint in `./lollms-webui/lollms_core/lollms/server/endpoints/lollms_user.py`. The vulnerability arises due to …

Jun 6, 2024
CVE-2024-2548
7.5 HIGH

A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `lollms_core/lollms/server/endpoints/lollms_binding_files_server.py` and `lollms_core/lollms/security.py` files. Due to inadequate validation of file paths between Windows …

Jun 6, 2024
CVE-2024-2383
6.1 MEDIUM

A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. …

Jun 6, 2024
CVE-2024-2362
9.1 CRITICAL

A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper validation of file paths between Windows and Linux …

Jun 6, 2024
CVE-2024-2360
9.8 CRITICAL

parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitization of user-supplied input in the 'Database path' …

Jun 6, 2024
CVE-2024-2359
9.8 CRITICAL

A vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and execute arbitrary code. The issue arises from the application's handling …

Jun 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.