CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7045
4.3 MEDIUM

In version v0.3.8 of open-webui/open-webui, improper access control vulnerabilities allow an attacker to view any prompts. The application does not verify whether the attacker is …

Mar 20, 2025
CVE-2024-7040
4.9 MEDIUM

In version v0.3.8 of open-webui/open-webui, there is an improper access control vulnerability. On the frontend admin page, administrators are intended to view only the chats …

Mar 20, 2025
CVE-2024-7039
6.7 MEDIUM

In open-webui/open-webui version v0.3.8, there is an improper privilege management vulnerability. The application allows an attacker, acting as an admin, to delete other administrators via …

Mar 20, 2025
CVE-2024-7035
6.9 MEDIUM

In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability allows an attacker to perform …

Mar 20, 2025
CVE-2024-6986
5.4 MEDIUM

A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is due to the improper use of the 'v-html' …

Mar 20, 2025
CVE-2024-6863
6.5 MEDIUM

In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on the target server with a key of …

Mar 20, 2025
CVE-2024-6844
5.3 MEDIUM

A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inconsistent CORS matching due to the handling of the '+' character in URL paths. The request.path is …

Mar 20, 2025
CVE-2024-6841
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability exists in the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502) of the vanna-ai/vanna repository. Two endpoints in the built-in web app that provide …

Mar 20, 2025
CVE-2024-6839
5.3 MEDIUM

corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes longer regex patterns over more specific ones when matching paths, which can …

Mar 20, 2025
CVE-2024-6838
5.3 MEDIUM

In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its name …

Mar 20, 2025
CVE-2024-6583
4.3 MEDIUM

A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker to upload files to arbitrary paths in an S3 …

Mar 20, 2025
CVE-2024-6577
6.3 MEDIUM

In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metrics-prod' without ensuring its ownership or confirming its accessibility. This could lead …

Mar 20, 2025
CVE-2024-6483
5.3 MEDIUM

A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or directory deletion through path traversal. The endpoint does not mitigate …

Mar 20, 2025
CVE-2024-13060
4.3 MEDIUM

A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the …

Mar 20, 2025
CVE-2024-12910
5.9 MEDIUM

A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling a …

Mar 20, 2025
CVE-2024-12880
6.5 MEDIUM

A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data querying. The issue arises from the way tenant IDs are handled …

Mar 20, 2025
CVE-2024-12871
5.4 MEDIUM

An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowledge base. When the file is viewed …

Mar 20, 2025
CVE-2024-12870
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in infiniflow/ragflow, affecting the latest commit on the main branch (cec2080). The vulnerability allows an attacker to upload …

Mar 20, 2025
CVE-2024-12869
4.3 MEDIUM

In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a …

Mar 20, 2025
CVE-2024-12777
5.9 MEDIUM

A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is single-threaded, can …

Mar 20, 2025
CVE-2024-12775
6.5 MEDIUM

langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool option via the REST API `POST …

Mar 20, 2025
CVE-2024-12580
5.3 MEDIUM

A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionId, fileId, userId, and file_id in the /code/download/:sessionId/:fileId and /download/:userId/:file_id …

Mar 20, 2025
CVE-2024-12392
6.5 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to download papers from arxiv.org, but the URL …

Mar 20, 2025
CVE-2024-12391
6.5 MEDIUM

A vulnerability in binary-husky/gpt_academic, as of commit 310122f, allows for a Regular Expression Denial of Service (ReDoS) attack. The function '解析项目源码(手动指定和筛选源码文件类型)' permits the execution of …

Mar 20, 2025
CVE-2024-12388
6.5 MEDIUM

A vulnerability in binary-husky/gpt_academic version 310122f allows for a Regular Expression Denial of Service (ReDoS) attack. The application uses a regular expression to parse user …

Mar 20, 2025
CVE-2024-12387
6.5 MEDIUM

A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the server by uploading a specially crafted zip bomb. …

Mar 20, 2025
CVE-2024-12375
6.5 MEDIUM

A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a973c. This vulnerability allows an attacker to read arbitrary files on the system …

Mar 20, 2025
CVE-2024-12374
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An attacker can upload an HTML file, which the application interprets as content-type …

Mar 20, 2025
CVE-2024-12217
5.3 MEDIUM

A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The implementation of the blocked_path functionality, which is intended …

Mar 20, 2025
CVE-2024-12074
6.5 MEDIUM

A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webui version 1.10.0. The vulnerability is due to improper handling of …

Mar 20, 2025
CVE-2024-11850
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is due to improper validation and sanitization of user input …

Mar 20, 2025
CVE-2024-11821
4.3 MEDIUM

A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to modify Orchestrate instructions for a chatbot created by an …

Mar 20, 2025
CVE-2024-11441
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in Serge version 0.9.0. The vulnerability is due to improper neutralization of input during web page generation in …

Mar 20, 2025
CVE-2024-11301
6.5 MEDIUM

In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique constraint on the combination of projectId and slug. This …

Mar 20, 2025
CVE-2024-11300
6.5 MEDIUM

In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version …

Mar 20, 2025
CVE-2024-11173
6.5 MEDIUM

An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, leading to a full denial of service. This issue …

Mar 20, 2025
CVE-2024-11167
5.3 MEDIUM

An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue …

Mar 20, 2025
CVE-2024-11044
6.1 MEDIUM

An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This …

Mar 20, 2025
CVE-2024-11037
6.5 MEDIUM

A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass the blocked_paths protection and read the config.py file containing …

Mar 20, 2025
CVE-2024-11033
6.5 MEDIUM

A Denial of Service (DoS) vulnerability exists in the file upload feature of binary-husky/gpt_academic version 3.83. The vulnerability is due to improper handling of form-data …

Mar 20, 2025
CVE-2024-10955
6.5 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability exists in gaizhenbiao/chuanhuchatgpt, as of commit 20b2e02. The server uses the regex pattern `r'<[^>]+>'` to parse user …

Mar 20, 2025
CVE-2024-10948
6.5 MEDIUM

A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the system, including sensitive files such as `config.py`. This …

Mar 20, 2025
CVE-2024-10940
5.3 MEDIUM

A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized users to read arbitrary files from the host file system. The issue arises from …

Mar 20, 2025
CVE-2024-10908
6.1 MEDIUM

An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This …

Mar 20, 2025
CVE-2024-10812
6.1 MEDIUM

An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is redirected to a URL specified by user-controlled input in …

Mar 20, 2025
CVE-2024-10727
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnerability arises when the application receives data in an HTTP request …

Mar 20, 2025
CVE-2024-10725
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which are …

Mar 20, 2025
CVE-2024-10724
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when editing the Destination address. This vulnerability …

Mar 20, 2025
CVE-2024-10723
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the destination address …

Mar 20, 2025
CVE-2024-10722
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows attackers to inject malicious scripts into the 'Description' field of custom …

Mar 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.