Latest CVE Feed
-
6.1
MEDIUMCVE-2024-51075
A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/user-search.php in PHPGurukul Online DJ Booking Management System v1.0, which allows remote attackers to execute arbitrary code via the searchdata parameter.... Read more
Affected Products : online_dj_booking_management_system- Published: Oct. 29, 2024
- Modified: Nov. 04, 2024
-
7.1
HIGHCVE-2024-49634
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rimon Habib BP Member Type Manager allows Reflected XSS.This issue affects BP Member Type Manager: from n/a through 1.01.... Read more
Affected Products : bp_member_type_manager- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-49632
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Coral Web Design CWD 3D Image Gallery allows Reflected XSS.This issue affects CWD 3D Image Gallery: from n/a through 1.0.... Read more
Affected Products : cwd_3d_image_gallery- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-47640
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in weDevs WP ERP allows Reflected XSS.This issue affects WP ERP: from n/a through 1.13.2.... Read more
Affected Products : wp_erp- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
6.4
MEDIUMCVE-2024-10226
The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 2.1.13 due to insufficient input sanitization and output escaping on user supplied attributes. ... Read more
Affected Products : arconix_shortcodes- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-8309
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deletin... Read more
Affected Products : langchain- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-8143
In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the use... Read more
Affected Products : chuanhuchatgpt- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.5
HIGHCVE-2024-7962
An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read any file that matches specific criteria using an absolute path. The file mus... Read more
Affected Products : chuanhuchatgpt- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
7.5
HIGHCVE-2024-7807
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process... Read more
Affected Products : chuanhuchatgpt- Published: Oct. 29, 2024
- Modified: Jan. 09, 2025
-
7.5
HIGHCVE-2024-7783
mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the passw... Read more
Affected Products : anythingllm- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
9.1
CRITICALCVE-2024-7774
A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite existing text files, read `.txt` files, and delete files. ... Read more
- Published: Oct. 29, 2024
- Modified: May. 28, 2025
-
9.1
CRITICALCVE-2024-7475
An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation of authentication processes, fraudulent login requests, and t... Read more
Affected Products : lunary- Published: Oct. 29, 2024
- Modified: Nov. 04, 2024
-
9.1
CRITICALCVE-2024-7474
In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view or delete external users by manipulating the 'id' parameter in the request URL. The application does not perform adequate checks on the ... Read more
Affected Products : lunary- Published: Oct. 29, 2024
- Modified: Jan. 09, 2025
-
7.5
HIGHCVE-2024-7473
An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update other users' prompts by manipulating the 'id' parameter in the request... Read more
Affected Products : lunary- Published: Oct. 29, 2024
- Modified: Nov. 03, 2024
-
6.5
MEDIUMCVE-2024-7472
lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup). An unauthenticated attacker can inject data into outgoing emails by bypassing the extractFi... Read more
Affected Products : lunary- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-7042
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This vulnerability permits unauthorized data manipulation, data exfiltration... Read more
- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.5
HIGHCVE-2024-7010
mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic algorithms. Specifically, in the context of password ha... Read more
Affected Products : localai- Published: Oct. 29, 2024
- Modified: Nov. 14, 2024
-
9.8
CRITICALCVE-2024-6868
mudler/LocalAI version 2.17.1 allows for arbitrary file write due to improper handling of automatic archive extraction. When model configurations specify additional files as archives (e.g., .tar), these archives are automatically extracted after downloadi... Read more
Affected Products : localai- Published: Oct. 29, 2024
- Modified: Nov. 13, 2024
-
8.1
HIGHCVE-2024-6674
A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers... Read more
Affected Products : lollms_web_ui- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-6673
A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-webui repository, versions v9.9 to the latest. The endpoint uses the GET method without requiring a client ID... Read more
Affected Products : lollms_web_ui- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024