Aggregator
CVE-2024-8859 | mlflow up to 2.16.x Dbfs Service path traversal
5 months 2 weeks ago
A vulnerability has been found in mlflow up to 2.16.x and classified as problematic. This vulnerability affects unknown code of the component Dbfs Service. The manipulation leads to path traversal: '\..\filename'.
This vulnerability was named CVE-2024-8859. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8524 | modelscope agentscope up to 0.0.4 POST Request /read-examples file inclusion
5 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in modelscope agentscope up to 0.0.4. This affects an unknown part of the file /read-examples of the component POST Request Handler. The manipulation leads to file inclusion.
This vulnerability is uniquely identified as CVE-2024-8524. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
Microsoft lifts Windows 11 upgrade block after Asphalt 8 crash fix
5 months 2 weeks ago
Microsoft has lifted an upgrade block that prevented Asphalt 8: Airborne players from upgrading their systems to Windows 11 24H2 due to compatibility issues. [...]
Sergiu Gatlan
CVE-2024-7959 | open-webui up to 0.3.8 /openai/models server-side request forgery
5 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in open-webui up to 0.3.8. Affected by this issue is some unknown functionality of the file /openai/models. The manipulation leads to server-side request forgery.
This vulnerability is handled as CVE-2024-7959. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-7771 | mintplex-labs anything-llm up to 1.3.0 Audio File resource consumption
5 months 2 weeks ago
A vulnerability classified as problematic was found in mintplex-labs anything-llm up to 1.3.0. Affected by this vulnerability is an unknown functionality of the component Audio File Handler. The manipulation leads to resource consumption.
This vulnerability is known as CVE-2024-7771. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6851 | aimhubio aim up to 3.22.0 LocalFileManager._cleanup path traversal
5 months 2 weeks ago
A vulnerability classified as critical has been found in aimhubio aim up to 3.22.0. Affected is the function LocalFileManager._cleanup. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2024-6851. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-6839 | corydolphin flask-cors up to 4.0.1 resolution of path
5 months 2 weeks ago
A vulnerability was found in corydolphin flask-cors up to 4.0.1. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to improper resolution of path equivalence.
The identification of this vulnerability is CVE-2024-6839. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-6827 | benoitc gunicorn up to 21.2.0 Transfer-Encoding request smuggling
5 months 2 weeks ago
A vulnerability was found in benoitc gunicorn up to 21.2.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation of the argument Transfer-Encoding leads to http request smuggling.
This vulnerability was named CVE-2024-6827. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-12375 | automatic1111 stable-diffusion-webui Request absolute path traversal
5 months 2 weeks ago
A vulnerability was found in automatic1111 stable-diffusion-webui and classified as problematic. Affected by this issue is some unknown functionality of the component Request Handler. The manipulation leads to absolute path traversal.
This vulnerability is handled as CVE-2024-12375. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11603 | lm-sys fastchat up to 0.2.36 /queue/join path server-side request forgery
5 months 2 weeks ago
A vulnerability was found in lm-sys fastchat up to 0.2.36. It has been classified as critical. This affects an unknown part of the file /queue/join. The manipulation of the argument path leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2024-11603. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-11822 | langgenius dify up to 0.9.1 api_endpoint server-side request forgery
5 months 2 weeks ago
A vulnerability has been found in langgenius dify up to 0.9.1 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument api_endpoint leads to server-side request forgery.
This vulnerability is known as CVE-2024-11822. The attack can be launched remotely. There is no exploit available.
vuldb.com
SlashNext’s URL analysis tool identifies malicious behavior
5 months 2 weeks ago
SlashNext launched a new advanced URL analysis feature that performs live, in-depth scanning of unknown URLs, tracking requests and following redirection to track the original link to its final destination. Developed specifically for complex attacks executed by cybercriminals who have learned to abuse trusted cloud application infrastructure, SlashNext’s URL analysis tool leverages AI to redefine email security, ensuring efficiency, accuracy, and continuous innovation. This feature enhances the arsenal of tools SlashNext customers already have at … More →
The post SlashNext’s URL analysis tool identifies malicious behavior appeared first on Help Net Security.
Industry News
CVE-2024-11449 | haotian-liu llava up to up to 1.2.0/1.6 path server-side request forgery
5 months 2 weeks ago
A vulnerability, which was classified as critical, was found in haotian-liu llava up to up to 1.2.0/1.6. Affected is an unknown function. The manipulation of the argument path leads to server-side request forgery.
This vulnerability is traded as CVE-2024-11449. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-10986 | binary-husky gpt_academic up to up to 3.83 input validation
5 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in binary-husky gpt_academic up to up to 3.83. This issue affects some unknown processing. The manipulation leads to improper input validation.
The identification of this vulnerability is CVE-2024-10986. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2024-10707 | gaizhenbiao ChuanhuChatGPT JSON File handle_dataset_selection information disclosure
5 months 2 weeks ago
A vulnerability classified as problematic was found in gaizhenbiao ChuanhuChatGPT. This vulnerability affects the function handle_dataset_selection of the component JSON File Handler. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-10707. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2025-0454 | significant-gravitas autogpt up to 0.3.x urllib.parse server-side request forgery
5 months 2 weeks ago
A vulnerability classified as critical has been found in significant-gravitas autogpt up to 0.3.x. This affects the function urllib.parse. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2025-0454. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8736 | parisneo lollms-webui /upload_avatar resource consumption
5 months 2 weeks ago
A vulnerability was found in parisneo lollms-webui. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /upload_avatar. The manipulation leads to resource consumption.
This vulnerability is handled as CVE-2024-8736. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-0188 | gaizhenbiao ChuanhuChatGPT up to 20240914 server-side request forgery
5 months 2 weeks ago
A vulnerability was found in gaizhenbiao ChuanhuChatGPT up to 20240914. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to server-side request forgery.
This vulnerability is known as CVE-2025-0188. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-9309 | haotian-liu llava up to 1.2.0/1.6 API Endpoint /worker_generate_stream server-side request forgery
5 months 2 weeks ago
A vulnerability was found in haotian-liu llava up to 1.2.0/1.6. It has been classified as critical. Affected is an unknown function of the file /worker_generate_stream of the component API Endpoint. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2024-9309. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com