Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2024-52805 |
|
Vulnerability in matrix-synapse (CVE-2024-52805)
vulnerability in matrix-synapse (CVE-2024-52805). Risk of unauthorized operations or information disclosure. Exploitable via ``max_upload_size``. Mitigation: upgrade to `1.120.1` or later.
|
| CVE-2024-52804 |
|
Vulnerability in tornado (CVE-2024-52804)
vulnerability in tornado (CVE-2024-52804). Risk of unauthorized operations or information disclosure. Exploitable via `Cookie header`. Mitigation: upgrade to `6.4.2` or later.
|
| CVE-2024-39162 |
|
Cross-Site Scripting (XSS) in pyspider (CVE-2024-39162)
cross-site scripting in pyspider (CVE-2024-39162). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-53848 |
|
Vulnerability in check-jsonschema (CVE-2024-53848)
vulnerability in check-jsonschema (CVE-2024-53848). Data can be tampered with by attackers. Mitigation: upgrade to `0.30.0` or later.
|
| CVE-2024-53916 |
|
Vulnerability in neutron (CVE-2024-53916)
vulnerability in neutron (CVE-2024-53916). Data can be tampered with by attackers. Mitigation: upgrade to `25.0.1` or later.
|
| CVE-2024-52803 |
|
OS Command Injection in llamafactory (CVE-2024-52803)
OS command injection in llamafactory (CVE-2024-52803). Confidential information can be exposed externally. Exploitable via ``Popen``. Mitigation: upgrade to `0.9.1` or later.
|
| CVE-2024-52787 |
|
Path Traversal in libre-chat (CVE-2024-52787)
path traversal in libre-chat (CVE-2024-52787). Confidential information can be exposed externally.
|
| CVE-2024-52008 |
|
Vulnerability in ethyca-fides (CVE-2024-52008)
vulnerability in ethyca-fides (CVE-2024-52008). Confidential information can be exposed externally. Mitigation: upgrade to `2.50.0` or later.
|
| CVE-2024-52304 |
|
Vulnerability in aiohttp (CVE-2024-52304)
vulnerability in aiohttp (CVE-2024-52304). Risk of unauthorized operations or information disclosure. Exploitable via ``AIOHTTP_NO_EXTENSIONS``. Mitigation: upgrade to `3.10.11` or later.
|
| CVE-2024-52303 |
|
Vulnerability in aiohttp (CVE-2024-52303)
vulnerability in aiohttp (CVE-2024-52303). Risk of unauthorized operations or information disclosure. Exploitable via ``MatchInfoError``. Mitigation: upgrade to `3.10.11` or later.
|
| CVE-2023-6110 |
|
Vulnerability in python-openstackclient (CVE-2023-6110)
vulnerability in python-openstackclient (CVE-2023-6110). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.3.0` or later.
|
| CVE-2024-4311 |
|
Vulnerability in zenml (CVE-2024-4311)
vulnerability in zenml (CVE-2024-4311). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.57.0rc2` or later.
|
| CVE-2023-34049 |
|
Vulnerability in salt (CVE-2023-34049)
vulnerability in salt (CVE-2023-34049). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3006.4` or later.
|
| CVE-2021-3987 |
|
Vulnerability in calibreweb (CVE-2021-3987)
vulnerability in calibreweb (CVE-2021-3987). Risk of unauthorized operations or information disclosure. Exploitable via ``create_shelf``. Mitigation: upgrade to `0.6.15` or later.
|
| CVE-2021-3988 |
|
Cross-Site Scripting (XSS) in calibreweb (CVE-2021-3988)
cross-site scripting in calibreweb (CVE-2021-3988). Risk of unauthorized operations or information disclosure. Exploitable via ``edit_books.js``. Mitigation: upgrade to `0.6.15` or later.
|
| CVE-2021-3986 |
|
Vulnerability in calibreweb (CVE-2021-3986)
vulnerability in calibreweb (CVE-2021-3986). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.15` or later.
|
| CVE-2024-51998 |
|
Path Traversal in changedetection-io (CVE-2024-51998)
path traversal in changedetection-io (CVE-2024-51998). Confidential information can be exposed externally. Exploitable via ``ALLOW_FILE_URI``. Mitigation: upgrade to `0.47.6` or later.
|
| CVE-2024-52524 |
|
Vulnerability in giskard (CVE-2024-52524)
vulnerability in giskard (CVE-2024-52524). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.15.5` or later.
|
| CVE-2024-47874 |
|
Vulnerability in starlette (CVE-2024-47874)
vulnerability in starlette (CVE-2024-47874). Risk of unauthorized operations or information disclosure. Exploitable via ``filename``. Mitigation: upgrade to `0.40.0` or later.
|
| CVE-2024-49766 |
|
Path Traversal in werkzeug (CVE-2024-49766)
path traversal in werkzeug (CVE-2024-49766). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.6` or later.
|
| CVE-2024-48052 |
|
SSRF (Server-Side Request Forgery) in gradio (CVE-2024-48052)
SSRF in gradio (CVE-2024-48052). Confidential information can be exposed externally.
|
| CVE-2024-10073 |
|
Code Injection in flair (CVE-2024-10073)
code injection in flair (CVE-2024-10073). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.15.0` or later.
|
| CVE-2024-51483 |
|
Path Traversal in changedetection-io (CVE-2024-51483)
path traversal in changedetection-io (CVE-2024-51483). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.47.5` or later.
|
| CVE-2024-49771 |
|
Path Traversal in mpxj (CVE-2024-49771)
path traversal in mpxj (CVE-2024-49771). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `13.5.1` or later.
|
| CVE-2024-21272 |
|
SQL Injection in mysql-connector-python (CVE-2024-21272)
SQL injection in mysql-connector-python (CVE-2024-21272). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.1.0` or later.
|
| CVE-2024-48061 |
|
Code Injection in langflow (CVE-2024-48061)
code injection in langflow (CVE-2024-48061). Successful exploitation can lead to full system takeover.
|
| CVE-2024-6971 |
|
Path Traversal in lollms (CVE-2024-6971)
path traversal in lollms (CVE-2024-6971). Risk of unauthorized operations or information disclosure. Exploitable via ``lollms_file_system.py``.
|
| CVE-2024-9014 |
|
Vulnerability in pgadmin4 (CVE-2024-9014)
vulnerability in pgadmin4 (CVE-2024-9014). Confidential information can be exposed externally. Mitigation: upgrade to `8.12` or later.
|
| CVE-2024-46488 |
|
Vulnerability in sqlite-vec (CVE-2024-46488)
vulnerability in sqlite-vec (CVE-2024-46488). Confidential information can be exposed externally. Mitigation: upgrade to `0.1.3` or later.
|
| CVE-2024-45793 |
|
Cross-Site Scripting (XSS) in confidant (CVE-2024-45793)
cross-site scripting in confidant (CVE-2024-45793). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.2` or later.
|
| CVE-2024-45601 |
|
Vulnerability in mesop (CVE-2024-45601)
vulnerability in mesop (CVE-2024-45601). Confidential information can be exposed externally. Mitigation: upgrade to `0.12.4` or later.
|
| CVE-2024-9277 |
|
Vulnerability in langflow (CVE-2024-9277)
vulnerability in langflow (CVE-2024-9277). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-47211 |
|
Vulnerability in ironic (CVE-2024-47211)
vulnerability in ironic (CVE-2024-47211). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-8939 |
|
Vulnerability in vllm (CVE-2024-8939)
vulnerability in vllm (CVE-2024-8939). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-8768 |
|
Vulnerability in vllm (CVE-2024-8768)
vulnerability in vllm (CVE-2024-8768). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.5.5` or later.
|
| CVE-2024-45606 |
|
Vulnerability in sentry (CVE-2024-45606)
vulnerability in sentry (CVE-2024-45606). Data can be tampered with by attackers. Mitigation: upgrade to `24.9.0` or later.
|
| CVE-2024-35515 |
|
Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.
sqlitedict insecure deserialization vulnerability
|
| CVE-2024-45605 |
|
Vulnerability in sentry (CVE-2024-45605)
vulnerability in sentry (CVE-2024-45605). Data can be tampered with by attackers. Mitigation: upgrade to `24.9.0` or later.
|
| CVE-2024-45858 |
|
Vulnerability in guardrails-ai (CVE-2024-45858)
vulnerability in guardrails-ai (CVE-2024-45858). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.5.10` or later.
|
| CVE-2024-8864 |
|
Code Injection in composio-core (CVE-2024-8864)
code injection in composio-core (CVE-2024-8864). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-8865 |
|
Path Traversal in composio-core (CVE-2024-8865)
path traversal in composio-core (CVE-2024-8865). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-8862 |
|
Vulnerability in dtale (CVE-2024-8862)
vulnerability in dtale (CVE-2024-8862). Risk of unauthorized operations or information disclosure. Exploitable via ``python``. Mitigation: upgrade to `3.14.1` or later.
|
| CVE-2024-8863 |
|
Cross-Site Scripting (XSS) in aim (CVE-2024-8863)
cross-site scripting in aim (CVE-2024-8863). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-45314 |
|
Vulnerability in flask-appbuilder (CVE-2024-45314)
vulnerability in flask-appbuilder (CVE-2024-45314). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.5.1` or later.
|
| CVE-2024-6587 |
|
SSRF (Server-Side Request Forgery) in litellm (CVE-2024-6587)
SSRF in litellm (CVE-2024-6587). Confidential information can be exposed externally. Exploitable via `POST /chat/completions`. Mitigation: upgrade to `1.44.8` or later.
|
| CVE-2024-45857 |
|
Unsafe Deserialization in cleanlab (CVE-2024-45857)
vulnerability in cleanlab (CVE-2024-45857). Successful exploitation can lead to full system takeover.
|
| CVE-2024-45847 |
|
Code Injection in mindsdb (CVE-2024-45847)
code injection in mindsdb (CVE-2024-45847). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `24.7.4.1` or later.
|
| CVE-2024-45856 |
|
Cross-Site Scripting (XSS) in mindsdb (CVE-2024-45856)
cross-site scripting in mindsdb (CVE-2024-45856). Successful exploitation can lead to full system takeover.
|
| CVE-2024-27320 |
|
Vulnerability in refuel-autolabel (CVE-2024-27320)
vulnerability in refuel-autolabel (CVE-2024-27320). Successful exploitation can lead to full system takeover.
|
| CVE-2024-27321 |
|
Vulnerability in refuel-autolabel (CVE-2024-27321)
vulnerability in refuel-autolabel (CVE-2024-27321). Successful exploitation can lead to full system takeover.
|