Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2024-45052 |
|
Vulnerability in ethyca-fides (CVE-2024-45052)
vulnerability in ethyca-fides (CVE-2024-45052). Risk of unauthorized operations or information disclosure. Exploitable via ``valid_user``. Mitigation: upgrade to `2.44.0` or later.
|
| CVE-2024-45595 |
|
Vulnerability in dtale (CVE-2024-45595)
vulnerability in dtale (CVE-2024-45595). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.14.1` or later.
|
| CVE-2024-45053 |
|
Vulnerability in ethyca-fides (CVE-2024-45053)
vulnerability in ethyca-fides (CVE-2024-45053). Successful exploitation can lead to full system takeover. Exploitable via `PUT /api/v1/messaging/templates/`. Mitigation: upgrade to `2.44.0` or later.
|
| CVE-2024-42816 |
|
Cross-Site Scripting (XSS) in fastapi-admin (CVE-2024-42816)
cross-site scripting in fastapi-admin (CVE-2024-42816). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-42818 |
|
Cross-Site Scripting (XSS) in fastapi-admin (CVE-2024-42818)
cross-site scripting in fastapi-admin (CVE-2024-42818). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-41674 |
|
Vulnerability in ckan (CVE-2024-41674)
vulnerability in ckan (CVE-2024-41674). Risk of unauthorized operations or information disclosure. Exploitable via ``package_search``. Mitigation: upgrade to `2.10.5` or later.
|
| CVE-2024-41675 |
|
Cross-Site Scripting (XSS) in ckan (CVE-2024-41675)
cross-site scripting in ckan (CVE-2024-41675). Confidential information can be exposed externally. Exploitable via ``datatables_view``. Mitigation: upgrade to `2.10.5` or later.
|
| CVE-2024-43371 |
|
SSRF (Server-Side Request Forgery) in ckan (CVE-2024-43371)
SSRF in ckan (CVE-2024-43371). Confidential information can be exposed externally. Exploitable via ``ckan.download_proxy``. Mitigation: upgrade to `2.10.5` or later.
|
| CVE-2024-45187 |
|
Vulnerability in mage-ai (CVE-2024-45187)
vulnerability in mage-ai (CVE-2024-45187). Successful exploitation can lead to full system takeover.
|
| CVE-2024-45189 |
|
Path Traversal in mage-ai (CVE-2024-45189)
path traversal in mage-ai (CVE-2024-45189). Confidential information can be exposed externally.
|
| CVE-2024-45190 |
|
Vulnerability in mage-ai (CVE-2024-45190)
vulnerability in mage-ai (CVE-2024-45190). Confidential information can be exposed externally.
|
| CVE-2024-8072 |
|
Information Disclosure in mage-ai (CVE-2024-8072)
vulnerability in mage-ai (CVE-2024-8072). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-43396 |
|
Cross-Site Scripting (XSS) in khoj (CVE-2024-43396)
cross-site scripting in khoj (CVE-2024-43396). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/automation`. Mitigation: upgrade to `1.15.0` or later.
|
| CVE-2024-45188 |
|
Path Traversal in mage-ai (CVE-2024-45188)
path traversal in mage-ai (CVE-2024-45188). Confidential information can be exposed externally.
|
| CVE-2024-41951 |
|
Vulnerability in pheonixappapi (CVE-2024-41951)
vulnerability in pheonixappapi (CVE-2024-41951). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.2.5` or later.
|
| CVE-2024-41950 |
|
Vulnerability in haystack-ai (CVE-2024-41950)
vulnerability in haystack-ai (CVE-2024-41950). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.3.1` or later.
|
| CVE-2024-7319 |
|
Information Disclosure in openstack-heat (CVE-2024-7319)
vulnerability in openstack-heat (CVE-2024-7319). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-41955 |
|
Open Redirect in mobsf (CVE-2024-41955)
vulnerability in mobsf (CVE-2024-41955). Data can be tampered with by attackers. Mitigation: upgrade to `4.0.5` or later.
|
| CVE-2024-43399 |
|
Path Traversal in mobsf (CVE-2024-43399)
path traversal in mobsf (CVE-2024-43399). Successful exploitation can lead to full system takeover. Exploitable via ``poc.VULN``. Mitigation: upgrade to `4.0.7` or later.
|
| CVE-2024-7340 |
|
Vulnerability in weave (CVE-2024-7340)
vulnerability in weave (CVE-2024-7340). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.50.8` or later.
|
| CVE-2024-42367 |
|
Vulnerability in aiohttp (CVE-2024-42367)
vulnerability in aiohttp (CVE-2024-42367). Risk of unauthorized operations or information disclosure. Exploitable via ``FileResponse``. Mitigation: upgrade to `3.10.2` or later.
|
| CVE-2024-41671 |
|
Vulnerability in twisted (CVE-2024-41671)
vulnerability in twisted (CVE-2024-41671). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `24.7.0rc1` or later.
|
| CVE-2024-35199 |
|
Vulnerability in torchserve (CVE-2024-35199)
vulnerability in torchserve (CVE-2024-35199). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2024-41656 |
|
Cross-Site Scripting (XSS) in sentry (CVE-2024-41656)
cross-site scripting in sentry (CVE-2024-41656). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `24.7.1` or later.
|
| CVE-2024-41124 |
|
Vulnerability in puncia (CVE-2024-41124)
vulnerability in puncia (CVE-2024-41124). Risk of unauthorized operations or information disclosure. Exploitable via ``API_URLS``. Mitigation: upgrade to `0.21` or later.
|
| CVE-2024-6961 |
|
XXE (XML External Entity) in guardrails-ai (CVE-2024-6961)
vulnerability in guardrails-ai (CVE-2024-6961). Confidential information can be exposed externally. Mitigation: upgrade to `0.5.0` or later.
|
| CVE-2024-39123 |
|
Cross-Site Scripting (XSS) in calibreweb (CVE-2024-39123)
cross-site scripting in calibreweb (CVE-2024-39123). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-40767 |
|
Vulnerability in nova (CVE-2024-40767)
vulnerability in nova (CVE-2024-40767). Confidential information can be exposed externally.
|
| CVE-2024-41129 |
|
Vulnerability in ops (CVE-2024-41129)
vulnerability in ops (CVE-2024-41129). Confidential information can be exposed externally. Exploitable via ``subprocess.CalledProcessError``. Mitigation: upgrade to `2.15.0` or later.
|
| CVE-2024-29073 |
|
Vulnerability in anki (CVE-2024-29073)
vulnerability in anki (CVE-2024-29073). Confidential information can be exposed externally. Mitigation: upgrade to `24.6` or later.
|
| CVE-2024-32152 |
|
Vulnerability in anki (CVE-2024-32152)
vulnerability in anki (CVE-2024-32152). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `24.6` or later.
|
| CVE-2024-26020 |
|
Vulnerability in anki (CVE-2024-26020)
vulnerability in anki (CVE-2024-26020). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `24.06` or later.
|
| CVE-2024-6578 |
|
Cross-Site Scripting (XSS) in aim (CVE-2024-6578)
cross-site scripting in aim (CVE-2024-6578). Risk of unauthorized operations or information disclosure. Exploitable via ``dangerouslySetInnerHTML``.
|
| CVE-2024-6281 |
|
Path Traversal in lollms (CVE-2024-6281)
path traversal in lollms (CVE-2024-6281). Risk of unauthorized operations or information disclosure. Exploitable via ``apply_settings``. Mitigation: upgrade to `9.5.1` or later.
|
| CVE-2024-5569 |
|
Vulnerability in zipp (CVE-2024-5569)
vulnerability in zipp (CVE-2024-5569). Risk of unauthorized operations or information disclosure. Exploitable via ``Path``. Mitigation: upgrade to `3.19.1` or later.
|
| CVE-2024-39303 |
|
Vulnerability in weblate (CVE-2024-39303)
vulnerability in weblate (CVE-2024-39303). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.6.2` or later.
|
| CVE-2024-5753 |
|
Information Disclosure in vanna (CVE-2024-5753)
vulnerability in vanna (CVE-2024-5753). Confidential information can be exposed externally.
|
| CVE-2024-38519 |
|
Unrestricted File Upload in yt-dlp (CVE-2024-38519)
vulnerability in yt-dlp (CVE-2024-38519). Successful exploitation can lead to full system takeover. Exploitable via ``system32``. Mitigation: upgrade to `2024.07.01` or later.
|
| CVE-2024-40627 |
|
Vulnerability in fastapi-opa (CVE-2024-40627)
vulnerability in fastapi-opa (CVE-2024-40627). Risk of unauthorized operations or information disclosure. Exploitable via ``OPTIONS``. Mitigation: upgrade to `2.0.1` or later.
|
| CVE-2024-39903 |
|
Path Traversal in solara (CVE-2024-39903)
path traversal in solara (CVE-2024-39903). Confidential information can be exposed externally. Mitigation: upgrade to `1.35.1` or later.
|
| CVE-2024-39905 |
|
Authorization Flaw in red-discordbot (CVE-2024-39905)
vulnerability in red-discordbot (CVE-2024-39905). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.5.10` or later.
|
| CVE-2024-5824 |
|
Path Traversal in lollms (CVE-2024-5824)
path traversal in lollms (CVE-2024-5824). Successful exploitation can lead to full system takeover. Exploitable via ``force_accept_remote_access``. Mitigation: upgrade to `9.5.0` or later.
|
| CVE-2024-38537 |
|
Vulnerability in ethyca-fides (CVE-2024-38537)
vulnerability in ethyca-fides (CVE-2024-38537). Risk of unauthorized operations or information disclosure. Exploitable via ``polyfill.io``. Mitigation: upgrade to `2.39.1` or later.
|
| CVE-2024-31223 |
|
Vulnerability in ethyca-fides (CVE-2024-31223)
vulnerability in ethyca-fides (CVE-2024-31223). Risk of unauthorized operations or information disclosure. Exploitable via ``SERVER_SIDE_FIDES_API_URL``. Mitigation: upgrade to `2.39.2` or later.
|
| CVE-2024-6227 |
|
Vulnerability in aim (CVE-2024-6227)
vulnerability in aim (CVE-2024-6227). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-22231 |
|
Path Traversal in salt (CVE-2024-22231)
path traversal in salt (CVE-2024-22231). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3006.6` or later.
|
| CVE-2024-4460 |
|
Vulnerability in zenml (CVE-2024-4460)
vulnerability in zenml (CVE-2024-4460). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.57.1` or later.
|
| CVE-2024-22232 |
|
Path Traversal in salt (CVE-2024-22232)
path traversal in salt (CVE-2024-22232). Confidential information can be exposed externally. Mitigation: upgrade to `3006.6` or later.
|
| CVE-2024-4940 |
|
Open Redirect in gradio (CVE-2024-4940)
vulnerability in gradio (CVE-2024-4940). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-5979 |
|
Vulnerability in h2o (CVE-2024-5979)
vulnerability in h2o (CVE-2024-5979). Risk of unauthorized operations or information disclosure. Exploitable via ``run_tool``.
|