Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2024-38526 Vulnerability in pdoc (CVE-2024-38526)
vulnerability in pdoc (CVE-2024-38526). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.5.1` or later.
CVE-2024-3121 OS Command Injection in lollms (CVE-2024-3121)
OS command injection in lollms (CVE-2024-3121). Successful exploitation can lead to full system takeover.
CVE-2024-6085 Path Traversal in lollms (CVE-2024-6085)
path traversal in lollms (CVE-2024-6085). Confidential information can be exposed externally.
CVE-2024-6139 Vulnerability in lollms (CVE-2024-6139)
vulnerability in lollms (CVE-2024-6139). Risk of unauthorized operations or information disclosure. Exploitable via ``tts_to_file``.
CVE-2024-28397 Code Injection in js2py (CVE-2024-28397)
code injection in js2py (CVE-2024-28397). Successful exploitation can lead to full system takeover.
CVE-2024-21520 Cross-Site Scripting (XSS) in djangorestframework (CVE-2024-21520)
cross-site scripting in djangorestframework (CVE-2024-21520). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.15.2` or later.
CVE-2024-5710 Vulnerability in litellm (CVE-2024-5710)
vulnerability in litellm (CVE-2024-5710). Data can be tampered with by attackers. Mitigation: upgrade to `1.40.15` or later.
CVE-2024-37891 Vulnerability in urllib3 (CVE-2024-37891)
vulnerability in urllib3 (CVE-2024-37891). Confidential information can be exposed externally. Exploitable via ``ProxyManager``. Mitigation: upgrade to `2.2.2` or later.
CVE-2024-4680 Vulnerability in zenml (CVE-2024-4680)
vulnerability in zenml (CVE-2024-4680). Risk of unauthorized operations or information disclosure.
CVE-2024-5225 SQL Injection in litellm (CVE-2024-5225)
SQL injection in litellm (CVE-2024-5225). Risk of unauthorized operations or information disclosure. Exploitable via ``api_key``. Mitigation: upgrade to `1.40.0` or later.
CVE-2024-3429 Path Traversal in lollms (CVE-2024-3429)
path traversal in lollms (CVE-2024-3429). Successful exploitation can lead to full system takeover. Exploitable via ``sanitize_path_from_endpoint``. Mitigation: upgrade to `9.5.0` or later.
CVE-2024-34694 Vulnerability in lnbits (CVE-2024-34694)
vulnerability in lnbits (CVE-2024-34694). Data can be tampered with by attackers. Mitigation: upgrade to `0.12.6` or later.
CVE-2024-4890 SQL Injection in litellm (CVE-2024-4890)
SQL injection in litellm (CVE-2024-4890). Confidential information can be exposed externally.
CVE-2024-4888 Vulnerability in litellm (CVE-2024-4888)
vulnerability in litellm (CVE-2024-4888). Data can be tampered with by attackers. Mitigation: upgrade to `1.35.36` or later.
CVE-2024-37388 XXE (XML External Entity) in ebookmeta (CVE-2024-37388)
vulnerability in ebookmeta (CVE-2024-37388). Confidential information can be exposed externally. Exploitable via ``ebookmeta.get_metadata``. Mitigation: upgrade to `1.2.8` or later.
CVE-2024-37301 Vulnerability in document-merge-service (CVE-2024-37301)
vulnerability in document-merge-service (CVE-2024-37301). Successful exploitation can lead to full system takeover. Exploitable via ``subprocess.Popen``. Mitigation: upgrade to `6.5.2` or later.
CVE-2024-38357 Cross-Site Scripting (XSS) in django-tinymce (CVE-2024-38357)
cross-site scripting in django-tinymce (CVE-2024-38357). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.1.0` or later.
CVE-2024-38356 Cross-Site Scripting (XSS) in django-tinymce (CVE-2024-38356)
cross-site scripting in django-tinymce (CVE-2024-38356). Risk of unauthorized operations or information disclosure. Exploitable via ``noneditable_regexp``. Mitigation: upgrade to `4.1.0` or later.
CVE-2024-37300 Authorization Flaw in oauthenticator (CVE-2024-37300)
vulnerability in oauthenticator (CVE-2024-37300). Confidential information can be exposed externally. Exploitable via ``GlobusOAuthenticator``. Mitigation: upgrade to `16.3.1` or later.
CVE-2024-5550 Information Disclosure in h2o (CVE-2024-5550)
vulnerability in h2o (CVE-2024-5550). Risk of unauthorized operations or information disclosure.
ECHO-84ae-05ad-87cf ECHO-84ae-05ad-87cf
ECHO-3b80-9e26-3298 ECHO-3b80-9e26-3298
CVE-2026-6101 Vulnerability in wordpress (CVE-2026-6101)
vulnerability in wordpress (CVE-2026-6101). Successful exploitation can lead to full system takeover.
CVE-2026-53479 OS Command Injection in dell (CVE-2026-53479)
OS command injection in dell (CVE-2026-53479). Successful exploitation can lead to full system takeover.
ECHO-71f5-8e5e-5945 ECHO-71f5-8e5e-5945
MINI-8rqg-vhvg-wq2v MINI-8rqg-vhvg-wq2v
MINI-5x88-jcc9-8hjq MINI-5x88-jcc9-8hjq
GHSA-q6cv-rc8j-6pp7 Vulnerability in @engagehub/test-claim (GHSA-q6cv-rc8j-6pp7)
vulnerability in @engagehub/test-claim (GHSA-q6cv-rc8j-6pp7). Risk of unauthorized operations or information disclosure.
GHSA-hpc6-h2fp-hcpj Vulnerability in brunomenozzi-test-pkg (GHSA-hpc6-h2fp-hcpj)
vulnerability in brunomenozzi-test-pkg (GHSA-hpc6-h2fp-hcpj). Risk of unauthorized operations or information disclosure.
MINI-xvgx-6h8h-v475 MINI-xvgx-6h8h-v475
MINI-gqwv-9rfj-r275 MINI-gqwv-9rfj-r275
MINI-x9wf-8324-h6jw MINI-x9wf-8324-h6jw
MINI-pc67-px3c-xcmc MINI-pc67-px3c-xcmc
MINI-rhfw-4pjv-h2c4 MINI-rhfw-4pjv-h2c4
MINI-pvhq-q572-3735 MINI-pvhq-q572-3735
MINI-7x7r-xq34-6vpc MINI-7x7r-xq34-6vpc
MINI-hcc4-2j3h-985c MINI-hcc4-2j3h-985c
MINI-ccwr-rjhx-7288 MINI-ccwr-rjhx-7288
MINI-j227-q669-crm6 MINI-j227-q669-crm6
MINI-636m-3c6f-43xc MINI-636m-3c6f-43xc
MINI-ghxx-chrp-v7h2 MINI-ghxx-chrp-v7h2
MINI-vfmv-gr5q-chrc MINI-vfmv-gr5q-chrc
MINI-qcrp-h9w2-h64r MINI-qcrp-h9w2-h64r
MINI-hx5x-9h8h-5mgq MINI-hx5x-9h8h-5mgq
MINI-gc94-53wx-58c5 MINI-gc94-53wx-58c5
MINI-rwrh-x52v-6gqr MINI-rwrh-x52v-6gqr
MINI-jf37-wwhq-7hfx MINI-jf37-wwhq-7hfx
MINI-c9h2-c888-858r MINI-c9h2-c888-858r
MINI-p887-mcv7-m665 MINI-p887-mcv7-m665
MINI-9xv2-2gvj-7hqp MINI-9xv2-2gvj-7hqp

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →