CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2024-10724

    Last Modified: 28 May 2025

    A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when editing the Destination address. This vulnerability allows an attacker to execute malicious code. The issue is fixed in version 1.7.0.

    Published: 20 Mar 2025
    8.3
    High

    CVE-2024-10109

    Last Modified: 11 Jul 2025

    A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "/api/system/custom-models". This access enables them to modify the model's API key and base path, leading to potential API key leakage and denial of service on chats.

    Published: 20 Mar 2025
    6.1
    Medium

    CVE-2024-10812

    Last Modified: 14 Jul 2025

    An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is redirected to a URL specified by user-controlled input in the 'file' parameter without proper validation or sanitization. This can be exploited by attackers to conduct phishing attacks, distribute malware, and steal user credentials.

    Published: 20 Mar 2025
    5.4
    Medium

    CVE-2024-10723

    Last Modified: 28 May 2025

    A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the destination address field of the NAT tool, which can be executed when a user interacts with the field. The impact of this vulnerability includes the potential theft of user cookies, unauthorized access to user accounts, and redirection to malicious websites. The issue has been fixed in version 1.7.0.

    Published: 20 Mar 2025
    6.5
    Medium

    CVE-2024-12775

    Last Modified: 14 Jul 2025

    langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool option via the REST API `POST /console/api/workspaces/current/tool-provider/api/test/pre`. Attackers can set the `url` in the `servers` dictionary in OpenAI's schema with arbitrary URL targets, allowing them to abuse the victim server's credentials to access unauthorized web resources.

    Published: 20 Mar 2025
    7.5
    High

    CVE-2024-10110

    Last Modified: 23 Jul 2025

    In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading to the main thread being blocked indefinitely. This results in a denial of service as the tracking server becomes unable to respond to other requests.

    Published: 20 Mar 2025
    9.8
    Critical

    CVE-2024-12909

    Last Modified: 30 Jul 2025

    A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql_query` function of the `database_agent`. This vulnerability can be exploited by an attacker to inject arbitrary SQL queries, leading to remote code execution (RCE) through the use of PostgreSQL's large object functionality. The issue is fixed in version 0.3.0.

    Published: 20 Mar 2025
    5.3
    Medium

    CVE-2024-12580

    Last Modified: 14 Jul 2025

    A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionId, fileId, userId, and file_id in the /code/download/:sessionId/:fileId and /download/:userId/:file_id APIs are not validated or filtered, leading to potential log injection attacks. This can cause distortion of monitoring and investigation information, evade detection from security systems, and create difficulties in maintenance and operation.

    Published: 20 Mar 2025
    7.5
    High

    CVE-2024-11031

    Last Modified: 15 Jul 2025

    In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerability is exploited through the HotReload(Markdown翻译中) plugin function, which allows downloading arbitrary web hosts by only checking if the link starts with 'http'. Attackers can exploit this vulnerability to abuse the victim GPT Academic's Gradio Web server's credentials to access unauthorized web resources.

    Published: 20 Mar 2025
    5.4
    Medium

    CVE-2024-10725

    Last Modified: 28 May 2025

    A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which are then executed in the context of other users who view the affected pages. The issue occurs when editing the NAT destination address, where user input is not properly sanitized. This can lead to data theft, account compromise, and other malicious activities. The vulnerability is fixed in version 1.7.0.

    Published: 20 Mar 2025
    7.5
    High

    CVE-2024-11822

    Last Modified: 1 Apr 2025

    langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due to improper handling of the api_endpoint parameter, allowing an attacker to make direct requests to internal network services. This can lead to unauthorized access to internal servers and potentially expose sensitive information, including access to the AWS metadata endpoint.

    Published: 20 Mar 2025
    7.6
    High

    CVE-2024-11824

    Last Modified: 14 Jul 2025

    A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log functionality. The vulnerability arises because certain HTML tags like <input> and <form> are not disallowed, allowing an attacker to inject malicious HTML into the log via prompts. When an admin views the log containing the malicious HTML, the attacker could steal the admin's credentials or sensitive information. This issue is fixed in version 0.12.1.

    Published: 20 Mar 2025
    9.1
    Critical

    CVE-2024-10831

    Last Modified: 17 Jul 2025

    In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the `file_key` and `doc_file.filename` parameters are user-controllable, enabling the construction of paths outside the intended directory. This can lead to overwriting essential system files, such as SSH keys, for further exploitation.

    Published: 20 Mar 2025
    9.8
    Critical

    CVE-2024-10096

    Last Modified: 26 Mar 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 20 Mar 2025
    9.8
    Critical

    CVE-2024-10553

    Last Modified: 14 Jul 2025

    A vulnerability in the h2oai/h2o-3 REST API versions 3.46.0.4 allows unauthenticated remote attackers to execute arbitrary code via deserialization of untrusted data. The vulnerability exists in the endpoints POST /99/ImportSQLTable and POST /3/SaveToHiveTable, where user-controlled JDBC URLs are passed to DriverManager.getConnection, leading to deserialization if a MySQL or PostgreSQL driver is available in the classpath. This issue is fixed in version 3.47.0.

    Published: 20 Mar 2025
    8.8
    High

    CVE-2024-11170

    Last Modified: 15 Jul 2025

    A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middleware. This can lead to arbitrary file write and potentially remote code execution. The issue is fixed in version 0.7.6.

    Published: 20 Mar 2025
    4.3
    Medium

    CVE-2024-11821

    Last Modified: 14 Jul 2025

    A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to modify Orchestrate instructions for a chatbot created by an admin user. The issue arises because the application does not properly enforce access controls on the endpoint /console/api/apps/{chatbot-id}/model-config, allowing unauthorized users to alter chatbot configurations.

    Published: 20 Mar 2025
    6.5
    Medium

    CVE-2024-11037

    Last Modified: 31 Jul 2025

    A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass the blocked_paths protection and read the config.py file containing sensitive information such as the OpenAI API key. This vulnerability is exploitable on Windows operating systems by accessing a specific URL that includes the absolute path of the project.

    Published: 20 Mar 2025
    7.5
    High

    CVE-2024-11449

    Last Modified: 14 Jul 2025

    A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the /run/predict endpoint. An attacker can gain unauthorized access to internal networks or the AWS metadata endpoint by sending crafted requests that exploit insufficient validation of the path parameter. This flaw can lead to unauthorized network access, sensitive data exposure, and further exploitation within the network.

    Published: 20 Mar 2025
    7.5
    High

    CVE-2024-12055

    Last Modified: 13 May 2025

    A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be uploaded to the public Ollama server. When the server processes this malicious model, it crashes, leading to a Denial of Service (DoS) attack. The root cause of the issue is an out-of-bounds read in the gguf.go file.

    Published: 20 Mar 2025
    7.4
    High

    CVE-2025-22228

    Last Modified: 15 Apr 2026

    BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.

    Published: 20 Mar 2025
    5.3
    Medium

    CVE-2025-1766

    Last Modified: 20 Apr 2026

    The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'payment_complete' function in all versions up to, and including, 4.0.24. This makes it possible for unauthenticated attackers to update the status of ticket payments to 'completed', possibly resulting in financial loss.

    Published: 20 Mar 2025
    8.8
    High

    CVE-2025-1770

    Last Modified: 21 Apr 2026

    The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.24 via the 'style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published: 20 Mar 2025
    4.3
    Medium

    CVE-2025-1314

    Last Modified: 22 Apr 2026

    The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.5. This is due to missing or incorrect nonce validation on the ctf_clear_cache_admin() function. This makes it possible for unauthenticated attackers to reset the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 20 Mar 2025
    7.1
    High

    CVE-2024-13881

    Last Modified: 8 Apr 2025

    The Link My Posts WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 20 Mar 2025
    7.1
    High

    CVE-2024-13880

    Last Modified: 8 Apr 2025

    The My Quota WordPress plugin through 1.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 20 Mar 2025
    7.1
    High

    CVE-2024-13878

    Last Modified: 8 Apr 2025

    The SpotBot WordPress plugin through 0.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 20 Mar 2025
    7.1
    High

    CVE-2024-13877

    Last Modified: 9 Apr 2025

    The Passbeemedia Web Push Notification WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 20 Mar 2025
    7.1
    High

    CVE-2024-13876

    Last Modified: 9 Apr 2025

    The mEintopf WordPress plugin through 0.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 20 Mar 2025
    7.1
    High

    CVE-2024-13875

    Last Modified: 10 Apr 2025

    The WP-PManager WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 20 Mar 2025
    4.8
    Medium

    CVE-2025-29412

    Last Modified: 1 Apr 2025

    A cross-site scripting (XSS) vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.

    Published: 20 Mar 2025
    6.5
    Medium

    CVE-2025-29217

    Last Modified: 25 Mar 2025

    Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiSSID parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 20 Mar 2025
    9.8
    Critical

    CVE-2024-48590

    Last Modified: 1 Apr 2025

    Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to escalate privileges and obtain sensitive information.

    Published: 20 Mar 2025
    6.1
    Medium

    CVE-2024-48591

    Last Modified: 1 Apr 2025

    Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded that will render and execute JavaScript upon direct viewing.

    Published: 20 Mar 2025
    7.5
    High

    CVE-2024-57440

    Last Modified: 20 Jan 2026

    D-Link DSL-3788 revA1 1.01R1B036_EU_EN is vulnerable to Buffer Overflow via the COMM_MAKECustomMsg function of the webproc cgi

    Published: 20 Mar 2025
    7.5
    High

    CVE-2025-25758

    Last Modified: 1 Apr 2025

    An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml

    Published: 20 Mar 2025
    10
    Critical

    CVE-2025-26852

    Last Modified: 23 Apr 2025

    DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection.

    Published: 20 Mar 2025
    10
    Critical

    CVE-2025-26853

    Last Modified: 23 Apr 2025

    DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.

    Published: 20 Mar 2025
    7.5
    High

    CVE-2025-29101

    Last Modified: 25 Mar 2025

    Tenda AC8V4.0 V16.03.34.06 was discovered to contain a stack overflow via the deviceid parameter in the get_parentControl_list_Info function.

    Published: 20 Mar 2025
    7.5
    High

    CVE-2025-29121

    Last Modified: 28 Mar 2025

    A vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_setting_wifi_set file form_fast_setting_wifi_set. Using the timeZone parameter causes a stack-based buffer overflow.

    Published: 20 Mar 2025
    7.5
    High

    CVE-2025-29149

    Last Modified: 27 Mar 2025

    Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.

    Published: 20 Mar 2025
    6.5
    Medium

    CVE-2025-29215

    Last Modified: 25 Mar 2025

    Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_43fdcc function at /goform/SetNetControlList.

    Published: 20 Mar 2025
    7.5
    High

    CVE-2025-29214

    Last Modified: 25 Mar 2025

    Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_42F69C function at /goform/setMacFilterCfg.

    Published: 20 Mar 2025
    6.5
    Medium

    CVE-2025-29218

    Last Modified: 26 Mar 2025

    Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiPwd parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 20 Mar 2025
    6.1
    Medium

    CVE-2025-29410

    Last Modified: 1 Apr 2025

    A cross-site scripting (XSS) vulnerability in the component /contact.php of Hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the txtEmail parameter.

    Published: 20 Mar 2025
    9.8
    Critical

    CVE-2025-29411

    Last Modified: 28 Mar 2025

    An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

    Published: 20 Mar 2025
    4.9
    Medium

    CVE-2025-2559

    Last Modified: 21 Sept 2026

    A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOfMemoryError. This issue could result in a denial of service condition, preventing legitimate users from accessing the system.

    Published: 20 Mar 2025
    8.8
    High

    CVE-2025-27774

    Last Modified: 1 Aug 2025

    Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py` (line 156 in 3.2.7). The blind SSRF allows for sending requests on behalf of Applio server and can be leveraged to probe for other vulnerabilities on the server itself or on other back-end systems on the internal network, that the Applio server can reach. The blind SSRF can also be coupled with the an arbitrary file read (e.g., CVE-2025-27784) to read files from hosts on the internal network, that the Applio server can reach, which would make it a full SSRF. The file write allows for writing files on the server, which can be coupled with other vulnerabilities, for example an unsafe deserialization, to achieve remote code execution on the Applio server. As of time of publication, no known patches are available.

    Published: 19 Mar 2025
    8.8
    High

    CVE-2025-27775

    Last Modified: 1 Aug 2025

    Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py` (line 143 in 3.2.7). The blind SSRF allows for sending requests on behalf of Applio server and can be leveraged to probe for other vulnerabilities on the server itself or on other back-end systems on the internal network, that the Applio server can reach. The file write allows for writing files on the server, which can be coupled with other vulnerabilities, for example an unsafe deserialization, to achieve remote code execution on the Applio server. As of time of publication, no known patches are available.

    Published: 19 Mar 2025
    8.8
    High

    CVE-2025-27776

    Last Modified: 1 Aug 2025

    Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py` (line 240 in 3.2.7). The blind SSRF allows for sending requests on behalf of Applio server and can be leveraged to probe for other vulnerabilities on the server itself or on other back-end systems on the internal network, that the Applio server can reach. The blind SSRF can also be coupled with the arbitrary file read CVE-2025-27784 to read files from hosts on the internal network, that the Applio server can reach, which would make it a full SSRF. The file write allows for writing files on the server, which can be coupled with other vulnerabilities, for example an unsafe deserialization, to achieve remote code execution on the Applio server. As of time of publication, no known patches are available.

    Published: 19 Mar 2025