Vulnerabilities > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-06-06 | CVE-2024-3429 | Path Traversal vulnerability in Lollms A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` functions in `lollms_core\lollms\security.py`. | 9.8 |
2024-06-06 | CVE-2024-4320 | Path Traversal vulnerability in Lollms web UI A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_extension")` route handler. | 9.8 |
2024-06-06 | CVE-2024-5328 | Unspecified vulnerability in Lunary A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the endpoint '/auth/saml/tto/download-idp-xml'. | 9.3 |
2024-06-06 | CVE-2024-1873 | Unspecified vulnerability in Lollms web UI parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database` endpoint in version a9d16b0. | 9.1 |
2024-06-06 | CVE-2024-1881 | Unspecified vulnerability in Agpt Autogpt 0.5.0 AutoGPT, a component of significant-gravitas/autogpt, is vulnerable to an improper neutralization of special elements used in an OS command ('OS Command Injection') due to a flaw in its shell command validation function. | 9.8 |
2024-06-06 | CVE-2024-2359 | Unspecified vulnerability in Lollms web UI 9.3 A vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and execute arbitrary code. | 9.8 |
2024-06-06 | CVE-2024-2360 | Path Traversal vulnerability in Lollms web UI parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitization of user-supplied input in the 'Database path' and 'PDF LaTeX path' settings. | 9.8 |
2024-06-06 | CVE-2024-2362 | Path Traversal vulnerability in Lollms web UI 9.3 A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. | 9.1 |
2024-06-06 | CVE-2024-2624 | Path Traversal vulnerability in Lollms web UI A path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically within the `@router.get("/switch_personal_path")` endpoint in `./lollms-webui/lollms_core/lollms/server/endpoints/lollms_user.py`. | 9.8 |
2024-06-06 | CVE-2024-36736 | Incorrect Calculation vulnerability in Oneflow 0.9.1 An issue in the oneflow.permute component of OneFlow-Inc. | 9.8 |