NA - CVE-2024-3379 - In lunary-ai/lunary versions 1.2.2 through...
In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key for projects they do not have access to....
NA - CVE-2024-3501 - In lunary-ai/lunary versions up to and...
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclusion of single-use tokens in the responses of `GET /v1/users/me` and `GET...
NA - CVE-2024-3502 - In lunary-ai/lunary versions up to and...
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists where account recovery hashes of users are inadvertently exposed to unauthorized actors. This...
NA - CVE-2024-48284 - A Reflected Cross-Site Scripting (XSS)...
A Reflected Cross-Site Scripting (XSS) vulnerability was found in the /search-result.php page of the PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows...
NA - CVE-2024-49362 - Joplin is a free, open source note taking and...
Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user clicks on an link within untrusted notes....
NA - CVE-2024-4311 - zenml-io/zenml version 0.56.4 is vulnerable to...
zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password change function. An attacker can brute-force the current password in the...
NA - CVE-2024-4343 - A Python command injection vulnerability exists...
A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/components/llm/custom/sagemaker.py` of the imartinez/privategpt...
NA - CVE-2024-50823 - A SQL Injection vulnerability was found in...
A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.