NA - CVE-2024-11031 - In version 3.83 of binary-husky/gpt_academic, a...
In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerability is exploited...
NA - CVE-2024-11033 - A Denial of Service (DoS) vulnerability exists...
A Denial of Service (DoS) vulnerability exists in the file upload feature of binary-husky/gpt_academic version 3.83. The vulnerability is due to improper handling of form-data with a large filename...
NA - CVE-2024-11037 - A path traversal vulnerability exists in...
A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass the blocked_paths protection and read the config.py file containing...
NA - CVE-2024-11039 - A pickle deserialization vulnerability exists...
A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt_academic versions up to and including 3.83. This vulnerability allows...
NA - CVE-2024-11040 - vllm-project vllm version 0.5.2.2 is vulnerable...
vllm-project vllm version 0.5.2.2 is vulnerable to Denial of Service attacks. The issue occurs in the 'POST /v1/completions' and 'POST /v1/embeddings' endpoints. For 'POST...
NA - CVE-2024-11041 - vllm-project vllm version v0.6.2 contains a...
vllm-project vllm version v0.6.2 contains a vulnerability in the MessageQueue.dequeue() API function. The function uses pickle.loads to parse received sockets directly, leading to a remote code...
NA - CVE-2024-11042 - In invoke-ai/invokeai version v5.0.2, the web...
In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion. This vulnerability allows unauthorized attackers to delete arbitrary files...
NA - CVE-2024-11043 - A Denial of Service (DoS) vulnerability was...
A Denial of Service (DoS) vulnerability was discovered in the /api/v1/boards/{board_id} endpoint of invoke-ai/invokeai version v5.0.2. This vulnerability occurs when an excessively large payload is...
NA - CVE-2024-11044 - An open redirect vulnerability in...
An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL....
NA - CVE-2024-11045 - A Cross-Site WebSocket Hijacking (CSWSH)...
A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The...