A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "/api/system/custom-models". This access enables...
NA - CVE-2024-10110 - In version 3.23.0 of aimhubio/aim, the...
In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading to the main thread being blocked indefinitely....
NA - CVE-2024-10188 - A vulnerability in BerriAI/litellm, as of...
A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of ast.literal_eval to parse user input. This...
NA - CVE-2024-10190 - Horovod versions up to and including v0.28.1...
Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability is due to improper handling of base64-encoded data in the...
NA - CVE-2024-10225 - A vulnerability in haotian-liu/llava v1.2.0...
A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large number of characters to the end of a multipart boundary in a file upload...
NA - CVE-2024-10264 - HTTP Request Smuggling vulnerability in...
HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistencies in the interpretation of HTTP requests between a proxy and a server. This...
NA - CVE-2024-10267 - An information disclosure vulnerability exists...
An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can leak sensitive user information, including names, emails, and passwords, by...
NA - CVE-2024-10272 - lunary-ai/lunary is vulnerable to broken access...
lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any dataset without any kind of authorization by sending a GET request to the...
NA - CVE-2024-10273 - In lunary-ai/lunary v1.5.0, improper privilege...
In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify models owned by others. The PATCH endpoint for models does not have...