NA - CVE-2024-11041 - vllm-project vllm version v0.6.2 contains a...
vllm-project vllm version v0.6.2 contains a vulnerability in the MessageQueue.dequeue() API function. The function uses pickle.loads to parse received sockets directly, leading to a remote code...
NA - CVE-2024-11042 - In invoke-ai/invokeai version v5.0.2, the web...
In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion. This vulnerability allows unauthorized attackers to delete arbitrary files...
NA - CVE-2024-11043 - A Denial of Service (DoS) vulnerability was...
A Denial of Service (DoS) vulnerability was discovered in the /api/v1/boards/{board_id} endpoint of invoke-ai/invokeai version v5.0.2. This vulnerability occurs when an excessively large payload is...
NA - CVE-2024-11044 - An open redirect vulnerability in...
An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL....
NA - CVE-2024-11045 - A Cross-Site WebSocket Hijacking (CSWSH)...
A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The...
NA - CVE-2024-11137 - An Insecure Direct Object Reference (IDOR)...
An Insecure Direct Object Reference (IDOR) vulnerability exists in the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/lunary version 1.6.0. This vulnerability allows an attacker to update the...
NA - CVE-2024-11167 - An improper access control vulnerability in...
An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs...
NA - CVE-2024-11169 - An unhandled exception in danny-avila/librechat...
An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs module throws an exception while handling file uploads. An unauthenticated...
High - CVE-2024-13558 - The NP Quote Request for WooCommerce plugin for...
The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.179 due to missing validation on a user...
Medium - CVE-2024-13920 - The Order Export & Order Import for WooCommerce...
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the download_file() function. This makes it...