Click to open the Alert Filter

 
Year Month
Severity
Categories
Search by Alert Name
Page(s) : 1 ... 60 61 62 63 64 65 66 67 68 69 [70] 71 72 73 74 75 76 77 78 79 80 ... Result(s) : 97115

Alerts Feed Alerts

DATE NAME CATEGORIES DETAIL
8.8 2025-03-21 CVE-2025-25274 cve Mattermost versions 10.4.x
8.7 2025-03-21 CVE-2025-29807 cve Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
8.8 2025-03-21 CVE-2025-2585 cve EBM Maintenance Center From EBM Technologies has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL commands to read, modif...
8.8 2025-03-20 CVE-2025-23120 cve A vulnerability allowing remote code execution (RCE) for domain users.
7.2 2025-03-20 CVE-2024-13921 cve The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 via deserialization of unt...
7.5 2025-03-20 CVE-2025-2539 cve The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3....
8.8 2025-03-20 CVE-2025-1770 cve The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.24 via ...
7.5 2025-03-20 CVE-2024-10718 cve In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext ove...
7.5 2025-03-20 CVE-2024-11822 cve langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due to improper handling of the api_endpoint parameter, allow...
7.5 2025-03-20 CVE-2024-12055 cve A vulnerability in Ollama versions
7.5 2025-03-20 CVE-2024-12537 cve In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the `api/v1/utils/code/format` endpoint. If a ...
7.5 2025-03-20 CVE-2024-12779 cve A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. The vulnerability is present in the `POST /v1/llm/add_llm` and `POST /v1/conversa...
7.5 2025-03-20 CVE-2024-7765 cve In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cause a denial of service. The server becomes unresponsive d...
8.1 2025-03-20 CVE-2024-7767 cve An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system to view, modify, and delete...
8.8 2025-03-20 CVE-2024-7806 cve A vulnerability in open-webui/open-webui versions
8.1 2025-03-20 CVE-2024-8026 cve A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The backend server has overly permissive CORS head...
8.2 2025-03-20 CVE-2024-8053 cve In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation ser...
7.5 2025-03-20 CVE-2024-8062 cve A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a `HEAD` request to verify the existence of a speci...
7.5 2025-03-20 CVE-2024-8063 cve A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile...
8.8 2025-03-20 CVE-2024-8501 cve An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0.4. This vulnerability allows any user to download any fil...
Page(s) : 1 ... 60 61 62 63 64 65 66 67 68 69 [70] 71 72 73 74 75 76 77 78 79 80 ... Result(s) : 97115