Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Chuanhuchatgpt MEDIUM 6.5
CVE-2025-0191

A Denial of Service (DoS) vulnerability exists in the file upload feature of gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability is due to…

No fix yet
Fix from $1,600 2025-03-20
Anythingllm MEDIUM 6.5
CVE-2024-7771

A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denial of service. Uploading an au…

Fix: 1.3.1+
Fix from $1,600 2025-03-20
Open Webui HIGH 7.5
CVE-2024-7036

A vulnerability in open-webui/open-webui v0.3.8 allows an unauthenticated attacker to sign up with excessively large text in the 'name' field, causin…

No fix yet
Fix from $1,950 2025-03-20
Mlflow MEDIUM 5.3
CVE-2024-6838

In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its…

No fix yet
Fix from $1,600 2025-03-20
Qanything HIGH 7.5
CVE-2024-12864

A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2.0.0. The vulnerability is du…

No fix yet
Fix from $1,950 2025-03-20
Open Webui HIGH 7.5
CVE-2024-12534

In version v0.3.32 of open-webui/open-webui, the application allows users to submit large payloads in the email and password fields during the sign-i…

No fix yet
Fix from $1,950 2025-03-20
Unclassified HIGH 7.5
CVE-2024-12761

A Denial of Service (DoS) vulnerability exists in the brycedrennan/imaginairy repository, version 15.0.0. The vulnerability is present in the `/api/s…

Mitigation only
Fix from $1,950 2025-03-20
Large Language And Vision Assistant HIGH 7.5
CVE-2024-12070

A Denial of Service (DoS) vulnerability exists in the file upload feature of haotian-liu/llava, specifically in Release v1.2.0 (LLaVA-1.6). The vulne…

No fix yet
Fix from $1,950 2025-03-20
Stable Diffusion Webui MEDIUM 6.5
CVE-2024-12074

A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webui version 1.10.0. The vulnera…

No fix yet
Fix from $1,600 2025-03-20
Privategpt HIGH 7.5
CVE-2024-12063

A Denial of Service (DoS) vulnerability exists in the file upload feature of imartinez/privategpt version v0.6.2. The vulnerability is due to imprope…

No fix yet
Fix from $1,950 2025-03-20
Unclassified HIGH 7.5
CVE-2024-11043

A Denial of Service (DoS) vulnerability was discovered in the /api/v1/boards/{board_id} endpoint of invoke-ai/invokeai version v5.0.2. This vulnerabi…

Mitigation only
Fix from $1,950 2025-03-20
Gpt Academic MEDIUM 6.5
CVE-2024-11033

A Denial of Service (DoS) vulnerability exists in the file upload feature of binary-husky/gpt_academic version 3.83. The vulnerability is due to impr…

No fix yet
Fix from $1,600 2025-03-20
Fastchat HIGH 7.5
CVE-2024-10912

A Denial of Service (DoS) vulnerability exists in the file upload feature of lm-sys/fastchat version 0.2.36. The vulnerability is due to improper han…

No fix yet
Fix from $1,950 2025-03-20
Aim HIGH 7.5
CVE-2024-10110

In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading t…

No fix yet
Fix from $1,950 2025-03-20
Unclassified HIGH 7.5
CVE-2024-10188

A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of as…

Patch available
Fix from $1,950 2025-03-20
Jspdf HIGH 7.5
CVE-2025-29907

jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user control of the first argument of the addImage method results in CPU utilizati…

Fix: 3.0.1+
Fix from $1,950 2025-03-18
Omniauth Saml HIGH 7.5
CVE-2025-25293

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is suscept…

Fix: 1.10.6 / 1.12.4+
Fix from $1,950 2025-03-12
Pan Os HIGH 7.5
CVE-2025-0114

A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to ren…

Fix: 10.1.14 / 10.2.5+
Fix from $1,950 2025-03-12
Safari MEDIUM 5.5
CVE-2024-44192

The issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS …

Fix: 2.0 / 11.0+
Fix from $1,600 2025-03-10
Ipados HIGH 7.5
CVE-2024-44227

The issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to cause une…

Fix: 15.0 / 18.0+
Fix from $1,950 2025-03-10
macOS HIGH 7.5
CVE-2024-54546

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to cause unexpected system termina…

Fix: 15.0+
Fix from $1,950 2025-03-10
Qts HIGH 7.1
CVE-2024-53693

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If …

Mitigation only
Fix from $1,950 2025-03-07
Multi Server HIGH 7.5
CVE-2024-53458

Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets.

No fix yet
Fix from $1,950 2025-03-05
Vasion Print HIGH 7.5
CVE-2025-27669

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Network Scanning (XSPA)/DoS OVE-20230…

Fix: 20.0.1923 / 22.0.843+
Fix from $1,950 2025-03-05
Unclassified HIGH 7.5
CVE-2025-27421

Abacus is a highly scalable and stateless counting API. A critical goroutine leak vulnerability has been identified in the Abacus server's Server-Sen…

Patch available
Fix from $1,950 2025-03-03
Unclassified MEDIUM 5.7
CVE-2024-34035

An issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must flood the system with a signifi…

Mitigation only
Fix from $1,600 2025-02-25
Unclassified MEDIUM 6.5
CVE-2025-27100

lakeFS is an open-source tool that transforms your object storage into a Git-like repository. In affected versions an authenticated user can crash la…

Patch available
Fix from $1,600 2025-02-21
Graphql Mesh HIGH 7.5
CVE-2025-27097

GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, su…

Mitigation only
Fix from $1,950 2025-02-20
Restaurant Booking System HIGH 7.5
CVE-2023-51314

A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Restaurant Booking System v3.0 allows attackers to send an e…

No fix yet
Fix from $1,950 2025-02-20
Bus Reservation System HIGH 7.5
CVE-2023-51316

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Bus Reservation System v1.1 allows attackers to send an excessive amount of em…

No fix yet
Fix from $1,950 2025-02-20