Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
MEDIUM 6.5 CVE-2025-0191 A Denial of Service (DoS) vulnerability exists in the file upload feature of gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability is due to… Chuanhuchatgpt No fix yet Fix from $1,6002025-03-20 MEDIUM 6.5 CVE-2024-7771 A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denial of service. Uploading an au… Anythingllm 1.3.1+ Fix from $1,6002025-03-20 HIGH 7.5 CVE-2024-7036 A vulnerability in open-webui/open-webui v0.3.8 allows an unauthenticated attacker to sign up with excessively large text in the 'name' field, causin… Open Webui No fix yet Fix from $1,9502025-03-20 MEDIUM 5.3 CVE-2024-6838 In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its… Mlflow No fix yet Fix from $1,6002025-03-20 HIGH 7.5 CVE-2024-12864 A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2.0.0. The vulnerability is du… Qanything No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-12534 In version v0.3.32 of open-webui/open-webui, the application allows users to submit large payloads in the email and password fields during the sign-i… Open Webui No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-12761 A Denial of Service (DoS) vulnerability exists in the brycedrennan/imaginairy repository, version 15.0.0. The vulnerability is present in the `/api/s… Mitigation only Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-12070 A Denial of Service (DoS) vulnerability exists in the file upload feature of haotian-liu/llava, specifically in Release v1.2.0 (LLaVA-1.6). The vulne… Large Language And Vision Assistant No fix yet Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2024-12074 A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webui version 1.10.0. The vulnera… Stable Diffusion Webui No fix yet Fix from $1,6002025-03-20 HIGH 7.5 CVE-2024-12063 A Denial of Service (DoS) vulnerability exists in the file upload feature of imartinez/privategpt version v0.6.2. The vulnerability is due to imprope… Privategpt No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-11043 A Denial of Service (DoS) vulnerability was discovered in the /api/v1/boards/{board_id} endpoint of invoke-ai/invokeai version v5.0.2. This vulnerabi… Mitigation only Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2024-11033 A Denial of Service (DoS) vulnerability exists in the file upload feature of binary-husky/gpt_academic version 3.83. The vulnerability is due to impr… Gpt Academic No fix yet Fix from $1,6002025-03-20 HIGH 7.5 CVE-2024-10912 A Denial of Service (DoS) vulnerability exists in the file upload feature of lm-sys/fastchat version 0.2.36. The vulnerability is due to improper han… Fastchat No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-10110 In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading t… Aim No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-10188 A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of as… Patch available Fix from $1,9502025-03-20 HIGH 7.5 CVE-2025-29907 jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user control of the first argument of the addImage method results in CPU utilizati… Jspdf 3.0.1+ Fix from $1,9502025-03-18 HIGH 7.5 CVE-2025-25293 ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is suscept… Omniauth Saml 1.10.6 / 1.12.4+ Fix from $1,9502025-03-12 HIGH 7.5 CVE-2025-0114 A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to ren… Pan Os 10.1.14 / 10.2.5+ Fix from $1,9502025-03-12 MEDIUM 5.5 CVE-2024-44192 The issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS … Safari 2.0 / 11.0+ Fix from $1,6002025-03-10 HIGH 7.5 CVE-2024-44227 The issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to cause une… Ipados 15.0 / 18.0+ Fix from $1,9502025-03-10 HIGH 7.5 CVE-2024-54546 The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to cause unexpected system termina… macOS 15.0+ Fix from $1,9502025-03-10 HIGH 7.1 CVE-2024-53693 An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If … Qts Mitigation only Fix from $1,9502025-03-07 HIGH 7.5 CVE-2024-53458 Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets. Multi Server No fix yet Fix from $1,9502025-03-05 HIGH 7.5 CVE-2025-27669 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Network Scanning (XSPA)/DoS OVE-20230… Vasion Print 20.0.1923 / 22.0.843+ Fix from $1,9502025-03-05 HIGH 7.5 CVE-2025-27421 Abacus is a highly scalable and stateless counting API. A critical goroutine leak vulnerability has been identified in the Abacus server's Server-Sen… Patch available Fix from $1,9502025-03-03 MEDIUM 5.7 CVE-2024-34035 An issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must flood the system with a signifi… Mitigation only Fix from $1,6002025-02-25 MEDIUM 6.5 CVE-2025-27100 lakeFS is an open-source tool that transforms your object storage into a Git-like repository. In affected versions an authenticated user can crash la… Patch available Fix from $1,6002025-02-21 HIGH 7.5 CVE-2025-27097 GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, su… Graphql Mesh Mitigation only Fix from $1,9502025-02-20 HIGH 7.5 CVE-2023-51314 A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Restaurant Booking System v3.0 allows attackers to send an e… Restaurant Booking System No fix yet Fix from $1,9502025-02-20 HIGH 7.5 CVE-2023-51316 A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Bus Reservation System v1.1 allows attackers to send an excessive amount of em… Bus Reservation System No fix yet Fix from $1,9502025-02-20