Vulnerability index

Browse CVEs

61 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lollms Webui HIGH 8.8
CVE-2024-4403

A Cross-Site Request Forgery (CSRF) vulnerability exists in the restart_program function of the parisneo/lollms-webui v9.6. This vulnerability allows…

No fix yet
Fix from $1,950 2024-06-10
Lollms HIGH 7.5
CVE-2024-4881

A path traversal vulnerability exists in the parisneo/lollms application, affecting version 9.4.0 and potentially earlier versions, but fixed in vers…

Fix: 5.9.0+
Fix from $1,950 2024-06-06
Lollms CRITICAL 9.8
CVE-2024-3429EPSS 28%

A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` f…

Fix: 9.6+
Fix from $2,300 2024-06-06
Lollms Web Ui CRITICAL 9.8
CVE-2024-4320EPSS 34%

A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within…

No fix yet
Fix from $2,300 2024-06-06
Lollms Web Ui CRITICAL 9.8
CVE-2024-3322

A path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui, affecting versions up to 9.5…

Fix: 9.5+
Fix from $2,300 2024-06-06
Lollms Web Ui CRITICAL 9.8
CVE-2024-2624

A path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically within the `@router.get("/swit…

Fix: 9.4+
Fix from $2,300 2024-06-06
Lollms Web Ui HIGH 7.5
CVE-2024-2548

A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `lollms_core/lollms/server/endpoints/lollms_b…

Fix: 9.5+
Fix from $1,950 2024-06-06
Lollms Web Ui CRITICAL 9.8
CVE-2024-2359

A vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and execute arbitrary code. The issu…

No fix yet
Fix from $2,300 2024-06-06
Lollms Web Ui CRITICAL 9.8
CVE-2024-2360

parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitization of user-supplie…

No fix yet
Fix from $2,300 2024-06-06
Lollms Web Ui CRITICAL 9.1
CVE-2024-2362

A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper validation of file paths betw…

No fix yet
Fix from $2,300 2024-06-06
Lollms Web Ui HIGH 8.3
CVE-2024-2288

A Cross-Site Request Forgery (CSRF) vulnerability exists in the profile picture upload functionality of the Lollms application, specifically in the p…

Fix: 9.3+
Fix from $1,950 2024-06-06
Lollms Web Ui CRITICAL 9.1
CVE-2024-1873EPSS 13%

parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database` endpoint in version a9d16b0.…

Patch available
Fix from $2,300 2024-06-06
Lollms Web Ui CRITICAL 9.8
CVE-2024-5482

A Server-Side Request Forgery (SSRF) vulnerability exists in the 'add_webpage' endpoint of the parisneo/lollms-webui application, affecting the lates…

No fix yet
Fix from $2,300 2024-06-06
Lollms Web Ui HIGH 7.5
CVE-2024-2178

A path traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'copy_to_custom_personas' endpoint in the 'lollms_persona…

Fix: 9.4+
Fix from $1,950 2024-06-02
Lollms Webui CRITICAL 9.8
CVE-2024-4267

A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnera…

No fix yet
Fix from $2,300 2024-05-22
Lollms Web Ui CRITICAL 9.8
CVE-2024-4326

A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insuffici…

Fix: 9.5+
Fix from $2,300 2024-05-16
Lollms Web Ui HIGH 7.5
CVE-2024-4322EPSS 31%

A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personalities` endpoint. By manipulati…

Fix: 9.8+
Fix from $1,950 2024-05-16
Lollms Web Ui HIGH 8.4
CVE-2024-3435

A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions up to the latest r…

Fix: 9.5+
Fix from $1,950 2024-05-16
Lollms Web Ui HIGH 8.4
CVE-2024-3126

A command injection vulnerability exists in the 'run_xtts_api_server' function of the parisneo/lollms-webui application, specifically within the 'lol…

Fix: 9.5+
Fix from $1,950 2024-05-16
Lollms Web Ui CRITICAL 9.6
CVE-2024-2361

A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization of user-supplied input. Speci…

Fix: 9.5+
Fix from $2,300 2024-05-16
Lollms Web Ui CRITICAL 9.0
CVE-2024-2366

A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall_binding functionality in lol…

Fix: 9.5+
Fix from $2,300 2024-05-16
Lollms Web Ui CRITICAL 9.8
CVE-2024-2358

A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary code. The vulnerabili…

Fix: 9.5+
Fix from $2,300 2024-05-16
Lollms Web Ui MEDIUM 6.1
CVE-2024-2299

A stored Cross-Site Scripting (XSS) vulnerability exists in the parisneo/lollms-webui application due to improper validation of uploaded files in the…

Fix: 9.5+
Fix from $1,600 2024-05-14
Lollms Webui CRITICAL 9.8
CVE-2024-1601EPSS 40%

An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, allowing an attacker to delete …

Patch available
Fix from $2,300 2024-04-16
Lollms Webui HIGH 8.2
CVE-2024-1646

parisneo/lollms-webui is vulnerable to authentication bypass due to insufficient protection over sensitive endpoints. The application checks if the h…

Fix: 9.3+
Fix from $1,950 2024-04-16
Lollms Webui HIGH 7.5
CVE-2024-1569

parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can exploit the `/open_co…

Patch available
Fix from $1,950 2024-04-16
Lollms Web Ui CRITICAL 9.3
CVE-2024-1600EPSS 33%

A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route. An attack…

Fix: 9.6+
Fix from $2,300 2024-04-10
Lollms Web Ui MEDIUM 6.1
CVE-2024-1602

parisneo/lollms-webui is vulnerable to stored Cross-Site Scripting (XSS) that leads to Remote Code Execution (RCE). The vulnerability arises due to i…

No fix yet
Fix from $1,600 2024-04-10
Lollms Web Ui CRITICAL 9.8
CVE-2024-1511

The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of user-supplied file paths. This …

No fix yet
Fix from $2,300 2024-04-10
Lollms Web Ui CRITICAL 9.8
CVE-2024-1520EPSS 48%

An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to improper validation…

Fix: 9.2+
Fix from $2,300 2024-04-10