Vulnerability index

Browse CVEs

66 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lunary HIGH 8.8
CVE-2024-5386

In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user with a 'viewer' role can expl…

Fix: 1.2.14+
Fix from $1,950 2026-02-02
Lunary MEDIUM 6.5
CVE-2024-4147

In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to delete prompts created in other organ…

Fix: 1.2.25+
Fix from $1,600 2026-02-02
Lunary HIGH 8.8
CVE-2025-9803

lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application …

Patch available
Fix from $1,950 2025-11-25
Lunary CRITICAL 9.6
CVE-2025-5352

A critical stored Cross-Site Scripting (XSS) vulnerability exists in the Analytics component of lunary-ai/lunary versions up to 1.9.23, where the NEX…

Fix: 1.9.25+
Fix from $2,300 2025-08-23
Lunary MEDIUM 6.1
CVE-2025-4779

lunary-ai/lunary versions prior to 1.9.24 are vulnerable to stored cross-site scripting (XSS). An unauthenticated attacker can inject malicious JavaS…

Fix: 1.9.24+
Fix from $1,600 2025-07-07
Lunary MEDIUM 5.4
CVE-2025-0281

A stored cross-site scripting (XSS) vulnerability exists in lunary-ai/lunary versions 1.6.7 and earlier. An attacker can inject malicious JavaScript …

Fix: 1.7.10+
Fix from $1,600 2025-03-20
Lunary HIGH 8.1
CVE-2024-9099

In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all projects to users with minimal p…

Patch available
Fix from $1,950 2025-03-20
Lunary CRITICAL 9.8
CVE-2024-9095

In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to create a Datastream to Googl…

Patch available
Fix from $2,300 2025-03-20
Lunary HIGH 7.1
CVE-2024-9096

In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending a PATCH request. The route l…

Patch available
Fix from $1,950 2025-03-20
Lunary MEDIUM 6.1
CVE-2024-9098

In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new members with billing permissions, …

Fix: 1.4.30+
Fix from $1,600 2025-03-20
Lunary HIGH 7.5
CVE-2024-8998

A Regular Expression Denial of Service (ReDoS) vulnerability exists in lunary-ai/lunary version git f07a845. The server uses the regex /{.*?}/ to mat…

Fix: 1.4.26+
Fix from $1,950 2025-03-20
Lunary HIGH 7.5
CVE-2024-8999

lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bigquery endpoint. This vulnera…

Fix: 1.4.26+
Fix from $1,950 2025-03-20
Lunary MEDIUM 6.5
CVE-2024-9000

In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists without validating whether the …

Patch available
Fix from $1,600 2025-03-20
Lunary HIGH 7.5
CVE-2024-8789

Lunary-ai/lunary version git 105a3f6 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. The application allows users to upload t…

Fix: 1.4.23+
Fix from $1,950 2025-03-20
Lunary HIGH 7.3
CVE-2024-8765

In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies certain endpoints as public if…

Fix: 1.4.23+
Fix from $1,950 2025-03-20
Lunary HIGH 7.5
CVE-2024-8763

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary repository, specifically in the compileTextTemplate funct…

Fix: 1.4.23+
Fix from $1,950 2025-03-20
Lunary HIGH 7.5
CVE-2024-8764

A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute arbitrary regular expressions on the server side. This …

Fix: 1.4.23+
Fix from $1,950 2025-03-20
Lunary MEDIUM 6.5
CVE-2024-11300

In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This i…

Fix: 1.6.3+
Fix from $1,600 2025-03-20
Lunary MEDIUM 6.5
CVE-2024-11301

In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique constraint on the combination …

Fix: 1.6.3+
Fix from $1,600 2025-03-20
Lunary HIGH 7.5
CVE-2024-11137

An Insecure Direct Object Reference (IDOR) vulnerability exists in the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/lunary version 1.6.0. This vu…

Fix: 1.6.1+
Fix from $1,950 2025-03-20
Lunary HIGH 8.1
CVE-2024-10762

In lunary-ai/lunary before version 1.5.9, the /v1/evaluators/ endpoint allows users to delete evaluators of a project by sending a DELETE request. Ho…

Fix: 1.5.9+
Fix from $1,950 2025-03-20
Lunary HIGH 7.3
CVE-2024-10275

In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access billing resources, can change…

Fix: 1.5.7+
Fix from $1,950 2025-03-20
Lunary MEDIUM 6.5
CVE-2024-10330

In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associated with a project to fetch a…

Fix: 1.5.7+
Fix from $1,600 2025-03-20
Lunary HIGH 7.5
CVE-2024-10272

lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any dataset without any kind of au…

Fix: 1.4.9+
Fix from $1,950 2025-03-20
Lunary MEDIUM 6.5
CVE-2024-10273

In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify models owned by others. The …

Fix: 1.5.7+
Fix from $1,600 2025-03-20
Lunary MEDIUM 6.5
CVE-2024-10274

An improper authorization vulnerability exists in lunary-ai/lunary version 1.5.5. The /users/me/org endpoint lacks adequate access control mechanisms…

Fix: 1.5.7+
Fix from $1,600 2025-03-20
Lunary HIGH 7.5
CVE-2024-3760

In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bombing vulnerability. Attackers…

Fix: 1.2.8+
Fix from $1,950 2024-11-14
Lunary HIGH 8.1
CVE-2024-3379

In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key f…

Fix: 1.2.7+
Fix from $1,950 2024-11-14
Lunary HIGH 8.1
CVE-2024-3501

In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclusion of single-use tokens in t…

Fix: 1.2.6+
Fix from $1,950 2024-11-14
Lunary HIGH 8.1
CVE-2024-3502

In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists where account recovery hashes of users are ina…

Fix: 1.2.6+
Fix from $1,950 2024-11-14