Vulnerability index

Browse CVEs

66 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lunary CRITICAL 9.8
CVE-2024-7456

A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query…

Patch available
Fix from $2,300 2024-11-01
Lunary CRITICAL 9.1
CVE-2024-7475

An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization.…

Fix: 1.3.4+
Fix from $2,300 2024-10-29
Lunary HIGH 8.1
CVE-2024-7474

In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view or delete external users by ma…

Fix: 1.3.4+
Fix from $1,950 2024-10-29
Lunary MEDIUM 6.5
CVE-2024-7472

lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (…

Patch available
Fix from $1,600 2024-10-29
Lunary MEDIUM 6.5
CVE-2024-7473

An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability all…

Patch available
Fix from $1,600 2024-10-29
Lunary HIGH 8.1
CVE-2024-6862

A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerabilit…

Patch available
Fix from $1,950 2024-09-13
Lunary MEDIUM 6.5
CVE-2024-6087

An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. The vulnerability allows an at…

Fix: 1.4.9+
Fix from $1,600 2024-09-13
Lunary MEDIUM 6.5
CVE-2024-6867

An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endpoint. This endpoint does not …

Patch available
Fix from $1,600 2024-09-13
Lunary MEDIUM 5.3
CVE-2024-5755

In lunary-ai/lunary versions <=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the email address. This allows the …

Fix: after 1.2.11
Fix from $1,600 2024-06-27
Lunary MEDIUM 6.8
CVE-2024-5714

In lunary-ai/lunary version 1.2.4, an improper access control vulnerability allows members with team management permissions to manipulate project ide…

Patch available
Fix from $1,600 2024-06-27
Lunary HIGH 8.1
CVE-2024-5389

In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to create, update, get, and delete promp…

No fix yet
Fix from $1,950 2024-06-09
Lunary CRITICAL 9.8
CVE-2024-4146

In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to access and manipulate projects…

Patch available
Fix from $2,300 2024-06-08
Lunary CRITICAL 9.3
CVE-2024-5328

A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the endpoint '/auth/saml/tto/downl…

No fix yet
Fix from $2,300 2024-06-06
Lunary MEDIUM 6.1
CVE-2024-5478

A Cross-site Scripting (XSS) vulnerability exists in the SAML metadata endpoint `/auth/saml/${org?.id}/metadata` of lunary-ai/lunary version 1.2.7. T…

No fix yet
Fix from $1,600 2024-06-06
Lunary MEDIUM 6.5
CVE-2024-5248

In lunary-ai/lunary version 1.2.5, an improper access control vulnerability exists due to a missing permission check in the `GET /v1/users/me/org` en…

Fix: 1.4.9+
Fix from $1,600 2024-06-06
Lunary HIGH 8.1
CVE-2024-5133

In lunary-ai/lunary version 1.2.4, an account takeover vulnerability exists due to the exposure of password recovery tokens in API responses. Specifi…

Fix: 1.2.14+
Fix from $1,950 2024-06-06
Lunary MEDIUM 6.5
CVE-2024-5131

An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and including 1.2.2. The vulnerability a…

Fix: 1.2.25+
Fix from $1,600 2024-06-06
Lunary HIGH 8.8
CVE-2024-5128

An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2. This vulne…

Fix: 1.2.25+
Fix from $1,950 2024-06-06
Lunary HIGH 8.2
CVE-2024-5129

A Privilege Escalation Vulnerability exists in lunary-ai/lunary version 1.2.2, where any user can delete any datasets due to missing authorization ch…

Fix: 1.2.8+
Fix from $1,950 2024-06-06
Lunary HIGH 7.5
CVE-2024-5130

An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete …

Fix: 1.2.8+
Fix from $1,950 2024-06-06
Lunary MEDIUM 6.5
CVE-2024-5126

An improper access control vulnerability exists in the lunary-ai/lunary repository, specifically within the versions.patch functionality for updating…

Fix: 1.2.25+
Fix from $1,600 2024-06-06
Lunary HIGH 7.5
CVE-2024-5277

In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after …

Fix: 1.4.9+
Fix from $1,950 2024-06-06
Lunary MEDIUM 5.4
CVE-2024-5127

In lunary-ai/lunary versions 1.2.2 through 1.2.25, an improper access control vulnerability allows users on the Free plan to invite other members and…

Fix: 1.2.25+
Fix from $1,600 2024-06-06
Lunary MEDIUM 6.5
CVE-2024-3504

An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization us…

Fix: 1.2.7+
Fix from $1,600 2024-06-06
Lunary HIGH 7.5
CVE-2024-4148

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary application, version 1.2.10. An attacker can exploit this…

Patch available
Fix from $1,950 2024-06-01
Lunary MEDIUM 6.5
CVE-2024-4154

In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged users to rename projects they do not have access to…

Fix: 1.2.26+
Fix from $1,600 2024-05-21
Lunary HIGH 8.1
CVE-2024-4151

An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any prompts in any projects due to…

Fix: 1.2.25+
Fix from $1,950 2024-05-20
Lunary HIGH 7.5
CVE-2024-3761

In lunary-ai/lunary version 1.2.2, the DELETE endpoint located at `packages/backend/src/api/v1/datasets` is vulnerable to unauthorized dataset deleti…

Fix: 1.2.8+
Fix from $1,950 2024-05-20
Lunary CRITICAL 9.1
CVE-2024-1739

lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the …

Fix: 1.0.2+
Fix from $2,300 2024-04-16
Lunary HIGH 7.5
CVE-2024-1738

An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.get route in the evaluations …

Fix: 1.2.4+
Fix from $1,950 2024-04-16