Vulnerability index

Browse CVEs

66 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-7456 A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query… Lunary Patch available Fix from $2,3002024-11-01 CRITICAL 9.1 CVE-2024-7475 An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization.… Lunary 1.3.4+ Fix from $2,3002024-10-29 HIGH 8.1 CVE-2024-7474 In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view or delete external users by ma… Lunary 1.3.4+ Fix from $1,9502024-10-29 MEDIUM 6.5 CVE-2024-7472 lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (… Lunary Patch available Fix from $1,6002024-10-29 MEDIUM 6.5 CVE-2024-7473 An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability all… Lunary Patch available Fix from $1,6002024-10-29 HIGH 8.1 CVE-2024-6862 A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerabilit… Lunary Patch available Fix from $1,9502024-09-13 MEDIUM 6.5 CVE-2024-6087 An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. The vulnerability allows an at… Lunary 1.4.9+ Fix from $1,6002024-09-13 MEDIUM 6.5 CVE-2024-6867 An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endpoint. This endpoint does not … Lunary Patch available Fix from $1,6002024-09-13 MEDIUM 5.3 CVE-2024-5755 In lunary-ai/lunary versions <=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the email address. This allows the … Lunary after 1.2.11 Fix from $1,6002024-06-27 MEDIUM 6.8 CVE-2024-5714 In lunary-ai/lunary version 1.2.4, an improper access control vulnerability allows members with team management permissions to manipulate project ide… Lunary Patch available Fix from $1,6002024-06-27 HIGH 8.1 CVE-2024-5389 In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to create, update, get, and delete promp… Lunary No fix yet Fix from $1,9502024-06-09 CRITICAL 9.8 CVE-2024-4146 In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to access and manipulate projects… Lunary Patch available Fix from $2,3002024-06-08 CRITICAL 9.3 CVE-2024-5328 A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the endpoint '/auth/saml/tto/downl… Lunary No fix yet Fix from $2,3002024-06-06 MEDIUM 6.1 CVE-2024-5478 A Cross-site Scripting (XSS) vulnerability exists in the SAML metadata endpoint `/auth/saml/${org?.id}/metadata` of lunary-ai/lunary version 1.2.7. T… Lunary No fix yet Fix from $1,6002024-06-06 MEDIUM 6.5 CVE-2024-5248 In lunary-ai/lunary version 1.2.5, an improper access control vulnerability exists due to a missing permission check in the `GET /v1/users/me/org` en… Lunary 1.4.9+ Fix from $1,6002024-06-06 HIGH 8.1 CVE-2024-5133 In lunary-ai/lunary version 1.2.4, an account takeover vulnerability exists due to the exposure of password recovery tokens in API responses. Specifi… Lunary 1.2.14+ Fix from $1,9502024-06-06 MEDIUM 6.5 CVE-2024-5131 An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and including 1.2.2. The vulnerability a… Lunary 1.2.25+ Fix from $1,6002024-06-06 HIGH 8.8 CVE-2024-5128 An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2. This vulne… Lunary 1.2.25+ Fix from $1,9502024-06-06 HIGH 8.2 CVE-2024-5129 A Privilege Escalation Vulnerability exists in lunary-ai/lunary version 1.2.2, where any user can delete any datasets due to missing authorization ch… Lunary 1.2.8+ Fix from $1,9502024-06-06 HIGH 7.5 CVE-2024-5130 An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete … Lunary 1.2.8+ Fix from $1,9502024-06-06 MEDIUM 6.5 CVE-2024-5126 An improper access control vulnerability exists in the lunary-ai/lunary repository, specifically within the versions.patch functionality for updating… Lunary 1.2.25+ Fix from $1,6002024-06-06 HIGH 7.5 CVE-2024-5277 In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after … Lunary 1.4.9+ Fix from $1,9502024-06-06 MEDIUM 5.4 CVE-2024-5127 In lunary-ai/lunary versions 1.2.2 through 1.2.25, an improper access control vulnerability allows users on the Free plan to invite other members and… Lunary 1.2.25+ Fix from $1,6002024-06-06 MEDIUM 6.5 CVE-2024-3504 An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization us… Lunary 1.2.7+ Fix from $1,6002024-06-06 HIGH 7.5 CVE-2024-4148 A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary application, version 1.2.10. An attacker can exploit this… Lunary Patch available Fix from $1,9502024-06-01 MEDIUM 6.5 CVE-2024-4154 In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged users to rename projects they do not have access to… Lunary 1.2.26+ Fix from $1,6002024-05-21 HIGH 8.1 CVE-2024-4151 An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any prompts in any projects due to… Lunary 1.2.25+ Fix from $1,9502024-05-20 HIGH 7.5 CVE-2024-3761 In lunary-ai/lunary version 1.2.2, the DELETE endpoint located at `packages/backend/src/api/v1/datasets` is vulnerable to unauthorized dataset deleti… Lunary 1.2.8+ Fix from $1,9502024-05-20 CRITICAL 9.1 CVE-2024-1739 lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the … Lunary 1.0.2+ Fix from $2,3002024-04-16 HIGH 7.5 CVE-2024-1738 An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.get route in the evaluations … Lunary 1.2.4+ Fix from $1,9502024-04-16