Vulnerability index

Browse CVEs

65 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.7 CVE-2024-3110 A stored Cross-Site Scripting (XSS) vulnerability exists in the mintplex-labs/anything-llm application, affecting versions up to and including the la… Anythingllm 1.0.0+ Fix from $1,9502024-06-06 MEDIUM 5.3 CVE-2024-3102 A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username parameter during the login pr… Anythingllm 1.0.0+ Fix from $1,6002024-06-06 CRITICAL 9.8 CVE-2024-3104 A remote code execution vulnerability exists in mintplex-labs/anything-llm due to improper handling of environment variables. Attackers can exploit t… Anythingllm 1.0.0+ Fix from $2,3002024-06-06 CRITICAL 9.4 CVE-2024-3033 An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-… Anythingllm 1.0.0+ Fix from $2,3002024-06-06 HIGH 8.8 CVE-2024-3152 mintplex-labs/anything-llm is vulnerable to multiple security issues due to improper input validation in several endpoints. An attacker can exploit t… Anythingllm 1.0.0+ Fix from $1,9502024-06-06 HIGH 7.5 CVE-2024-4084 A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of mintplex-labs/anything-llm, allowing attackers to bypass the offic… Anythingllm after 1.5.4 Fix from $1,9502024-06-05 HIGH 7.2 CVE-2024-4287 In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. Specifically, the application… Anythingllm 1.0.0+ Fix from $1,9502024-05-20 MEDIUM 6.5 CVE-2024-2913 A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite acceptance process. Attackers… Anythingllm after 1.0.0 Fix from $1,6002024-05-07 HIGH 8.0 CVE-2024-3029 In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to the '/system/enable-multi-use… Anythingllm 1.0.0+ Fix from $1,9502024-04-16 HIGH 7.2 CVE-2024-3028 mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary files on the server. By manipu… Anythingllm 1.0.0+ Fix from $1,9502024-04-16 CRITICAL 9.1 CVE-2024-0404 A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository, allowing unauthorized creati… Anythingllm 1.0.0+ Fix from $2,3002024-04-16 HIGH 8.1 CVE-2024-0549 mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a default role account to delete f… Anythingllm 1.0.0+ Fix from $1,9502024-04-16 HIGH 7.5 CVE-2024-3569 A Denial of Service (DoS) vulnerability exists in the mintplex-labs/anything-llm repository when the application is running in 'just me' mode with a … Anythingllm 1.0.0+ Fix from $1,9502024-04-10 MEDIUM 5.4 CVE-2024-3570 A stored Cross-Site Scripting (XSS) vulnerability exists in the chat functionality of the mintplex-labs/anything-llm repository, allowing attackers t… Anythingllm 1.0.0+ Fix from $1,6002024-04-10 HIGH 7.2 CVE-2024-3101 In mintplex-labs/anything-llm, an improper input validation vulnerability allows attackers to escalate privileges by deactivating 'Multi-User Mode'. … Anythingllm 1.0.0+ Fix from $1,9502024-04-10 HIGH 7.2 CVE-2024-3283 A vulnerability in mintplex-labs/anything-llm allows users with manager roles to escalate their privileges to admin roles through a mass assignment i… Anythingllm 1.0.0+ Fix from $1,9502024-04-10 CRITICAL 9.9 CVE-2024-3025 mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input in the logo filename functio… Anythingllm 1.0.0+ Fix from $2,3002024-04-10 MEDIUM 6.5 CVE-2024-0765 As a default user on a multi-user instance of AnythingLLM, you could execute a call to the `/export-data` endpoint of the system and then unzip and r… Anythingllm 1.0.0+ Fix from $1,6002024-03-03 HIGH 7.2 CVE-2024-0795 If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from… Anythingllm 1.0.0+ Fix from $1,9502024-03-02 MEDIUM 6.5 CVE-2024-0550 A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relative filepath to then user the P… Anythingllm 1.0.0+ Fix from $1,6002024-02-28 HIGH 8.1 CVE-2024-0763 Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would … Anythingllm 1.0.0+ Fix from $1,9502024-02-27 HIGH 7.1 CVE-2024-0551 Enable exports of the database and associated exported information of the system via the default user role. The attacked would have to have been gran… Anythingllm 1.0.0+ Fix from $1,9502024-02-27 HIGH 7.5 CVE-2024-0759 Should an instance of AnythingLLM be hosted on an internal network and the attacked be explicitly granted a permission level of manager or admin, the… Anythingllm 1.0.0+ Fix from $1,9502024-02-27 MEDIUM 6.5 CVE-2024-0798 A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete documents uploaded by 'admin'… Anythingllm Patch available Fix from $1,6002024-02-26 HIGH 8.8 CVE-2024-0439 As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most manager… Anythingllm 1.0.0+ Fix from $1,9502024-02-26 HIGH 7.5 CVE-2024-0455 The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin, and when in single user) co… Anythingllm Patch available Fix from $1,9502024-02-26 MEDIUM 6.5 CVE-2024-0440 Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protocol can then introspect host fi… Anythingllm Patch available Fix from $1,6002024-02-26 MEDIUM 5.9 CVE-2024-0436 Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing … Anythingllm 1.0.0+ Fix from $1,6002024-02-26 MEDIUM 5.4 CVE-2024-0435 User can send a chat that contains an XSS opportunity that will then run when the chat is sent and on subsequent page loads. Given the minimum requi… Anythingllm Patch available Fix from $1,6002024-02-26 HIGH 7.5 CVE-2024-22422 AnythingLLM is an application that turns any document, resource, or piece of content into context that any LLM can use as references during chatting.… Anythingllm 2024-01-18+ Fix from $1,9502024-01-19