Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Privategpt MEDIUM 6.5
CVE-2025-4515

A vulnerability, which was classified as problematic, was found in Zylon PrivateGPT up to 0.6.2. This affects an unknown part of the file settings.ya…

Fix: after 0.6.2
Fix from $1,600 2025-05-10
Privategpt MEDIUM 6.1
CVE-2024-8029

An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which exe…

No fix yet
Fix from $1,600 2025-03-20
Privategpt HIGH 7.5
CVE-2024-8018

A vulnerability in imartinez/privategpt version 0.5.0 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a la…

No fix yet
Fix from $1,950 2025-03-20
Privategpt HIGH 7.5
CVE-2024-12063

A Denial of Service (DoS) vulnerability exists in the file upload feature of imartinez/privategpt version v0.6.2. The vulnerability is due to imprope…

No fix yet
Fix from $1,950 2025-03-20
Privategpt CRITICAL 9.8
CVE-2024-4343

A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/components/llm/custom/sagemak…

Fix: 0.6.0+
Fix from $2,300 2024-11-14
Privategpt MEDIUM 6.1
CVE-2024-5936EPSS 29%

An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allo…

No fix yet
Fix from $1,600 2024-06-27
Privategpt MEDIUM 5.4
CVE-2024-5935

A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete all uploaded files on the ser…

No fix yet
Fix from $1,600 2024-06-27
Privategpt HIGH 7.2
CVE-2024-5186

A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of imartinez/privategpt version 0.5.0. This vulnerability allows…

No fix yet
Fix from $1,950 2024-06-06
Privategpt HIGH 7.5
CVE-2024-3403

imartinez/privategpt version 0.2.0 is vulnerable to a local file inclusion vulnerability that allows attackers to read arbitrary files from the files…

Fix: 0.6.0+
Fix from $1,950 2024-05-16
Privategpt MEDIUM 5.4
CVE-2024-3851

A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper validation of file uploads. Attacke…

Fix: after 0.6.2
Fix from $1,600 2024-05-16