Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2024-7790
A stored cross site scripting vulnerabilities exists in DevikaAI from commit 6acce21fb08c3d1123ef05df6a33912bf0ee77c2 onwards via improperly decoded …
Devika
No fix yet
MEDIUM 6.5
CVE-2024-6331
stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable to Local File Read (LFI) by Prompt Injection. The in…
Devika
No fix yet
CRITICAL 9.1
CVE-2024-40422EPSS 11%
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker c…
Devika
Patch available
HIGH 8.1
CVE-2024-5549
A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs, browser sessions, and settin…
Devika
Patch available
MEDIUM 6.1
CVE-2024-5711
A stored Cross-Site Scripting (XSS) vulnerability exists in the stitionai/devika chat feature, allowing attackers to inject malicious payloads into t…
Devika
Patch available
CRITICAL 9.1
CVE-2024-5926
A path traversal vulnerability in the get-project-files functionality of stitionai/devika allows attackers to read arbitrary files from the filesyste…
Devika
No fix yet
HIGH 8.1
CVE-2024-5712
A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the latest version. This vulnerabilit…
Devika
No fix yet
HIGH 8.8
CVE-2024-5820
An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious website to connect to the backend a…
Devika
No fix yet
HIGH 7.5
CVE-2024-5334
A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerability is due to improper handlin…
Devika
Patch available
HIGH 7.5
CVE-2024-5547
A directory traversal vulnerability exists in the /api/download-project-pdf endpoint of the stitionai/devika repository, affecting the latest version…
Devika
Patch available
HIGH 7.5
CVE-2024-5548
A directory traversal vulnerability exists in the stitionai/devika repository, specifically within the /api/download-project endpoint. Attackers can …
Devika
Patch available