Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2024-7790 A stored cross site scripting vulnerabilities exists in DevikaAI from commit 6acce21fb08c3d1123ef05df6a33912bf0ee77c2 onwards via improperly decoded … Devika No fix yet Fix from $1,6002024-08-14 MEDIUM 6.5 CVE-2024-6331 stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable to Local File Read (LFI) by Prompt Injection. The in… Devika No fix yet Fix from $1,6002024-08-04 CRITICAL 9.1 CVE-2024-40422EPSS 11% The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker c… Devika Patch available Fix from $2,3002024-07-24 HIGH 8.1 CVE-2024-5549 A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs, browser sessions, and settin… Devika Patch available Fix from $1,9502024-07-09 MEDIUM 6.1 CVE-2024-5711 A stored Cross-Site Scripting (XSS) vulnerability exists in the stitionai/devika chat feature, allowing attackers to inject malicious payloads into t… Devika Patch available Fix from $1,6002024-07-08 CRITICAL 9.1 CVE-2024-5926 A path traversal vulnerability in the get-project-files functionality of stitionai/devika allows attackers to read arbitrary files from the filesyste… Devika No fix yet Fix from $2,3002024-06-30 HIGH 8.1 CVE-2024-5712 A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the latest version. This vulnerabilit… Devika No fix yet Fix from $1,9502024-06-28 HIGH 8.8 CVE-2024-5820 An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious website to connect to the backend a… Devika No fix yet Fix from $1,9502024-06-27 HIGH 7.5 CVE-2024-5334 A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerability is due to improper handlin… Devika Patch available Fix from $1,9502024-06-27 HIGH 7.5 CVE-2024-5547 A directory traversal vulnerability exists in the /api/download-project-pdf endpoint of the stitionai/devika repository, affecting the latest version… Devika Patch available Fix from $1,9502024-06-27 HIGH 7.5 CVE-2024-5548 A directory traversal vulnerability exists in the stitionai/devika repository, specifically within the /api/download-project endpoint. Attackers can … Devika Patch available Fix from $1,9502024-06-27