A vulnerability has been found in parisneo lollms-webui up to 9.8 and classified as critical. This vulnerability affects unknown code of the component Private API Key Handler. The manipulation leads to origin validation error.
This vulnerability was named CVE-2024-6674. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in mudler LocalAI up to 2.18.0. This affects an unknown part of the component Automatic Archive Extraction. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2024-6868. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in PHPGurukul Online DJ Booking Management System 1.0. Affected by this issue is some unknown functionality of the file /odms/admin/booking-search.php. The manipulation of the argument searchdata leads to cross site scripting.
This vulnerability is handled as CVE-2024-51076. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as problematic was found in mudler localai up to 2.20. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-7010. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in parisneo lollms up to 9.8. Affected is the function sanitize_svg of the component SVG Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-6581. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in lunary-ai lunary up to 1.3.3. It has been rated as critical. This issue affects some unknown processing of the component SAML Configuration Handler. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2024-7475. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in lunary-ai lunary up to 1.3.3. It has been declared as critical. This vulnerability affects unknown code. The manipulation of the argument id leads to improper access controls.
This vulnerability was named CVE-2024-7474. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in lunary-ai lunary up to 1.4.2. It has been classified as critical. This affects an unknown part of the component Evaluations. The manipulation of the argument id leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2024-7473. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in gaizhenbiao ChuanhuChatGPT 20240305/20240310/20240410 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to resource consumption.
This vulnerability is handled as CVE-2024-7807. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in gaizhenbiao ChuanhuChatGPT 20240305/20240310/20240410 and classified as critical. Affected by this vulnerability is the function load_chat_history. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-5982. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in langchain-ai langchainjs up to 0.3.0. Affected is the function GraphCypherQAChain. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2024-7042. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in gaizhenbiao ChuanhuChatGPT up to 20240410. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to file inclusion.
The identification of this vulnerability is CVE-2024-5823. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as problematic was found in Hitachi Energy TRO600 up to 9.2.0.0. This vulnerability affects unknown code. The manipulation leads to improper removal of sensitive information before storage or transfer.
This vulnerability was named CVE-2024-41156. The attack can be initiated remotely. There is no exploit available.
A vulnerability classified as problematic has been found in mintplex-labs anything-llm up to 1.0.2. This affects an unknown part of the component JSON Web Token Handler. The manipulation leads to cleartext storage of sensitive information.
This vulnerability is uniquely identified as CVE-2024-7783. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.