Show filters
10,578 Total Results
Displaying 461-470 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown
CVE-2024-7048
Disclosure Date: October 10, 2024 (last updated February 26, 2025)
In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and overwrite files managed by a higher-privileged admin. By exploiting this vulnerability, an attacker can view metadata of files uploaded by an admin and overwrite these files, compromising the integrity and availability of the RAG models.
0
Attacker Value
Unknown
CVE-2024-7041
Disclosure Date: October 09, 2024 (last updated February 26, 2025)
An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint `http://0.0.0.0:3000/api/v1/memories/{id}/update`, where the decentralization design is flawed, allowing attackers to edit other users' memories without proper authorization.
0
Attacker Value
Unknown
CVE-2024-7037
Disclosure Date: October 09, 2024 (last updated February 26, 2025)
In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized file.filename concatenation with CACHE_DIR. This vulnerability allows attackers to overwrite and delete system files, potentially leading to remote code execution.
0
Attacker Value
Unknown
CVE-2024-7038
Disclosure Date: October 09, 2024 (last updated February 26, 2025)
An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user updates the model path, the system checks if the file exists and provides different error messages based on the existence and configuration of the file. This behavior allows an attacker to enumerate file names and traverse directories by observing the error messages, leading to potential exposure of sensitive information.
0
Attacker Value
Unknown
CVE-2024-46307
Disclosure Date: October 09, 2024 (last updated February 26, 2025)
A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.
0
Attacker Value
Unknown
CVE-2024-45231
Disclosure Date: October 08, 2024 (last updated February 26, 2025)
An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and observing the outcome (only when e-mail sending is consistently failing).
0
Attacker Value
Unknown
CVE-2024-45230
Disclosure Date: October 08, 2024 (last updated February 26, 2025)
An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.
0
Attacker Value
Unknown
CVE-2024-45382
Disclosure Date: October 08, 2024 (last updated February 26, 2025)
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write.
0
Attacker Value
Unknown
CVE-2024-43697
Disclosure Date: October 08, 2024 (last updated February 26, 2025)
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input.
0
Attacker Value
Unknown
CVE-2024-43696
Disclosure Date: October 08, 2024 (last updated February 26, 2025)
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak.
0