Show filters
10,578 Total Results
Displaying 461-470 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-7048

Disclosure Date: October 10, 2024 (last updated February 26, 2025)
In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and overwrite files managed by a higher-privileged admin. By exploiting this vulnerability, an attacker can view metadata of files uploaded by an admin and overwrite these files, compromising the integrity and availability of the RAG models.
0
Attacker Value
Unknown

CVE-2024-7041

Disclosure Date: October 09, 2024 (last updated February 26, 2025)
An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint `http://0.0.0.0:3000/api/v1/memories/{id}/update`, where the decentralization design is flawed, allowing attackers to edit other users' memories without proper authorization.
0
Attacker Value
Unknown

CVE-2024-7037

Disclosure Date: October 09, 2024 (last updated February 26, 2025)
In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized file.filename concatenation with CACHE_DIR. This vulnerability allows attackers to overwrite and delete system files, potentially leading to remote code execution.
0
Attacker Value
Unknown

CVE-2024-7038

Disclosure Date: October 09, 2024 (last updated February 26, 2025)
An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user updates the model path, the system checks if the file exists and provides different error messages based on the existence and configuration of the file. This behavior allows an attacker to enumerate file names and traverse directories by observing the error messages, leading to potential exposure of sensitive information.
Attacker Value
Unknown

CVE-2024-46307

Disclosure Date: October 09, 2024 (last updated February 26, 2025)
A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.
Attacker Value
Unknown

CVE-2024-45231

Disclosure Date: October 08, 2024 (last updated February 26, 2025)
An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and observing the outcome (only when e-mail sending is consistently failing).
Attacker Value
Unknown

CVE-2024-45230

Disclosure Date: October 08, 2024 (last updated February 26, 2025)
An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.
Attacker Value
Unknown

CVE-2024-45382

Disclosure Date: October 08, 2024 (last updated February 26, 2025)
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write.
Attacker Value
Unknown

CVE-2024-43697

Disclosure Date: October 08, 2024 (last updated February 26, 2025)
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input.
Attacker Value
Unknown

CVE-2024-43696

Disclosure Date: October 08, 2024 (last updated February 26, 2025)
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak.