LOW3.4CVE-2024-6971EPSS 0.03%Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py
LOW3.7EPSS 0.16%Gradio performs a non-constant-time comparison when comparing hashes
LOW2.7EPSS 0.21%open-webui allows enumeration of file names and traversal of directories by observing the error messages
LOW2.9EPSS 0.01%Race condition could lead to WebAssembly control-flow integrity and type safety violations
LOW3.7EPSS 0.24%Django allows enumeration of user e-mail addresses
LOW3.5EPSS 0.17%Inefficient Regular Expression Complexity in langflow
LOW3.1EPSS 0.07%Maven Archetype Plugin: Maven Archetype integration-test may package local settings into the published artifact, possibly containing credentials
LOW3.3EPSS 0.10%Apache Hadoop: Temporary File Local Information Disclosure
LOW3.1EPSS 0.32%Apache Druid: Users can provide MySQL JDBC properties not on allow list
LOW3.7EPSS 0.22%druid-pac4j, Apache Druid extension, has Padding Oracle vulnerability
LOW3.5EPSS 0.13%Aim Stored XSS through TEXT EXPLORER
LOW3.3EPSS 0.10%A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used.
LOW3.6EPSS 0.13%Flask-AppBuilder's login form allows browser to cache sensitive fields
LOW3.7EPSS 0.15%LTI 1.3 Grade Pass Back Implementation has Missing Authorization Vulnerability
LOW2.8EPSS 0.06%freewvs vulnerable to denial of service through large files
LOW2.8EPSS 0.17%freewvs's nested directory structure can interrupt scan
LOW3.0EPSS 0.16%biscuit-java vulnerable to public key confusion in third party block
LOW3.1EPSS 0.26%Ankitects Anki LaTeX Blocklist Bypass vulnerability
LOW3.8EPSS 0.03%[PUNCIA] [CWE-319] Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`
LOW2.5EPSS 0.03%Sentry's Python SDK unintentionally exposes environment variables to subprocesses
LOW3.7EPSS 1.4%Apache StreamPipes potentially allows creation of multiple identical accounts
LOW2.9EPSS 0.22%A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used.
LOW3.1EPSS 0.21%Exposure of secrets through system log in Jenkins Structs Plugin