CVE-2024-9439 – SuperAGI Remote Code Execution Vulnerability

The following table lists the changes that have been made to the CVE-2024-9439 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 20, 2025 Action […]

CVE-2024-9415 – Superagi Path Traversal Remote File Upload Vulnerability

The following table lists the changes that have been made to the CVE-2024-9415 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 20, 2025 Action […]

CVE-2024-9309 – LLaVA Controller API Server SSRF

The following table lists the changes that have been made to the CVE-2024-9309 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 20, 2025 Action […]

CVE-2024-9216 – ChuanhuChatGPT Authentication Bypass

The following table lists the changes that have been made to the CVE-2024-9216 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 20, 2025 Action […]

CVE-2024-9070 – BentoML Runner Server Deserialization Code Execution Vulnerability

The following table lists the changes that have been made to the CVE-2024-9070 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 20, 2025 Action […]

CVE-2024-9099 – Lunary AI Lunary API Key Exposure Vulnerability

In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all projects to users with minimal permissions, such as Viewers or Prompt Editors. This vulnerability allows unauthorized users to retrieve sensitive credentials, which can be used to perform actions on behalf of the project, access private data, and […]

CVE-2024-9095 – Lunary-ai Lunary Unauthenticated Data Exfiltration Vulnerability

In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to create a Datastream to Google BigQuery and export the entire database. This includes sensitive data such as password hashes and secret API keys. The route is protected by a config check (`config.DATA_WAREHOUSE_EXPORTS_ALLOWED`), but it does not verify the […]

CVE-2024-9053 – Vllm-Project Cloudpickle Remote Code Execution

The following table lists the changes that have been made to the CVE-2024-9053 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 20, 2025 Action […]

CVE-2024-9052 – Vllm-Project Pickle Deserialization Remote Code Execution

The following table lists the changes that have been made to the CVE-2024-9052 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 20, 2025 Action […]

CVE-2024-9016 – Man Group DtaLe Python Command Injection Vulnerability

The following table lists the changes that have been made to the CVE-2024-9016 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 20, 2025 Action […]