Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18855

18855 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-12070 Denial of Service in haotian-liu/llava — haotian-liu/llavaCWE-400 7.5 -2025-03-20
CVE-2024-8053 Improper Authentication in open-webui/open-webui — open-webui/open-webuiCWE-306 9.1 -2025-03-20
CVE-2024-12074 Denial of Service in automatic1111/stable-diffusion-webui — automatic1111/stable-diffusion-webuiCWE-400 7.5 -2025-03-20
CVE-2024-10051 Unauthenticated Denial of Service in shaunwei/realchar — shaunwei/realcharCWE-770 7.5 -2025-03-20
CVE-2024-10188 Denial of Service in BerriAI/litellm — berriai/litellmCWE-400 7.5 -2025-03-20
CVE-2024-8057 Improper Access Control in danswer-ai/danswer — danswer-ai/danswerCWE-306 9.8 -2025-03-20
CVE-2024-9229 Denial of Service (DoS) via Multipart Boundary in stangirard/quivr — stangirard/quivrCWE-770 7.5 -2025-03-20
CVE-2024-9437 Unauthenticated Denial of Service in transformeroptimus/superagi — transformeroptimus/superagiCWE-770 7.5 -2025-03-20
CVE-2024-8765 Improper Path Equivalence Resolution in lunary-ai/lunary — lunary-ai/lunaryCWE-41 9.4 -2025-03-20
CVE-2024-9308 Open Redirect in haotian-liu/llava — haotian-liu/llavaCWE-601 6.1 -2025-03-20
CVE-2024-7983 Denial of Service in open-webui/open-webui — open-webui/open-webuiCWE-770 7.5 -2025-03-20
CVE-2024-11173 Unhandled Exception in danny-avila/librechat — danny-avila/librechatCWE-248 7.5 -2025-03-20
CVE-2024-9311 Cross-Site Request Forgery to XSS in haotian-liu/llava — haotian-liu/llavaCWE-352 8.1 -2025-03-20
CVE-2024-8055 Local File Read (LFI) by Prompt Injection via SnowFlake SQL in vanna-ai/vanna — vanna-ai/vannaCWE-89 9.1 -2025-03-20
CVE-2024-10907 Denial of Service (DoS) via Multipart Boundary in lm-sys/fastchat — lm-sys/fastchatCWE-835 7.5 -2025-03-20
CVE-2024-9056 Denial of Service in bentoml/bentoml — bentoml/bentomlCWE-770 7.5 -2025-03-20
CVE-2024-11172 Denial of Service in danny-avila/librechat — danny-avila/librechatCWE-248 7.5 -2025-03-20
CVE-2024-11169 Unhandled Exception Leading to Server Crash in danny-avila/librechat — danny-avila/librechatCWE-115 7.5 -2025-03-20
CVE-2024-10908 Open Redirect in lm-sys/fastchat — lm-sys/fastchatCWE-601 6.1 -2025-03-20
CVE-2024-7036 Denial of Service in open-webui/open-webui — open-webui/open-webuiCWE-400 7.5 -2025-03-20
CVE-2024-10707 Local File Inclusion in gaizhenbiao/chuanhuchatgpt — gaizhenbiao/chuanhuchatgptCWE-22 7.5 -2025-03-20
CVE-2024-10190 Unauthenticated Remote Code Execution in ElasticRendezvousHandler in horovod/horovod — horovod/horovodCWE-502 9.8 -2025-03-20
CVE-2024-10935 Unauthenticated DoS via Multipart Boundary in automatic1111/stable-diffusion-webui — automatic1111/stable-diffusion-webuiCWE-770 7.5 -2025-03-20
CVE-2024-10829 Denial of Service (DoS) via Multipart Boundary in eosphoros-ai/db-gpt — eosphoros-ai/db-gptCWE-835 7.5 -2025-03-20
CVE-2024-9362 Directory Traversal in polyaxon/polyaxon — polyaxon/polyaxonCWE-22 7.5 -2025-03-20
CVE-2024-8249 Unauthenticated Denial of Service (DoS) in mintplex-labs/anything-llm — mintplex-labs/anything-llmCWE-248 7.5 -2025-03-20
CVE-2024-12039 Improper Restriction of Excessive Authentication Attempts in langgenius/dify — langgenius/difyCWE-307 9.8 -2025-03-20
CVE-2024-11044 Open Redirect in automatic1111/stable-diffusion-webui — automatic1111/stable-diffusion-webuiCWE-601 6.1 -2025-03-20
CVE-2024-8984 Denial of Service (DoS) in berriai/litellm — berriai/litellmCWE-770 7.5 -2025-03-20
CVE-2024-10821 Denial of Service (DoS) in invoke-ai/invokeai — invoke-ai/invokeaiCWE-835 7.5 -2025-03-20

Vulnerabilities classified as access:pre-auth represent 18855 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.