Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model

CVSS 7.5 torch View details

Picklescan is vulnerable to RCE via missing detection when calling

picklescan View details

llama-index-core insecurely handles temporary files

CVSS 7.3 llama-index-core View details

Open WebUI's process_files_batch() endpoint missing ownership check

CVSS 7.1 open-webui View details

Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base

CVSS 7.5 open-webui View details

Open WebUI: Redis Cache Keys tool_servers and terminal_servers

CVSS 8.7 open-webui View details

vLLM is an inference and serving engine for large language

CVSS 8.0 vllm View details