All CVEs — page 167 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
LightLLM through 1.2.0 allows unauthenticated attackers to register arbitrary nodes via the /pd_register WebSocket endpoint, leading to potential full user prompt disclosure, denial of service, or internal network request issues.
The flaw allows attackers to upload arbitrary files, leading to potential remote code execution, due to missing capability checks and lack of file validation.
The flaw allows a remote authenticated attacker to execute arbitrary code, posing a significant risk due to improper input handling in web page generation.