Loading HuntDB...

Mintplex-Labs

3 Products 48 CVEs

CVE Severity Distribution (All Time)

Critical
13
High
23
Medium
10
Low
1

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2024-7783 MEDIUM 1 year ago

mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within …

CVE-2024-3279 CRITICAL 1 year, 3 months ago

An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerab…

CVE-2024-5216 HIGH 1 year, 4 months ago

A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resource consumption. Specifically, …

CVE-2024-5213 MEDIUM 1 year, 5 months ago

In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a user is returned in the respon…

CVE-2024-5208 MEDIUM 1 year, 5 months ago

An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. This vulnerability allows atta…

CVE-2024-5211 CRITICAL 1 year, 5 months ago

A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against p…

CVE-2024-3150 HIGH 1 year, 5 months ago

In mintplex-labs/anything-llm, a vulnerability exists in the thread update process that allows users with Default or Manager roles to escalate their …

CVE-2024-3149 CRITICAL 1 year, 5 months ago

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex-labs/anything-llm. This feature, intended for users …

CVE-2024-3153 MEDIUM 1 year, 5 months ago

mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of serv…

CVE-2024-3166 LOW 1 year, 5 months ago

A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest …