Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

lunary-ai/lunary — Vulnerabilities & Security Advisories 71

All 71 CVE vulnerabilities found in lunary-ai/lunary, with AI-generated Chinese analysis, references, and POCs.

This page aggregates common vulnerabilities associated with the lunary-ai/lunary software product. It compiles data regarding various security weaknesses identified in this specific tool, providing a centralized view of its risk profile. The content includes a comprehensive collection of known vulnerabilities affecting lunary-ai/lunary, covering incidents reported and disclosed over a broad historical time range to ensure context for both legacy and recent security concerns. By reviewing this aggregated data, users can track the vendor's advisory history and response patterns, gaining insight into how the maintainers address security flaws. The page also helps readers understand the specific weakness classes that impact this product, allowing for a deeper comprehension of the underlying security mechanisms and potential failure points. Additionally, it serves as a reference for looking up the product’s complete vulnerability history, enabling security teams and developers to assess long-term stability and risk exposure. This resource is designed to facilitate informed decision-making by presenting factual security data without filtering or prioritization, allowing stakeholders to evaluate the product's safety based on transparent and complete historical records of disclosed issues.

Vendor: lunary-ai

CVE IDTitleCVSSSeverityPublished
CVE-2024-3501 Exposure of Sensitive Information in lunary-ai/lunary CWE-922 9.1 -2024-11-14
CVE-2024-3379 Incorrect Authorization in lunary-ai/lunary CWE-863 7.1 -2024-11-14
CVE-2024-7456 SQL Injection in lunary-ai/lunary CWE-89 9.8AICriticalAI2024-11-01
CVE-2024-7472 Email Injection Vulnerability in lunary-ai/lunary CWE-93 5.3AIMediumAI2024-10-29
CVE-2024-7473 IDOR Vulnerability in lunary-ai/lunary CWE-639 4.3AIMediumAI2024-10-29
CVE-2024-7474 IDOR in lunary-ai/lunary CWE-639 7.1AIHighAI2024-10-29
CVE-2024-7475 Improper Access Control in lunary-ai/lunary CWE-862 7.5AIHighAI2024-10-29
CVE-2024-6862 Cross-Site Request Forgery (CSRF) in lunary-ai/lunary CWE-352 8.8AIHighAI2024-09-13
CVE-2024-6867 Information Disclosure in lunary-ai/lunary CWE-1220 4.3AIMediumAI2024-09-13
CVE-2024-6087 Improper Access Control in lunary-ai/lunary CWE-639 8.8AIHighAI2024-09-13
CVE-2024-6582 Broken Access Control in lunary-ai/lunary CWE-306 6.1AIMediumAI2024-09-13
CVE-2024-6086 Improper Access Control in lunary-ai/lunary CWE-863 4.3AIMediumAI2024-06-27
CVE-2024-5755 Email Validation Bypass in lunary-ai/lunary CWE-821 5.3AIMediumAI2024-06-27
CVE-2024-5714 Improper Access Control in lunary-ai/lunary CWE-863 8.8AIHighAI2024-06-27
CVE-2024-5389 Insufficient Access Control in lunary-ai/lunary CWE-1220 4.3 -2024-06-09
CVE-2024-4146 Incorrect Authorization in lunary-ai/lunary CWE-863 9.8 Critical2024-06-08
CVE-2024-5328 SSRF Vulnerability in lunary-ai/lunary CWE-918 9.8AICriticalAI2024-06-06
CVE-2024-5248 Improper Access Control in lunary-ai/lunary CWE-862 4.3AIMediumAI2024-06-06
CVE-2024-5130 Incorrect Authorization in lunary-ai/lunary CWE-862 5.3AIMediumAI2024-06-06
CVE-2024-5131 Improper Access Control in lunary-ai/lunary CWE-639 4.3AIMediumAI2024-06-06
CVE-2024-5129 Privilege Escalation Vulnerability in lunary-ai/lunary CWE-862 8.1AIHighAI2024-06-06
CVE-2024-5133 Account Takeover via Exposed Recovery Token in lunary-ai/lunary CWE-200 8.0AIHighAI2024-06-06
CVE-2024-5478 Cross-site Scripting (XSS) in SAML metadata endpoint in lunary-ai/lunary CWE-79 6.1AIMediumAI2024-06-06
CVE-2024-5126 Improper Access Control in lunary-ai/lunary CWE-862 4.3AIMediumAI2024-06-06
CVE-2024-5128 IDOR Vulnerability in lunary-ai/lunary CWE-639 7.6AIHighAI2024-06-06
CVE-2024-3504 Improper Access Control in lunary-ai/lunary CWE-863 4.9AIMediumAI2024-06-06
CVE-2024-5277 Weak Password Recovery Mechanism in lunary-ai/lunary CWE-640 9.8AICriticalAI2024-06-06
CVE-2024-5127 Improper Access Control in lunary-ai/lunary CWE-862 8.1AIHighAI2024-06-06
CVE-2024-4148 Redos (Regular Expression Denial of Service) in lunary-ai/lunary CWE-1333 7.5 -2024-06-01
CVE-2024-4154 Incorrect Synchronization in lunary-ai/lunary CWE-639 7.1AIHighAI2024-05-21

All 71 known CVE vulnerabilities affecting lunary-ai/lunary with full Chinese analysis, references, and POCs where available.