Timothy Carambat
41 exploits
Active since Sep 2023
AnythingLLM < 1.0.0 - Authenticated Privilege Escalation via User Creation
CVSS 7.2
mintplex-labs/anything-llm - Privilege Escalation
CVSS 6.5
AnythingLLM Docker <1.3.1 - Info Disclosure
CVSS 4.3
mintplex-labs/anything-llm - Privilege Escalation
CVSS 7.2
AnythingLLM Upload Link - Manager Server-Side Request Forgery
CVSS 8.8
AnythingLLM < 1.0.0 - Denial of Service via Invalid Upload Request
CVSS 6.5
AnythingLLM Desktop < 1.4.2 - Stored Cross-Site Scripting and Remote Code Execution via Website Content Embedding
CVSS 9.6
AnythingLLM < 1.0.0 - Authenticated Privilege Escalation via Mass Assignment in Admin System Preferences
CVSS 7.2
AnythingLLM < 1.0.0 - Denial of Service via Crafted Authorization Header
CVSS 7.5
AnythingLLM < 1.0.0 - Stored Cross-Site Scripting via ChatBot Response Manipulation
CVSS 5.4
AnythingLLM < 1.0.0 - Authenticated Denial of Service via User ID Modification
CVSS 4.9
Mintplex-Labs' anything-llm - Info Disclosure
CVSS 4.9
mintplex-labs/anything-llm - Privilege Escalation
CVSS 7.2
mintplex-labs/anything-llm <1.5.5 - Info Disclosure
CVSS 7.5
AnythingLLM < 1.2.1 - Cleartext Storage of Sensitive Information in JWT Bearer Token
CVSS 7.5
AnythingLLM <e287fab56089cf8fcea9ba579a3ecdeca0daa313 - Info Disclo...
CVSS 5.3