sysy
6 exploits
Active since May 2026
F5-TTS <= 1.1.20 - Unauthenticated Path Traversal and Arbitrary File Write via Gradio Project Name
CVSS 8.2
Banana Slides <= 0.4.0 - Unauthenticated Path Traversal via AI Service generate_image Function
CVSS 7.5
ai-goofish-monitor Unauthenticated Arbitrary File Read via GET /api/prompts/
CVSS 7.5
manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model
CVSS 9.8
XX-Net V5.16.6 WebSocket Frame Parsing Data Corruption via simple_http_server.py
CVSS 4.0
xiaomusic 0.5.7 Path Traversal via GET /music endpoint
CVSS 7.5