CVE-2024-12074
- EPSS 0.12%
- Veröffentlicht 20.03.2025 10:11:10
- Zuletzt bearbeitet 05.08.2025 16:21:38
A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webui version 1.10.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By ...
CVE-2024-11045
- EPSS 0.08%
- Veröffentlicht 20.03.2025 10:10:12
- Zuletzt bearbeitet 05.08.2025 16:26:33
A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability arises from the lack of proper validati...
CVE-2024-12375
- EPSS 0.09%
- Veröffentlicht 20.03.2025 10:10:02
- Zuletzt bearbeitet 30.10.2025 15:21:43
A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a973c. This vulnerability allows an attacker to read arbitrary files on the system by sending a specially crafted request to the appl...
CVE-2024-10935
- EPSS 0.14%
- Veröffentlicht 20.03.2025 10:09:51
- Zuletzt bearbeitet 15.10.2025 13:15:37
automatic1111/stable-diffusion-webui version 1.10.0 contains a vulnerability where the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with ar...
CVE-2024-11044
- EPSS 0.4%
- Veröffentlicht 20.03.2025 10:09:31
- Zuletzt bearbeitet 05.08.2025 16:40:28
An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishin...
CVE-2024-12374
- EPSS 0.05%
- Veröffentlicht 20.03.2025 10:08:49
- Zuletzt bearbeitet 30.10.2025 15:29:31
A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An attacker can upload an HTML file, which the application interprets as content-type application/html. If a victim accesses the mal...