Vulnerabilities in ltdrdata
2 resultsVexday analysis
A LTdrdata apresenta um perfil de risco moderado com 2 vulnerabilidades catalogadas, ambas críticas em severidade (CVSS), porém nenhuma sob exploração ativa conhecida. Não há registros de novas vulnerabilidades nos últimos 90 dias, indicando que o risco atual é estável. A fraqueza predominante (CWE-35) sugere problemas de validação ou tratamento de dados que merecem monitoramento contínuo.
CVE-2024-21574CRITICALThe issue stems from a missing validation of the pip field in a POST request sent to the /customnode/install endpoint used to install customEPSS 1.1%CVE-2024-21575CRITICALComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST requestEPSS 1.0%