modelscope records
9 published records for vendor modelscope.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 11.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-23 Relative Path Traversal1
- CWE-29 Path Traversal: '\..\filename'1
- CWE-346 Origin Validation Error1
- CWE-36 Absolute Path Traversal1
- CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-48050No exploit | In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression.modelscope · agentscope · CWE-94 | Critical9.8 | — | 0.8% | Nov 4, 2024 |
39Monitor | CVE-2024-8487No exploit | CORS Vulnerability in modelscope/agentscopemodelscope · agentscope · CWE-346 | Critical9.8 | — | 0.3% | Mar 20, 2025 |
36Monitor | CVE-2024-8537No exploit | Path Traversal in modelscope/agentscopemodelscope · agentscope · CWE-29 | Critical9.1 | — | 1.0% | Mar 20, 2025 |
36Monitor | CVE-2024-8551No exploit | Path Traversal in modelscope/agentscopemodelscope · agentscope · CWE-23 | Critical9.1 | — | 1.0% | Mar 20, 2025 |
35Monitor | CVE-2024-8501No exploit | Arbitrary File Download in modelscope/agentscopemodelscope · agentscope · CWE-36 | High8.8 | — | 1.0% | Mar 20, 2025 |
30Monitor | CVE-2024-8524No exploit | Directory Traversal in modelscope/agentscopemodelscope · agentscope · CWE-22 | High7.5 | — | 1.2% | Mar 20, 2025 |
30Monitor | CVE-2024-8438No exploit | Path Traversal in modelscope/agentscopemodelscope · agentscope · CWE-22 | High7.5 | — | 0.8% | Mar 20, 2025 |
30Monitor | CVE-2024-8550No exploit | Local File Inclusion (LFI) in modelscope/agentscopemodelscope · agentscope · CWE-497 | High7.5 | — | 0.5% | Feb 10, 2025 |
24Monitor | CVE-2024-8556No exploit | Stored XSS in modelscope/agentscopemodelscope · agentscope · CWE-79 | Medium6.1 | — | 0.4% | Mar 20, 2025 |
- CVE-2024-4805039Monitor
In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression.
CriticalCVSS 9.8No exploitEPSS 1%modelscope · agentscopeNov 4, 2024
- CVE-2024-848739Monitor
CORS Vulnerability in modelscope/agentscope
CriticalCVSS 9.8No exploitEPSS 0%modelscope · agentscopeMar 20, 2025
- CVE-2024-853736Monitor
Path Traversal in modelscope/agentscope
CriticalCVSS 9.1No exploitEPSS 1%modelscope · agentscopeMar 20, 2025
- CVE-2024-855136Monitor
Path Traversal in modelscope/agentscope
CriticalCVSS 9.1No exploitEPSS 1%modelscope · agentscopeMar 20, 2025
- CVE-2024-850135Monitor
Arbitrary File Download in modelscope/agentscope
HighCVSS 8.8No exploitEPSS 1%modelscope · agentscopeMar 20, 2025
- CVE-2024-852430Monitor
Directory Traversal in modelscope/agentscope
HighCVSS 7.5No exploitEPSS 1%modelscope · agentscopeMar 20, 2025
- CVE-2024-843830Monitor
Path Traversal in modelscope/agentscope
HighCVSS 7.5No exploitEPSS 1%modelscope · agentscopeMar 20, 2025
- CVE-2024-855030Monitor
Local File Inclusion (LFI) in modelscope/agentscope
HighCVSS 7.5No exploitEPSS 1%modelscope · agentscopeFeb 10, 2025
- CVE-2024-855624Monitor
Stored XSS in modelscope/agentscope
MediumCVSS 6.1No exploitEPSS 0%modelscope · agentscopeMar 20, 2025