Записи superagi
13 опубликованных записей вендора superagi.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-304 Missing Critical Step in Authentication1
- CWE-359 Exposure of Private Personal Information to an Unauthorized Actor1
- CWE-1230 Exposure of Sensitive Information Through Metadata1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2024-21552Эксплойта нет | All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function.CWE-94 | Критическая9,8 | — | 0,6 % | 22 июл. 2024 г. |
35Наблюдать | CVE-2024-9415Эксплойта нет | Path Traversal in transformeroptimus/superagisuperagi · superagi · CWE-22 | Высокая8,8 | — | 1,5 % | 20 мар. 2025 г. |
35Наблюдать | CVE-2024-9439Эксплойта нет | Remote Code Execution in transformeroptimus/superagisuperagi · superagi · CWE-94 | Высокая8,8 | — | 1,2 % | 20 мар. 2025 г. |
35Наблюдать | CVE-2024-12048Эксплойта нет | IDOR Vulnerability in transformeroptimus/superagisuperagi · superagi · CWE-304 | Высокая8,8 | — | 0,7 % | 20 мар. 2025 г. |
35Наблюдать | CVE-2024-9431Эксплойта нет | Improper Privilege Management in transformeroptimus/superagisuperagi · superagi · CWE-620 | Высокая8,8 | — | 0,6 % | 20 мар. 2025 г. |
30Наблюдать | CVE-2024-9437Эксплойта нет | Unauthenticated Denial of Service in transformeroptimus/superagisuperagi · superagi · CWE-770 | Высокая7,5 | — | 0,8 % | 20 мар. 2025 г. |
30Наблюдать | CVE-2024-10267Эксплойта нет | Information Disclosure in transformeroptimus/superagisuperagi · superagi · CWE-359 | Высокая7,5 | — | 0,6 % | 20 мар. 2025 г. |
30Наблюдать | CVE-2023-48055Эксплойта нет | SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations.superagi · superagi · CWE-798 | Высокая7,5 | — | 0,4 % | 16 нояб. 2023 г. |
26Наблюдать | CVE-2024-9447Эксплойта нет | Exposure of Sensitive Information in transformeroptimus/superagisuperagi · superagi · CWE-1230 | Средняя6,5 | — | 0,6 % | 20 мар. 2025 г. |
26Наблюдать | CVE-2024-9418Эксплойта нет | Insufficiently Protected Credentials in transformeroptimus/superagisuperagi · superagi · CWE-256 | Средняя6,5 | — | 0,6 % | 20 мар. 2025 г. |
26Наблюдать | CVE-2025-51472Эксплойта нет | Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python superagi · superagi · CWE-77 | Средняя6,5 | — | 0,4 % | 22 июл. 2025 г. |
20Наблюдать | CVE-2025-51475Эксплойта нет | Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to ovesuperagi · superagi · CWE-22 | Средняя5,0 | — | 0,8 % | 22 июл. 2025 г. |
8Наблюдать | CVE-2025-6280Эксплойта нет | TransformerOptimus SuperAGI EmailToolKit read_email.py download_attachment path traversalsuperagi · superagi · CWE-22 | Низкая2,0 | — | 0,7 % | 19 июн. 2025 г. |
- CVE-2024-2155239Наблюдать
All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %22 июл. 2024 г.
- CVE-2024-941535Наблюдать
Path Traversal in transformeroptimus/superagi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %superagi · superagi20 мар. 2025 г.
- CVE-2024-943935Наблюдать
Remote Code Execution in transformeroptimus/superagi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %superagi · superagi20 мар. 2025 г.
- CVE-2024-1204835Наблюдать
IDOR Vulnerability in transformeroptimus/superagi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %superagi · superagi20 мар. 2025 г.
- CVE-2024-943135Наблюдать
Improper Privilege Management in transformeroptimus/superagi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %superagi · superagi20 мар. 2025 г.
- CVE-2024-943730Наблюдать
Unauthenticated Denial of Service in transformeroptimus/superagi
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %superagi · superagi20 мар. 2025 г.
- CVE-2024-1026730Наблюдать
Information Disclosure in transformeroptimus/superagi
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %superagi · superagi20 мар. 2025 г.
- CVE-2023-4805530Наблюдать
SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %superagi · superagi16 нояб. 2023 г.
- CVE-2024-944726Наблюдать
Exposure of Sensitive Information in transformeroptimus/superagi
СредняяCVSS 6,5Эксплойта нетEPSS 1 %superagi · superagi20 мар. 2025 г.
- CVE-2024-941826Наблюдать
Insufficiently Protected Credentials in transformeroptimus/superagi
СредняяCVSS 6,5Эксплойта нетEPSS 1 %superagi · superagi20 мар. 2025 г.
- CVE-2025-5147226Наблюдать
Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python
СредняяCVSS 6,5Эксплойта нетEPSS 0 %superagi · superagi22 июл. 2025 г.
- CVE-2025-5147520Наблюдать
Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to ove
СредняяCVSS 5,0Эксплойта нетEPSS 1 %superagi · superagi22 июл. 2025 г.
- CVE-2025-62808Наблюдать
TransformerOptimus SuperAGI EmailToolKit read_email.py download_attachment path traversal
НизкаяCVSS 2,0Эксплойта нетEPSS 1 %superagi · superagi19 июн. 2025 г.