10

CVSS3.1

CVE-2025-32444 - vLLM Vulnerable to Remote Code Execution via Mooncake Integration

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and prior to 0.8.5, having vLLM integration with mooncake, are vulnerable to remote code execution due to using pickle based serialization over unsecured ZeroMQ sockets. The vulnerableโ€ฆ

๐Ÿ“… Published: April 30, 2025, 12:25 a.m. ๐Ÿ”„ Last Modified: April 30, 2025, 12:25 a.m.

6.5

CVSS3.1

CVE-2025-46560 - vLLM phi4mm: Quadratic Time Complexity in Input Token Processingโ€‹ leads to denial of service

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.8.0 and prior to 0.8.5 are affected by a critical performance vulnerability in the input preprocessing logic of the multimodal tokenizer. The code dynamically replaces placeholder tokens (โ€ฆ

๐Ÿ“… Published: April 30, 2025, 12:24 a.m. ๐Ÿ”„ Last Modified: April 30, 2025, 12:24 a.m.

7.5

CVSS3.1

CVE-2025-30202 - Data exposure via ZeroMQ on multi-node vLLM deployment

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.5.2 and prior to 0.8.5 are vulnerable to denial of service and data exposure via ZeroMQ on multi-node vLLM deployment. In a multi-node vLLM deployment, vLLM uses ZeroMQ for some multi-nodeโ€ฆ

๐Ÿ“… Published: April 30, 2025, 12:24 a.m. ๐Ÿ”„ Last Modified: April 30, 2025, 12:24 a.m.

8.6

CVSS3.1

CVE-2025-29906 - Finit bundled getty can bypass /bin/login

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authentication. This issue has been patched in version 4โ€ฆ

๐Ÿ“… Published: April 29, 2025, 10:17 p.m. ๐Ÿ”„ Last Modified: April 29, 2025, 11:16 p.m.

6.3

CVSS4.0

CVE-2025-46552 - KHC-INVITATION-AUTOMATION Sensitive User Information Leakage in Invitation Automation

KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join your organization. In some commits on version 1.2, a vulnerability was identified where user data, including email addresses and Discord usernames, were exposed in API responses witโ€ฆ

๐Ÿ“… Published: April 29, 2025, 10:13 p.m. ๐Ÿ”„ Last Modified: April 29, 2025, 11:16 p.m.

5.4

CVSS3.1

CVE-2025-3910 - Org.keycloak.authentication: two factor authentication bypass

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.

๐Ÿ“… Published: April 29, 2025, 8:46 p.m. ๐Ÿ”„ Last Modified: April 29, 2025, 11:16 p.m.

8.2

CVSS3.1

CVE-2025-3501 - Org.keycloak.protocol.services: keycloak hostname verification

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

๐Ÿ“… Published: April 29, 2025, 8:45 p.m. ๐Ÿ”„ Last Modified: April 29, 2025, 11:16 p.m.

4.9

CVSS4.0

CVE-2025-46344 - Auth0 NextJS SDK v4 Missing Session Invalidation

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not contain an internal expiration claim. Whileโ€ฆ

๐Ÿ“… Published: April 29, 2025, 8:43 p.m. ๐Ÿ”„ Last Modified: April 29, 2025, 9:15 p.m.

4.3

CVSS3.1

CVE-2025-46550 - Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are vulnerable to cross-site scripting. An attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious liโ€ฆ

๐Ÿ“… Published: April 29, 2025, 8:41 p.m. ๐Ÿ”„ Last Modified: April 29, 2025, 9:15 p.m.

4.3

CVSS3.1

CVE-2025-46549 - Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the userโ€™s session. This vulnerability maโ€ฆ

๐Ÿ“… Published: April 29, 2025, 8:40 p.m. ๐Ÿ”„ Last Modified: April 29, 2025, 9:15 p.m.
Total resulsts: 291767
Page 1 of 29,177
ยป next page
Filters