5.3

CVSS3.1

CVE-2025-6208 - Uncontrolled Memory Consumption in run-llama/llama_index

The `SimpleDirectoryReader` component in `llama_index.core` version 0.12.23 suffers from uncontrolled memory consumption due to a resource management flaw. The vulnerability arises because the user-specified file limit (`num_files_limit`) is applied after all files in a directory are loaded into meโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 10:36 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 2:34 p.m.

7

CVSS3.0

CVE-2025-10279 - Privilege Escalation in mlflow/mlflow

In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o777). This vulnerability allows an attacker with write access to the `/tmp` directory to exploit a race condition and overwrite `.py` files in the virtuโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 10:36 a.m. ๐Ÿ”„ Last Modified: April 14, 2026, 2:57 p.m.

6.5

CVSS3.1

CVE-2024-4147 - Insufficient Access Control in lunary-ai/lunary

In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to delete prompts created in other organizations through ID manipulation. The vulnerability stems from the application's failure to validate the ownership of the prompt before deletion, onlyโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 10:36 a.m. ๐Ÿ”„ Last Modified: Feb. 11, 2026, 9:14 p.m.

8.2

CVSS3.0

CVE-2026-1117 - Improper Access Control in parisneo/lollms

A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated access to sensitive Socket.IO events. The `add_events` function registers event handlers such as `generate_text`, `cancel_generation`, `generate_msg`, and `generate_msg_from` withoโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 9:55 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 12:45 a.m.

7.5

CVSS3.1

CVE-2024-54263 - WordPress Spirit Framework plugin <= 1.2.13 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Talemy Spirit Framework allows PHP Local File Inclusion.This issue affects Spirit Framework: from n/a through 1.2.13.

๐Ÿ“… Published: Feb. 2, 2026, 9:11 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.1

CVSS3.1

CVE-2026-1751 - Missing Authorization in GitLab

A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.

๐Ÿ“… Published: Feb. 2, 2026, 9:04 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 12:45 a.m.

8

CVSS3.1

CVE-2025-9974 - Insufficient Input Validation on WEBUI in Nokia ONT/Beacon product

The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users to trigger unintended system-level command execution. Due to insufficient validation of user-supplied data, a low-privileged authenticated attacker may be able to execute arbitraryโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 9:01 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2026-20419 - Firmware Exception Causes Remote Denial of Service in MediaTek WLAN Devices

In wlan AP/STA firmware, there is a possible system becoming irresponsive due to an uncaught exception. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00461663 / WCNCR00โ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 8:16 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7:15 a.m.

9.8

CVSS3.1

CVE-2026-20418 - Outโ€‘ofโ€‘Bounds Write in MediaTek Thread Leading to Remote Privilege Escalation

In Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00465153; Issue ID: MSV-4927.

๐Ÿ“… Published: Feb. 2, 2026, 8:15 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 5:45 p.m.

5.3

CVSS3.1

CVE-2026-20417 - PCIe Outโ€‘ofโ€‘Bounds Write Allowing Local Escalation of Privilege on MediaTek SoCs

In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10314946 / ALPS10340155; Issue ID: MSV-5154.

๐Ÿ“… Published: Feb. 2, 2026, 8:15 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7:15 a.m.
Total resulsts: 347619
Page 1706 of 34,762
ยซ previous page ยป next page
Filters