7.5

CVSS3.1

CVE-2025-30202 - Data exposure via ZeroMQ on multi-node vLLM deployment

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.5.2 and prior to 0.8.5 are vulnerable to denial of service and data exposure via ZeroMQ on multi-node vLLM deployment. In a multi-node vLLM deployment, vLLM uses ZeroMQ for some multi-node…

πŸ“… Published: April 30, 2025, 12:24 a.m. πŸ”„ Last Modified: April 30, 2025, 1:15 a.m.

8.6

CVSS3.1

CVE-2025-29906 - Finit bundled getty can bypass /bin/login

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authentication. This issue has been patched in version 4…

πŸ“… Published: April 29, 2025, 10:17 p.m. πŸ”„ Last Modified: April 29, 2025, 11:16 p.m.

6.3

CVSS4.0

CVE-2025-46552 - KHC-INVITATION-AUTOMATION Sensitive User Information Leakage in Invitation Automation

KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join your organization. In some commits on version 1.2, a vulnerability was identified where user data, including email addresses and Discord usernames, were exposed in API responses wit…

πŸ“… Published: April 29, 2025, 10:13 p.m. πŸ”„ Last Modified: April 29, 2025, 11:16 p.m.

5.4

CVSS3.1

CVE-2025-3910 - Org.keycloak.authentication: two factor authentication bypass

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.

πŸ“… Published: April 29, 2025, 8:46 p.m. πŸ”„ Last Modified: April 30, 2025, 3:15 a.m.

8.2

CVSS3.1

CVE-2025-3501 - Org.keycloak.protocol.services: keycloak hostname verification

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

πŸ“… Published: April 29, 2025, 8:45 p.m. πŸ”„ Last Modified: April 30, 2025, 3:15 a.m.

4.9

CVSS4.0

CVE-2025-46344 - Auth0 NextJS SDK v4 Missing Session Invalidation

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not contain an internal expiration claim. While…

πŸ“… Published: April 29, 2025, 8:43 p.m. πŸ”„ Last Modified: April 29, 2025, 9:15 p.m.

4.3

CVSS3.1

CVE-2025-46550 - Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are vulnerable to cross-site scripting. An attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious li…

πŸ“… Published: April 29, 2025, 8:41 p.m. πŸ”„ Last Modified: April 29, 2025, 9:15 p.m.

4.3

CVSS3.1

CVE-2025-46549 - Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the user’s session. This vulnerability ma…

πŸ“… Published: April 29, 2025, 8:40 p.m. πŸ”„ Last Modified: April 29, 2025, 9:15 p.m.

10

CVSS3.1

CVE-2025-46348 - YesWiki Vulnerable to Unauthenticated Site Backup Creation and Download

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authentication. The archives are created with a predictable filename, so a malicious user could create and download an archive without being authenticated. …

πŸ“… Published: April 29, 2025, 8:39 p.m. πŸ”„ Last Modified: April 29, 2025, 9:15 p.m.

5.3

CVSS4.0

CVE-2025-4078 - Wangshen SecGate 3600 g=log_export_file path traversal

A vulnerability, which was classified as problematic, has been found in Wangshen SecGate 3600 2400. This issue affects some unknown processing of the file ?g=log_export_file. The manipulation of the argument file_name leads to path traversal. The attack may be initiated remotely. The exploit has be…

πŸ“… Published: April 29, 2025, 8:08 p.m. πŸ”„ Last Modified: April 29, 2025, 8:21 p.m.
Total resulsts: 291780
Page 2 of 29,178
Β« previous page Β» next page
Filters