7.8

CVSS3.1

CVE-2025-21481 - Buffer Copy Without Checking Size of Input in HLOS

Memory corruption while performing private key encryption in trusted application.

πŸ“… Published: Sept. 24, 2025, 3:33 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

7.8

CVSS3.1

CVE-2025-21476 - Buffer Copy Without Checking Size of Input in Computer Vision

Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.

πŸ“… Published: Sept. 24, 2025, 3:33 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

5.9

CVSS4.0

CVE-2025-8869 - Fallback tar extraction in pip doesn't check symbolic links point to extraction directory

When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version…

πŸ“… Published: Sept. 24, 2025, 2:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-48868 - Horilla vulnerable to authenticated RCE via eval() in project_bulk_archive

Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to the unsafe use of Python’s eval() function on a user-controlled query parameter in the project_bulk_archive view. This allows privileg…

πŸ“… Published: Sept. 24, 2025, 1:51 p.m. πŸ”„ Last Modified: Sept. 29, 2025, 2:06 p.m.

7.8

CVSS3.1

CVE-2025-23354 -

NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data created by an attacker may cause an injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, Information disclosure, and data tamper…

πŸ“… Published: Sept. 24, 2025, 1:14 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 6:24 p.m.

7.8

CVSS3.1

CVE-2025-23353 -

NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data created by an attacker may cause an injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, Information disclosure, and data tamper…

πŸ“… Published: Sept. 24, 2025, 1:14 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 6:21 p.m.

7.8

CVSS3.1

CVE-2025-23349 -

NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an attacker may cause a code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.

πŸ“… Published: Sept. 24, 2025, 1:13 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 6:24 p.m.

7.8

CVSS3.1

CVE-2025-23348 -

NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created by an attacker may cause a code injection issue. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data t…

πŸ“… Published: Sept. 24, 2025, 1:13 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 6:24 p.m.

3.3

CVSS3.1

CVE-2025-23346 -

NVIDIA CUDA Toolkit contains a vulnerability in cuobjdump, where an unprivileged user can cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to a limited denial of service.

πŸ“… Published: Sept. 24, 2025, 1:13 p.m. πŸ”„ Last Modified: Oct. 6, 2025, 2:27 p.m.

3.3

CVSS3.1

CVE-2025-23340 -

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-bounds read by passing a malformed ELF file to nvdisasm. A successful exploit of this vulnerability may lead to a partial denial of service.

πŸ“… Published: Sept. 24, 2025, 1:13 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 7:15 p.m.
Total resulsts: 349182
Page 3697 of 34,919
Β« previous page Β» next page
Filters