5.1

CVSS4.0

CVE-2025-7123 - Campcodes Complaint Management System complaint-details.php sql injection

A vulnerability was found in Campcodes Complaint Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/complaint-details.php. The manipulation of the argument cid/uid leads to sql injection. The attack may be initiated remotely. The explโ€ฆ

๐Ÿ“… Published: July 7, 2025, 10:02 a.m. ๐Ÿ”„ Last Modified: July 8, 2025, 6:29 p.m.

5.4

CVSS3.1

CVE-2025-3467 - XSS Vulnerability in langgenius/dify

An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vulnerability allows an attacker to obtain the administrator's token by sending a payload in the published chat. When the administrator views the conversation content through the moโ€ฆ

๐Ÿ“… Published: July 7, 2025, 9:56 a.m. ๐Ÿ”„ Last Modified: July 13, 2025, 9:47 p.m.

6.5

CVSS3.0

CVE-2025-5472 - Denial of Service via Uncontrolled Recursive JSON Parsing in JSONReader in run-llama/llama_index

The JSONReader in run-llama/llama_index versions 0.12.28 is vulnerable to a stack overflow due to uncontrolled recursive JSON parsing. This vulnerability allows attackers to trigger a Denial of Service (DoS) by submitting deeply nested JSON structures, leading to a RecursionError and crashing appliโ€ฆ

๐Ÿ“… Published: July 7, 2025, 9:55 a.m. ๐Ÿ”„ Last Modified: July 30, 2025, 8:03 p.m.

6.2

CVSS3.0

CVE-2025-6210 - Hardlink-Based Path Traversal in run-llama/llama_index

A vulnerability in the ObsidianReader class of the run-llama/llama_index repository, specifically in version 0.12.27, allows for hardlink-based path traversal. This flaw permits attackers to bypass path restrictions and access sensitive system files, such as /etc/passwd, by exploiting hardlinks. Thโ€ฆ

๐Ÿ“… Published: July 7, 2025, 9:55 a.m. ๐Ÿ”„ Last Modified: July 30, 2025, 8:01 p.m.

3.5

CVSS3.0

CVE-2025-3777 - Improper Input Validation in huggingface/transformers

Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using the `startswith()` method, which can be bypassed through URL username injection. This allows attackersโ€ฆ

๐Ÿ“… Published: July 7, 2025, 9:55 a.m. ๐Ÿ”„ Last Modified: Aug. 7, 2025, 12:54 a.m.

7.2

CVSS3.1

CVE-2025-3466 - Unsanitized Input in langgenius/dify

langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbitrary code with full root permissions. The vulnerability arises from the ability to override global functions in JavaScript, such as parseInt, before sandbox security restrictionsโ€ฆ

๐Ÿ“… Published: July 7, 2025, 9:55 a.m. ๐Ÿ”„ Last Modified: July 13, 2025, 9:47 p.m.

7.5

CVSS3.0

CVE-2025-6386 - Timing Attack Vulnerability in parisneo/lollms

The parisneo/lollms repository is affected by a timing attack vulnerability in the `authenticate_user` function within the `lollms_authentication.py` file. This vulnerability allows attackers to enumerate valid usernames and guess passwords incrementally by analyzing response time differences. The โ€ฆ

๐Ÿ“… Published: July 7, 2025, 9:55 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.0

CVE-2025-3264 - Regular Expression Denial of Service (ReDoS) in huggingface/transformers

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`. This vulnerability affects versions 4.49.0 and is fixed in version 4.51.0. The issue arises from a regโ€ฆ

๐Ÿ“… Published: July 7, 2025, 9:55 a.m. ๐Ÿ”„ Last Modified: Aug. 7, 2025, 1:02 a.m.

5.3

CVSS3.0

CVE-2025-3263 - Regular Expression Denial of Service (ReDoS) in huggingface/transformers

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the `transformers.configuration_utils` module. The affected version is 4.49.0, and the issue is resolved in version 4.โ€ฆ

๐Ÿ“… Published: July 7, 2025, 9:54 a.m. ๐Ÿ”„ Last Modified: Aug. 7, 2025, 1:03 a.m.

7.5

CVSS3.0

CVE-2025-3046 - Path Traversal via Symbolic Links in run-llama/llama_index

A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allows for arbitrary file read through symbolic links. The `ObsidianReader` fails to resolve symlinks to their real paths and does not validate whether the resolved paths lie within tโ€ฆ

๐Ÿ“… Published: July 7, 2025, 9:54 a.m. ๐Ÿ”„ Last Modified: July 30, 2025, 9:25 p.m.
Total resulsts: 345171
Page 4367 of 34,518
ยซ previous page ยป next page
Filters