8.2

CVSS3.1

CVE-2025-32353 -

Kaseya Rapid Fire Tools Network Detective 2.0.16.0 has Unencrypted Credentials (for privileged access) stored in the collector.txt configuration file.

📅 Published: July 16, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.1

CVSS3.1

CVE-2025-53906 - Vim has path traversal issue with zip.vim and special crafted zip archives

Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of arbitrary files when opening specially crafted zip archives. Impact is low because this exploit requires direct user interaction. However, successfully…

📅 Published: July 15, 2025, 8:52 p.m. 🔄 Last Modified: April 1, 2026, 7:16 p.m.

4.1

CVSS3.1

CVE-2025-53905 - Vim has path traversial issue with tar.vim and special crafted tar files

Vim is an open source, command line text editor. Prior to version 9.1.1552, a path traversal issue in Vim’s tar.vim plugin can allow overwriting of arbitrary files when opening specially crafted tar archives. Impact is low because this exploit requires direct user interaction. However, successfully…

📅 Published: July 15, 2025, 8:48 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2025-6981 - Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed unaut…

An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor accounts when the Contractors API feature was enabled. The Contractors API is a rarely-enabled feature in private preview. This vulnerability affected all versions of Gi…

📅 Published: July 15, 2025, 8:44 p.m. 🔄 Last Modified: Aug. 27, 2025, 2:41 p.m.

8.9

CVSS4.0

CVE-2025-49841 - GHSL-2025-053: GPT-SoVITS Deserialization of Untrusted Data vulnerability

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in process_ckpt.py. The SoVITS_dropdown variable takes user input and passes it to the load_sovits_new function in process_ckpt.py. In load_sovits_new,…

📅 Published: July 15, 2025, 8:43 p.m. 🔄 Last Modified: July 30, 2025, 8:15 p.m.

8.9

CVSS4.0

CVE-2025-49840 - GHSL-2025-052: GPT-SoVITS Deserialization of Untrusted Data vulnerability

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in inference_webui.py. The GPT_dropdown variable takes user input and passes it to the change_gpt_weights function. In change_gpt_weights, the user inp…

📅 Published: July 15, 2025, 8:42 p.m. 🔄 Last Modified: July 30, 2025, 8:15 p.m.

8.9

CVSS4.0

CVE-2025-49839 - GHSL-2025-051: GPT-SoVITS Deserialization of Untrusted Data vulnerability

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in bsroformer.py. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function. In uvr, a new instance of Rofo…

📅 Published: July 15, 2025, 8:40 p.m. 🔄 Last Modified: July 30, 2025, 8:13 p.m.

8.9

CVSS4.0

CVE-2025-49838 - GHSL-2025-050: GPT-SoVITS Deserialization of Untrusted Data vulnerability

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in vr.py AudioPreDeEcho. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function. In uvr, a new instance …

📅 Published: July 15, 2025, 8:36 p.m. 🔄 Last Modified: July 30, 2025, 8:14 p.m.

8.9

CVSS4.0

CVE-2025-49837 - GHSL-2025-049: GPT-SoVITS Deserialization of Untrusted Data vulnerability

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in vr.py AudioPre. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function. In uvr, a new instance of Aud…

📅 Published: July 15, 2025, 8:34 p.m. 🔄 Last Modified: July 30, 2025, 8:12 p.m.

8.9

CVSS4.0

CVE-2025-49836 - GHSL-2025-048: GPT-SoVITS Command Injection vulnerability

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui.py change_label function. path_list takes user input, which is passed to the change_label function, which concatenates the user input into a command…

📅 Published: July 15, 2025, 8:31 p.m. 🔄 Last Modified: July 30, 2025, 8:14 p.m.
Total resulsts: 347734
Page 4486 of 34,774
« previous page » next page
Filters