8.9

CVSS4.0

CVE-2025-49839 - GHSL-2025-051: GPT-SoVITS Deserialization of Untrusted Data vulnerability

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in bsroformer.py. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function. In uvr, a new instance of Rofo…

📅 Published: July 15, 2025, 8:40 p.m. 🔄 Last Modified: July 30, 2025, 8:13 p.m.

8.9

CVSS4.0

CVE-2025-49838 - GHSL-2025-050: GPT-SoVITS Deserialization of Untrusted Data vulnerability

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in vr.py AudioPreDeEcho. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function. In uvr, a new instance …

📅 Published: July 15, 2025, 8:36 p.m. 🔄 Last Modified: July 30, 2025, 8:14 p.m.

8.9

CVSS4.0

CVE-2025-49837 - GHSL-2025-049: GPT-SoVITS Deserialization of Untrusted Data vulnerability

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in vr.py AudioPre. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function. In uvr, a new instance of Aud…

📅 Published: July 15, 2025, 8:34 p.m. 🔄 Last Modified: July 30, 2025, 8:12 p.m.

8.9

CVSS4.0

CVE-2025-49836 - GHSL-2025-048: GPT-SoVITS Command Injection vulnerability

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui.py change_label function. path_list takes user input, which is passed to the change_label function, which concatenates the user input into a command…

📅 Published: July 15, 2025, 8:31 p.m. 🔄 Last Modified: July 30, 2025, 8:14 p.m.

8.9

CVSS4.0

CVE-2025-49835 - GHSL-2025-047: GPT-SoVITS Command Injection vulnerability

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui.py open_asr function. asr_inp_dir (and a number of other variables) takes user input, which is passed to the open_asr function, which concatenates t…

📅 Published: July 15, 2025, 8:29 p.m. 🔄 Last Modified: July 30, 2025, 8:12 p.m.

8.9

CVSS4.0

CVE-2025-49834 - GHSL-2025-046: GPT-SoVITS Command Injection vulnerability

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui.py open_denoise function. denoise_inp_dir and denoise_opt_dir take user input, which is passed to the open_denoise function, which concatenates the …

📅 Published: July 15, 2025, 8:25 p.m. 🔄 Last Modified: July 30, 2025, 8:13 p.m.

8.9

CVSS4.0

CVE-2025-49833 - GHSL-2025-045: GPT-SoVITS Command Injection vulnerability

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in the webui.py open_slice function. slice_opt_root and slice-inp-path takes user input, which is passed to the open_slice function, which concatenates the u…

📅 Published: July 15, 2025, 8:22 p.m. 🔄 Last Modified: July 30, 2025, 8:11 p.m.

9.1

CVSS4.0

CVE-2025-49831 - Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) vulnerable to IAM Authenti…

An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can reroute authentication requests to a malicious server under the attacker’s control. CyberArk believes there to be very few installations where this iss…

📅 Published: July 15, 2025, 8:10 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

7.1

CVSS4.0

CVE-2025-49830 - Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) vulnerable to path travers…

Conjur provides secrets management and application identity for infrastructure. An authenticated attacker who is able to load policy can use the policy yaml parser to reference files on the Secrets Manager, Self-Hosted server. These references may be used as reconnaissance to better understand the …

📅 Published: July 15, 2025, 8:04 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

5.9

CVSS3.1

CVE-2025-30761 - openjdk: Improve scripting supports (Oracle CPU 2025-07)

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u451, 8u451-perf and 11.0.27; Oracle GraalVM Enterprise Edition: 21.3.14. Difficult to exploit vulnerability allows un…

📅 Published: July 15, 2025, 8 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.
Total resulsts: 347738
Page 4487 of 34,774
« previous page » next page
Filters