5.3

CVSS4.0

CVE-2025-7946 - PHPGurukul Apartment Visitors Management System HTTP POST Request search-visitor.php cross site scr…

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /search-visitor.php of the component HTTP POST Request Handler. The manipulation of the argument searchdata leads to cross site …

πŸ“… Published: July 22, 2025, 12:02 a.m. πŸ”„ Last Modified: July 29, 2025, 8:42 p.m.

8.8

CVSS3.1

CVE-2025-51865 -

Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to gain sensitvie information via enumerating thread keys in the URL.

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS3.1

CVE-2025-51481 -

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 8:34 p.m.

8.8

CVSS3.1

CVE-2025-51464 -

Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python code submitted to the /api/reports endpoint, which is interpreted and executed by Pyodide when the report is viewed. No sanitisation or sandbox restrict…

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 4:24 p.m.

6.1

CVSS3.1

CVE-2025-51858 -

Self Cross-Site Scripting (XSS) vulnerability in ChatPlayground.ai through 2025-05-24, allows attackers to execute arbitrary code and gain sensitive information via a crafted SVG file contents sent through the chat component.

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-51482 -

Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Python code and system commands via crafted payloads to the /v1/tools/run endpoint, bypassing intended sandbox restrictions.

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 8:33 p.m.

6.1

CVSS3.1

CVE-2025-51863 -

Self Cross Site Scripting (XSS) vulnerability in ChatGPT Unli (ChatGPTUnli.com) thru 2025-05-26 allows attackers to execute arbitrary code via a crafted SVG file to the chat interface.

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-51867 -

Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI (deepfiction.ai) thru June 3, 2025, allowing attackers to chat with the LLM using other users' credits via sensitive information gained by the /browse/stories endpoint.

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-51472 -

Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via malicious values in agent template configurations such as the goal, constraints, or instruction field, which are evaluated using eval() without valida…

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 4:09 p.m.

6.5

CVSS3.1

CVE-2025-51859 -

Stored Cross-Site Scripting (XSS) vulnerability in Chaindesk thru 2025-05-26 in its agent chat component. An attacker can achieve arbitrary client-side script execution by crafting an AI agent whose system prompt instructs the underlying Large Language Model (LLM) to embed malicious script payloads…

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4554 of 34,919
Β« previous page Β» next page
Filters