6.9

CVSS3.1

CVE-2025-51471 -

Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW-Authenticate header returned by the /api/pull endpoint.

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 6:15 p.m.

5.4

CVSS3.1

CVE-2025-51479 -

Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary user groups via crafted PATCH requests to the /api/manage/admin/user-group/id endpoint, bypassing intended curator-group assignment checks.

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 4:10 p.m.

5

CVSS3.1

CVE-2025-51475 -

Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite arbitrary files via unsanitised filenames submitted to the file upload endpoint, due to improper handling of directory traversal in os.path.join() and l…

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 4:08 p.m.

7.4

CVSS3.1

CVE-2025-38352 - posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_timers() from IRQ, it can be reaped by its pare…

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

6.1

CVSS3.1

CVE-2025-51462 -

Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary JavaScript via crafted input to the assistant greeting field, which is stored unsanitised and rendered using a markdown component with rehype-raw.

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 4:02 p.m.

7

CVSS3.1

CVE-2025-51463 -

Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a crafted backup tar file submitted to the run_instruction API, which is extracted without path validation during restoration.

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 4:26 p.m.

8.8

CVSS3.1

CVE-2025-51480 -

Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions.

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: Oct. 8, 2025, 1:11 p.m.

6.5

CVSS3.1

CVE-2025-31513 -

An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can elevate to administrator privileges via the IsAdminApprover parameter in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version equal to or greater th…

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-31512 -

An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval via isAddedByApprover in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version equal to or greater than one of the following …

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-51860 -

Stored Cross-Site Scripting (XSS) in TelegAI (telegai.com) 2025-05-26 in its chat component and character container component. An attacker can achieve arbitrary client-side script execution by crafting an AI Character with SVG XSS payloads in either description, greeting, example dialog, or system …

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4555 of 34,919
Β« previous page Β» next page
Filters