10.0

CVSS3.1

CVE-2025-2828 - SSRF Vulnerability in RequestsToolkit in langchain-ai/langchain

A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain_community.agent_toolkits.openapi.toolkit.RequestsToolkit) in langchain-ai/langchain version 0.0.27. This vulnerability occurs because the toolkit do…

πŸ“… Published: June 23, 2025, 8:42 p.m. πŸ”„ Last Modified: July 16, 2025, 7:46 p.m.

6.4

CVSS3.1

CVE-2025-49574 - Quarkus potential data leak when duplicating a duplicated context

Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.1, 3.20.2, and 3.15.6, there is a potential data leak when duplicating a duplicated context. Quarkus extensively uses the Vert.x duplicated context to implement context propagation.…

πŸ“… Published: June 23, 2025, 7:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-49144 - Notepad++ Privilege Escalation in Installer via Uncontrolled Executable Search Path

Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social en…

πŸ“… Published: June 23, 2025, 7:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS4.0

CVE-2025-6547 - On Node.js < 3, pbkdf2 silently disregards Uint8Array input, returning static keys

Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: <=3.1.2.

πŸ“… Published: June 23, 2025, 7 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-6518 - PySpur-Dev pyspur Jinja2 Template single_llm_call.py SingleLLMCallNode special elements used in a t…

A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the function SingleLLMCallNode of the file backend/pyspur/nodes/llm/single_llm_call.py of the component Jinja2 Template Handler. The manipulation of the argument user_message leads to improp…

πŸ“… Published: June 23, 2025, 7 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS4.0

CVE-2025-6545 - pbkdf2 silently returns predictable uninitialized/zero-filled memory for non-normalized or unimplem…

Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js. This issue affects pbkdf2: from 3.0.10 through 3.1.2.

πŸ“… Published: June 23, 2025, 6:41 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-6517 - Dromara MaxKey Meta URL SAML20DetailsController.java add server-side request forgery

A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add of the file maxkey-webs\maxkey-web-mgt\src\main\java\org\dromara\maxkey\web\apps\contorller\SAML20DetailsController.java of the component Meta URL Handler. The manipulation of the…

πŸ“… Published: June 23, 2025, 6 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 6:19 p.m.

0.0

CVE-2025-52971 -

Not used

πŸ“… Published: June 23, 2025, 5:39 p.m. πŸ”„ Last Modified: June 24, 2025, 3:15 a.m.

0.0

CVE-2025-52972 -

Not used

πŸ“… Published: June 23, 2025, 5:39 p.m. πŸ”„ Last Modified: June 24, 2025, 3:15 a.m.

0.0

CVE-2025-52974 -

Not used

πŸ“… Published: June 23, 2025, 5:39 p.m. πŸ”„ Last Modified: June 24, 2025, 3:15 a.m.
Total resulsts: 349182
Page 4912 of 34,919
Β« previous page Β» next page
Filters