8.1
CVE-2025-46725 - Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store
Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `LanceDocChatAgent` uses pandas eval() through `compute_from_docs()`. As a result, an attacker may be able to make the agent run malicious commands through `QueryPlan.dataframe_calc]`)β¦
9.8
CVE-2025-46724 - Langroid has a Code Injection vulnerability in TableChatAgent
Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `TableChatAgent` uses `pandas eval()`. If fed by untrusted user input, like the case of a public-facing LLM application, it may be vulnerable to code injection. Langroid 0.53.15 sanitiβ¦
6.5
CVE-2024-45641 - IBM Security ReaQta improper certificate validation
IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate validation.
7.5
CVE-2025-48018 - Deserialization of Untrusted Data
An authenticated user can modify application state data.
9
CVE-2025-48017 - Improper Limitation of a Pathname to a Restricted Directory
Improper limitation of pathname in Circuit Provisioning and File Import applications allows modification and uploading of files
4.3
CVE-2025-48016 - Improper Control of Interaction Frequency
OpenFlow discovery protocol can exhaust resources because it is not rate limited
3.7
CVE-2025-48015 - Observable Response Discrepancy
Failed login response could be different depending on whether the username was local or central.
7.5
CVE-2025-48014 - Improper Restriction of Excessive Authentication Attempts
Password guessing limits could be bypassed when using LDAP authentication.
6.5
CVE-2023-33861 - IBM Security ReaQta improper certificate validation
IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication path between the host and client.
4.3
CVE-2025-41228 - VMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) Vulnerability
VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation.Β A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.