3.5

CVSS3.0

CVE-2025-3777 - Improper Input Validation in huggingface/transformers

Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using the `startswith()` method, which can be bypassed through URL username injection. This allows attackers…

πŸ“… Published: July 7, 2025, 9:55 a.m. πŸ”„ Last Modified: July 7, 2025, 12:26 p.m.

9.8

CVSS3.0

CVE-2025-3466 - Unsanitized Input in langgenius/dify

langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbitrary code with full root permissions. The vulnerability arises from the ability to override global functions in JavaScript, such as parseInt, before sandbox security restrictions…

πŸ“… Published: July 7, 2025, 9:55 a.m. πŸ”„ Last Modified: July 7, 2025, 2:21 p.m.

7.5

CVSS3.0

CVE-2025-6386 - Timing Attack Vulnerability in parisneo/lollms

The parisneo/lollms repository is affected by a timing attack vulnerability in the `authenticate_user` function within the `lollms_authentication.py` file. This vulnerability allows attackers to enumerate valid usernames and guess passwords incrementally by analyzing response time differences. The …

πŸ“… Published: July 7, 2025, 9:55 a.m. πŸ”„ Last Modified: July 7, 2025, 2:22 p.m.

5.3

CVSS3.0

CVE-2025-3264 - Regular Expression Denial of Service (ReDoS) in huggingface/transformers

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`. This vulnerability affects versions 4.49.0 and is fixed in version 4.51.0. The issue arises from a reg…

πŸ“… Published: July 7, 2025, 9:55 a.m. πŸ”„ Last Modified: July 7, 2025, 2:40 p.m.

5.3

CVSS3.0

CVE-2025-3263 - Regular Expression Denial of Service (ReDoS) in huggingface/transformers

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the `transformers.configuration_utils` module. The affected version is 4.49.0, and the issue is resolved in version 4.…

πŸ“… Published: July 7, 2025, 9:54 a.m. πŸ”„ Last Modified: July 7, 2025, 2:51 p.m.

7.5

CVSS3.0

CVE-2025-3046 - Path Traversal via Symbolic Links in run-llama/llama_index

A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allows for arbitrary file read through symbolic links. The `ObsidianReader` fails to resolve symlinks to their real paths and does not validate whether the resolved paths lie within t…

πŸ“… Published: July 7, 2025, 9:54 a.m. πŸ”„ Last Modified: July 7, 2025, 2:15 p.m.

5.3

CVSS3.0

CVE-2025-3262 - Regular Expression Denial of Service (ReDoS) in huggingface/transformers

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient regular expression complexity in the `SETTING_RE` variable within the `transformers/commands/chat.py` file.…

πŸ“… Published: July 7, 2025, 9:54 a.m. πŸ”„ Last Modified: July 7, 2025, 3:19 p.m.

5.3

CVSS3.0

CVE-2025-3044 - MD5 Hash Collision in run-llama/llama_index

A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. This can lead to data loss as papers with identical titles but different contents may overwrite each other…

πŸ“… Published: July 7, 2025, 9:54 a.m. πŸ”„ Last Modified: July 7, 2025, 3:23 p.m.

7.5

CVSS3.0

CVE-2025-3225 - XML Entity Expansion vulnerability in run-llama/llama_index

An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. This vulnerability allows an attacker to supply a malicious Sitemap XML, leading to a Denial of Service (DoS…

πŸ“… Published: July 7, 2025, 9:54 a.m. πŸ”„ Last Modified: July 7, 2025, 2:59 p.m.

7.1

CVSS3.1

CVE-2024-43334 - WordPress Halpes theme <= 1.0.3 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gavias Halpes allows Reflected XSS.This issue affects Halpes: from n/a before 1.2.5.

πŸ“… Published: July 7, 2025, 9:53 a.m. πŸ”„ Last Modified: July 7, 2025, 10:15 a.m.
Total resulsts: 300675
Page 6 of 30,068
Β« previous page Β» next page
Filters