4.8

CVSS4.0

CVE-2025-3165 - thu-pacman chitu backend.py torch.load deserialization

A vulnerability classified as critical has been found in thu-pacman chitu 0.1.0. This affects the function torch.load of the file chitu/chitu/backend.py. The manipulation of the argument ckpt_path/quant_ckpt_dir leads to deserialization. An attack has to be approached locally.

πŸ“… Published: April 3, 2025, 4 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-3164 - Tencent Music Entertainment SuperSonic H2 Database Connection testConnect code injection

A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/semantic/database/testConnect of the component H2 Database Connection Handler. The manipulation leads to code injecti…

πŸ“… Published: April 3, 2025, 3:31 p.m. πŸ”„ Last Modified: April 23, 2025, 3:18 p.m.

4.8

CVSS4.0

CVE-2025-3163 - InternLM LMDeploy conf.py open code injection

A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of the file lmdeploy/docs/en/conf.py. The manipulation leads to code injection. It is possible to launch the attack on the local host. The exploit has be…

πŸ“… Published: April 3, 2025, 3:31 p.m. πŸ”„ Last Modified: April 23, 2025, 3:31 p.m.

9

CVSS3.1

CVE-2025-22457 -

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

πŸ“… Published: April 3, 2025, 3:20 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

8.8

CVSS3.1

CVE-2025-29987 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privile…

πŸ“… Published: April 3, 2025, 3:18 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

8.8

CVSS3.1

CVE-2024-4877 -

OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges

πŸ“… Published: April 3, 2025, 3:11 p.m. πŸ”„ Last Modified: April 29, 2025, 7:45 p.m.

4.8

CVSS4.0

CVE-2025-3162 - InternLM LMDeploy PT File utils.py load_weight_ckpt deserialization

A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation leads to deserialization. Attacking locally is a requirement. …

πŸ“… Published: April 3, 2025, 3 p.m. πŸ”„ Last Modified: April 23, 2025, 10:29 p.m.

5.4

CVSS3.1

CVE-2025-0272 - HCL DevOps Deploy / HCL Launch is susceptible to an HTML injection vulnerability

HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.

πŸ“… Published: April 3, 2025, 2:56 p.m. πŸ”„ Last Modified: April 10, 2025, 1:27 p.m.

8.7

CVSS4.0

CVE-2025-3161 - Tenda AC10 ShutdownSetAdd stack-based overflow

A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. This issue affects the function ShutdownSetAdd of the file /goform/ShutdownSetAdd. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been d…

πŸ“… Published: April 3, 2025, 2:31 p.m. πŸ”„ Last Modified: April 9, 2025, 4:27 p.m.

4.8

CVSS4.0

CVE-2025-3160 - Open Asset Import Library Assimp File SceneCombiner.cpp AddNodeHashes out-of-bounds

A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the component File Handler. The manipulation leads to out-of-bounds read.…

πŸ“… Published: April 3, 2025, 2:31 p.m. πŸ”„ Last Modified: May 28, 2025, 2:11 p.m.
Total resulsts: 349182
Page 6032 of 34,919
Β« previous page Β» next page
Filters