7.7

CVSS4.0

CVE-2025-27785 - Applio allows arbitrary file read in train.py export_index function

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_index` function. This issue may lead to reading arbitrary files on the Applio server. It can also be used in conjunction with blind server-side request forgery to read fileโ€ฆ

๐Ÿ“… Published: March 19, 2025, 8:35 p.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 4:19 p.m.

8.9

CVSS4.0

CVE-2025-27781 - Applio allows unsafe deserialization in inference.py

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in inference.py. `model_file` in inference.py as well as `model_file` in tts.py take user-supplied input (e.g. a path to a model) and pass that value to the `change_choices` and later to `getโ€ฆ

๐Ÿ“… Published: March 19, 2025, 8:22 p.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 4:35 p.m.

8.9

CVSS4.0

CVE-2025-27780 - Applio allows unsafe deserialization in model_information.py

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in model_information.py. `model_name` in model_information.py takes user-supplied input (e.g. a path to a model) and pass that value to the `run_model_information_script` and later to `model_โ€ฆ

๐Ÿ“… Published: March 19, 2025, 8:16 p.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 4:38 p.m.

5.5

CVSS4.0

CVE-2025-27705 -

There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.53. Attackers with system administrator permissions can interfere with another system administratorโ€™s use of the management console when the second administrator lโ€ฆ

๐Ÿ“… Published: March 19, 2025, 7:15 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS4.0

CVE-2025-27704 -

There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.53. Attackers with system administrator permissions can interfere with another system administratorโ€™s use of the management console when the second administrator lโ€ฆ

๐Ÿ“… Published: March 19, 2025, 7:08 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-27415 - Nuxt allows DOS via cache poisoning with payload rendering response

Nuxt is an open-source web development framework for Vue.js. Prior to 3.16.0, by sending a crafted HTTP request to a server behind an CDN, it is possible in some circumstances to poison the CDN cache and highly impacts the availability of a site. It is possible to craft a request, such as https://mโ€ฆ

๐Ÿ“… Published: March 19, 2025, 7:02 p.m. ๐Ÿ”„ Last Modified: Dec. 3, 2025, 6:44 p.m.

5.1

CVSS4.0

CVE-2025-2536 -

Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 82 through update 92 in the Frontend JS module's layouโ€ฆ

๐Ÿ“… Published: March 19, 2025, 7 p.m. ๐Ÿ”„ Last Modified: Dec. 16, 2025, 6:43 p.m.

8.8

CVSS3.1

CVE-2025-2476 -

Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

๐Ÿ“… Published: March 19, 2025, 6:59 p.m. ๐Ÿ”„ Last Modified: April 1, 2025, 8:37 p.m.

8.4

CVSS3.1

CVE-2024-51459 - IBM InfoSphere Server Information command execution

IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions.

๐Ÿ“… Published: March 19, 2025, 6:08 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

4.3

CVSS3.1

CVE-2024-7631 - Openshift-console: openshift console: path traversal

A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/resources.json. This endpoint's lng and ns parameters are used to construct a filepath in pkg/plugins/handlers unsafely.go#L112 Because of this unsafe filepath construction, an authโ€ฆ

๐Ÿ“… Published: March 19, 2025, 5:49 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6302 of 34,919
ยซ previous page ยป next page
Filters