9.3
CVE-2025-27510 - RCE in the package conda-forge-metadata
conda-forge-metadata provides programatic access to conda-forge's metadata. conda-forge-metadata uses an optional dependency - "conda-oci-mirror" which was neither present on the PyPi repository nor registered by any entity. If conda-oci-mirror is taken over by a threat actor, it can result in remo…
6.9
CVE-2025-1956 - code-projects Shopping Portal Login index.php sql injection
A vulnerability classified as critical has been found in code-projects Shopping Portal 1.0. This affects an unknown part of the file /Shopping/Admin/index.php of the component Login. The manipulation of the argument password leads to sql injection. It is possible to initiate the attack remotely. Th…
5.1
CVE-2025-1955 - code-projects Online Class and Exam Scheduling System profile.php cross site scripting
A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Scheduling/scheduling/pages/profile.php. The manipulation of the argument username leads to cross site scriptin…
6.9
CVE-2025-1954 - PHPGurukul Human Metapneumovirus Testing Management System login.php sql injection
A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument username leads to sql injection. The attack can be launc…
5.3
CVE-2024-8000 - On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where…
On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restart. Note: supplicants with pending captive…
5.3
CVE-2024-9135 - On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause th…
On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping.
7.2
CVE-2025-1080 - Macro URL arbitrary script execution
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with a…
2.1
CVE-2025-1953 - vLLM AIBrix Prefix Caching hash.go random values
A vulnerability has been found in vLLM AIBrix 0.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file pkg/plugins/gateway/prefixcacheindexer/hash.go of the component Prefix Caching. The manipulation leads to insufficiently random values. The compl…
9.1
CVE-2025-1260 - On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when…
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in unexpected configuration/operations being applied to the switch.
7.7
CVE-2025-1259 - On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when…
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in users retrieving data that should not have been available