8.9

CVSS4.0

CVE-2025-43847 - GHSL-2025-017_Retrieval-based-Voice-Conversion-WebUI

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path2 variable takes user input (e.g. a path to a model) and passes it to the extract_small_model function in process_ckpt.py, which u…

📅 Published: May 5, 2025, 5:21 p.m. 🔄 Last Modified: Aug. 1, 2025, 4:54 p.m.

8.9

CVSS4.0

CVE-2025-43846 - GHSL-2025-016_Retrieval-based-Voice-Conversion-WebUI

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path1 variable takes user input (e.g. a path to a model) and passes it to the show_info function in process_ckpt.py, which uses it to …

📅 Published: May 5, 2025, 5:16 p.m. 🔄 Last Modified: Aug. 1, 2025, 4:54 p.m.

8.9

CVSS4.0

CVE-2025-43845 - GHSL-2025-015_Retrieval-based-Voice-Conversion-WebUI

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to code injection. The ckpt_path2 variable takes user input (e.g. a path to a model) and passes it to change_info_ function, which opens and reads the file on the given p…

📅 Published: May 5, 2025, 5:15 p.m. 🔄 Last Modified: Aug. 1, 2025, 4:54 p.m.

8.9

CVSS4.0

CVE-2025-43844 - GHSL-2025-014_Retrieval-based-Voice-Conversion-WebUI

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, among others, take user input and pass it to the click_train function, which concatenates them into a command that is run on…

📅 Published: May 5, 2025, 5:11 p.m. 🔄 Last Modified: Aug. 1, 2025, 4:54 p.m.

8.9

CVSS4.0

CVE-2025-43843 - GHSL-2025-013_Retrieval-based-Voice-Conversion-WebUI

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, np7 and f0method8 take user input and pass it into the extract_f0_feature function, which concatenates them into a command t…

📅 Published: May 5, 2025, 5:09 p.m. 🔄 Last Modified: Aug. 1, 2025, 4:54 p.m.

8.9

CVSS4.0

CVE-2025-43842 - GHSL-2025-012_Retrieval-based-Voice-Conversion-WebUI

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, np7, trainset_dir4 and sr2 take user input and pass it to the preprocess_dataset function, which concatenates them into a co…

📅 Published: May 5, 2025, 5:08 p.m. 🔄 Last Modified: Aug. 1, 2025, 4:55 p.m.

9.1

CVSS3.1

CVE-2025-24977 - OpenCTI has remote code execution and sensitive secrets exposed through web hook

OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` can execute commands on the underlying infrastructure where OpenCTI is hosted and can access internal server side secrets by misusing the web-hooks. Since the ma…

📅 Published: May 5, 2025, 5:07 p.m. 🔄 Last Modified: May 22, 2025, 3:52 p.m.

1.1

CVSS4.0

CVE-2024-51991 - October CMS Allows Unprotected SVG Rename in Media Manager

October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authenticated administrators with sites that have the `media.clean_vectors` configuration enabled. This configuration will sanitize SVG files uploaded using the media manager. This vuln…

📅 Published: May 5, 2025, 5:04 p.m. 🔄 Last Modified: Sept. 3, 2025, 6:54 p.m.

7.3

CVSS4.0

CVE-2025-0217 - Privileged Remote Access Authentication Bypass

BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to connected sessions.

📅 Published: May 5, 2025, 5 p.m. 🔄 Last Modified: Nov. 3, 2025, 8:17 p.m.

5.3

CVSS3.1

CVE-2025-1992 - IBM Db2 denial of service

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user in federation environment, to cause a denial of service due to insufficient release of allocated memory after usage.

📅 Published: May 5, 2025, 4:54 p.m. 🔄 Last Modified: Nov. 3, 2025, 8:17 p.m.
Total resulsts: 345209
Page 5154 of 34,521
« previous page » next page
Filters