0.0
CVE-2025-47298 -
Not used
0.0
CVE-2025-47299 -
Not used
0.0
CVE-2025-47300 -
Not used
0.0
CVE-2025-47301 -
Not used
0.0
CVE-2025-47302 -
Not used
5.8
CVE-2025-46813 - Private data leak on login-required Discourse sites
Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fdee060d44accdee7679d66d778d1136510 and 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b. On login-required sites, the leak meant that some content on the site's homepage could be visible tβ¦
4.8
CVE-2025-4287 - PyTorch nccl.py torch.cuda.nccl.reduce denial of service
A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function torch.cuda.nccl.reduce of the file torch/cuda/nccl.py. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been β¦
6.4
CVE-2025-46734 - league/commonmark Cross-site Scripting vulnerability in Attributes extension
league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert malicious JavaScript calls into HTML. The league/commonmark library provides configuraβ¦
9.8
CVE-2025-1909 - BuddyBoss Platform Pro <= 2.7.01 - Authentication Bypass via Apple OAuth provider
The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the plugin. This makes it possible for unauthenticβ¦
7.3
CVE-2025-46731 - Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI
Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work.β¦