8.9

CVSS4.0

CVE-2025-43844 - GHSL-2025-014_Retrieval-based-Voice-Conversion-WebUI

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, among others, take user input and pass it to the click_train function, which concatenates them into a command that is run on…

📅 Published: May 5, 2025, 5:11 p.m. 🔄 Last Modified: Aug. 1, 2025, 4:54 p.m.

8.9

CVSS4.0

CVE-2025-43843 - GHSL-2025-013_Retrieval-based-Voice-Conversion-WebUI

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, np7 and f0method8 take user input and pass it into the extract_f0_feature function, which concatenates them into a command t…

📅 Published: May 5, 2025, 5:09 p.m. 🔄 Last Modified: Aug. 1, 2025, 4:54 p.m.

8.9

CVSS4.0

CVE-2025-43842 - GHSL-2025-012_Retrieval-based-Voice-Conversion-WebUI

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, np7, trainset_dir4 and sr2 take user input and pass it to the preprocess_dataset function, which concatenates them into a co…

📅 Published: May 5, 2025, 5:08 p.m. 🔄 Last Modified: Aug. 1, 2025, 4:55 p.m.

9.1

CVSS3.1

CVE-2025-24977 - OpenCTI has remote code execution and sensitive secrets exposed through web hook

OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` can execute commands on the underlying infrastructure where OpenCTI is hosted and can access internal server side secrets by misusing the web-hooks. Since the ma…

📅 Published: May 5, 2025, 5:07 p.m. 🔄 Last Modified: May 22, 2025, 3:52 p.m.

1.1

CVSS4.0

CVE-2024-51991 - October CMS Allows Unprotected SVG Rename in Media Manager

October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authenticated administrators with sites that have the `media.clean_vectors` configuration enabled. This configuration will sanitize SVG files uploaded using the media manager. This vuln…

📅 Published: May 5, 2025, 5:04 p.m. 🔄 Last Modified: Sept. 3, 2025, 6:54 p.m.

7.3

CVSS4.0

CVE-2025-0217 - Privileged Remote Access Authentication Bypass

BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to connected sessions.

📅 Published: May 5, 2025, 5 p.m. 🔄 Last Modified: Nov. 3, 2025, 8:17 p.m.

5.3

CVSS3.1

CVE-2025-1992 - IBM Db2 denial of service

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user in federation environment, to cause a denial of service due to insufficient release of allocated memory after usage.

📅 Published: May 5, 2025, 4:54 p.m. 🔄 Last Modified: Nov. 3, 2025, 8:17 p.m.

5.3

CVSS3.1

CVE-2024-11615 - Envolve Plugin <= 1.0 - Unauthenticated Language File Deletion

The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.0 via the 'zetra_deleteLanguageFile' and 'zetra_deleteFontsFile' functions. This is due to the plugin not properly validating a file or its path prior to deleting it. This makes …

📅 Published: May 5, 2025, 4:21 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-4281 - Shenzhen Sixun Software Sixun Shanghui Group Business Management System LoadData information disclo…

A vulnerability, which was classified as problematic, was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 7. This affects an unknown part of the file /api/GylOperator/LoadData. The manipulation leads to information disclosure. It is possible to initiate the attack r…

📅 Published: May 5, 2025, 4 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-4316 -

Improper access control in PAM feature in Devolutions Server allows a PAM user to self approve their PAM requests even if disallowed by the configured policy via specific user interface actions. This issue affects Devolutions Server versions from 2025.1.3.0 through 2025.1.6.0, and all versions…

📅 Published: May 5, 2025, 2 p.m. 🔄 Last Modified: June 17, 2025, 2:13 p.m.
Total resulsts: 346616
Page 5295 of 34,662
« previous page » next page
Filters