Latest CVE Feed
-
7.3
HIGHCVE-2025-46722
vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before 0.9.0, in the file vllm/multimodal/hasher.py, the MultiModalHasher class has a security and data integrity issue in its image hashing metho... Read more
Affected Products : vllm- Published: May. 29, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Misconfiguration
-
5.7
MEDIUMCVE-2025-32752
Dell ThinOS 2502 and prior contain a Cleartext Storage of Sensitive Information vulnerability. A high privileged attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.... Read more
Affected Products : thinos- Published: May. 29, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2022-44794
An issue was discovered in Object First Ootbi BETA build 1.0.7.712. Management protocol has a flow which allows a remote attacker to execute arbitrary Bash code with root privileges. The command that sets the hostname doesn't validate input parameters. As... Read more
- Published: Nov. 07, 2022
- Modified: Jun. 24, 2025
-
6.5
MEDIUMCVE-2022-44795
An issue was discovered in Object First Ootbi BETA build 1.0.7.712. A flaw was found in the Web Service, which could lead to local information disclosure. The command that creates the URL for the support bundle uses an insecure RNG. That can lead to predi... Read more
- Published: Nov. 07, 2022
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2022-44796
An issue was discovered in Object First Ootbi BETA build 1.0.7.712. The authorization service has a flow that allows getting access to the Web UI without knowing credentials. For signing, the JWT token uses a secret key that is generated through a functio... Read more
- Published: Nov. 07, 2022
- Modified: Jun. 24, 2025
-
6.5
MEDIUMCVE-2025-48942
vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, hitting the /v1/completions API with a invalid json_schema as a Guided Param kills the vllm server. This vulnerability is similar GHSA-... Read more
Affected Products : vllm- Published: May. 30, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-48943
vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) that causes the vLLM server to crash if an invalid regex was provided while using structured output. This vu... Read more
Affected Products : vllm- Published: May. 30, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2023-4527
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents... Read more
Affected Products : enterprise_linux fedora enterprise_linux_server_aus h410c_firmware enterprise_linux_eus h300s_firmware h500s_firmware h700s_firmware h410s_firmware glibc +22 more products- Published: Sep. 18, 2023
- Modified: Jun. 24, 2025
-
5.3
MEDIUMCVE-2024-56946
Denial of service in DNS-over-QUIC in Technitium DNS Server <= v13.2.2 allows remote attackers to permanently stop the server from accepting new DNS-over-QUIC connections by triggering unhandled exceptions in listener threads.... Read more
Affected Products : dnsserver- Published: Feb. 03, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Denial of Service
-
7.3
HIGHCVE-2025-1936
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have be... Read more
- Published: Mar. 04, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Information Disclosure
-
9.1
CRITICALCVE-2024-11705
`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred, leading to crashes. This behavior conflicted with the PKCS#11 v3.0 specification, which allows `phKey` t... Read more
- Published: Nov. 26, 2024
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2024-11698
A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened during the transition. This issue left users unable to exit fullscreen mode using standard actions li... Read more
- Published: Nov. 26, 2024
- Modified: Jun. 24, 2025
-
5.4
MEDIUMCVE-2024-11696
The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the si... Read more
- Published: Nov. 26, 2024
- Modified: Jun. 24, 2025
-
6.1
MEDIUMCVE-2024-11694
Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading... Read more
- Published: Nov. 26, 2024
- Modified: Jun. 24, 2025
-
8.8
HIGHCVE-2024-11691
Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were unaf... Read more
Affected Products : firefox firefox_esr thunderbird m1 m1_max m1_pro m1_ultra m2 m2_max m2_pro +8 more products- Published: Nov. 26, 2024
- Modified: Jun. 24, 2025
-
5.4
MEDIUMCVE-2024-50637
UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies.... Read more
Affected Products : unopim- Published: Nov. 06, 2024
- Modified: Jun. 24, 2025
-
6.1
MEDIUMCVE-2023-2142
In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross ... Read more
Affected Products : nunjucks- Published: Nov. 26, 2024
- Modified: Jun. 24, 2025
-
7.5
HIGHCVE-2025-1975
A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloading a m... Read more
Affected Products : ollama- Published: May. 16, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2024-7297
Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing a mass assignment request on the '/api/v1/users' endpoint.... Read more
Affected Products : langflow- Published: Jul. 30, 2024
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2025-32966
DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.8.... Read more
Affected Products : dataease- Published: Apr. 23, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Authentication