Latest CVE Feed
-
8.0
HIGHCVE-2025-3467
An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vulnerability allows an attacker to obtain the administrator's token by sending a payload in the published chat. When the administrator v... Read more
- Published: Jul. 07, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-3466
langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbitrary code with full root permissions. The vulnerability arises from the ability to override global functions in JavaScript, such as pa... Read more
- Published: Jul. 07, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-3264
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`. This vulnerability affects versions 4.49.0 and is fixed in... Read more
Affected Products : transformers- Published: Jul. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2025-3263
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the `transformers.configuration_utils` module. The affected version is 4.4... Read more
Affected Products : transformers- Published: Jul. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-3262
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient regular expression complexity in the `SETTING_RE` variable with... Read more
Affected Products : transformers- Published: Jul. 07, 2025
- Modified: Aug. 02, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-3225
An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. This vulnerability allows an attacker to supply a malicious Site... Read more
Affected Products : llamaindex- Published: Jul. 07, 2025
- Modified: Jul. 30, 2025
- Vuln Type: XML External Entity
-
7.5
HIGHCVE-2025-3046
A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allows for arbitrary file read through symbolic links. The `ObsidianReader` fails to resolve symlinks to their real paths and does not vali... Read more
Affected Products : llamaindex- Published: Jul. 07, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2025-3044
A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. This can lead to data loss as papers with identical titles but... Read more
Affected Products : llamaindex- Published: Jul. 07, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Misconfiguration
-
7.1
HIGHCVE-2024-43334
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gavias Halpes allows Reflected XSS.This issue affects Halpes: from n/a before 1.2.5.... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-7121
A vulnerability was found in Campcodes Complaint Management System 1.0. It has been classified as critical. This affects an unknown part of the file /users/complaint-details.php. The manipulation of the argument cid leads to sql injection. It is possible ... Read more
Affected Products : complaint_management_system- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7120
A vulnerability was found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /users/check_availability.php. The manipulation of the argument email leads to sql injectio... Read more
Affected Products : complaint_management_system- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
-
8.5
HIGHCVE-2025-3920
A vulnerability was identified in SUR-FBD CMMS where hard-coded credentials were found within a compiled DLL file. These credentials correspond to a built-in administrative account of the software. An attacker with local access to the system or the applic... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-7119
A vulnerability has been found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /users/index.php. The manipulation of the argument Username leads to sql injecti... Read more
Affected Products : complaint_management_system- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-7118
A vulnerability, which was classified as critical, has been found in UTT HiPER 840G up to 3.1.1-190328. This issue affects some unknown processing of the file /goform/formPictureUrl. The manipulation of the argument importpictureurl leads to buffer overfl... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-7117
A vulnerability classified as critical was found in UTT HiPER 840G up to 3.1.1-190328. This vulnerability affects unknown code of the file /goform/websWhiteList. The manipulation of the argument addHostFilter leads to buffer overflow. The attack can be in... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-7116
A vulnerability classified as critical has been found in UTT 进取 750W up to 3.2.2-191225. This affects an unknown part of the file /goform/Fast_wireless_conf. The manipulation of the argument ssid leads to buffer overflow. It is possible to initiate the at... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
10.0
CRITICALCVE-2025-41672
A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain full access to the tool and all connected devices.... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-7115
A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as critical. Affected by this issue is the function PUT of the file apps/rowboat/app/api/uploads/[fileId]/route.ts of the component Session ... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-7114
A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as critical. Affected by this vulnerability is the function POST of the file apps/sim/app/api/files/upload/route.ts of the component Session ... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
-
5.4
MEDIUMCVE-2025-7113
A vulnerability was found in Portabilis i-Educar 2.9.0. It has been classified as problematic. Affected is an unknown function of the file /module/ComponenteCurricular/edit?id=ID of the component Curricular Components Module. The manipulation of the argum... Read more
Affected Products : i-educar- Published: Jul. 07, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Cross-Site Scripting