Latest CVE Feed
-
9.8
CRITICALCVE-2025-43850
Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_dir variable takes user input (e.g. a path to a model) and passes it to the change_info fu... Read more
Affected Products : retrieval-based-voice-conversion-webui- Published: May. 05, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-43849
Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_a and cpkt_b variables take user input (e.g. a path to a model) and pass it to the merge f... Read more
Affected Products : retrieval-based-voice-conversion-webui- Published: May. 05, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-29573
Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms module.... Read more
Affected Products : mezzanine- Published: May. 05, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2024-42213
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosu... Read more
Affected Products : bigfix_compliance- Published: May. 05, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2024-42212
HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.... Read more
Affected Products : bigfix_compliance- Published: May. 05, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-4282
A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save. The manipulation leads to cross-site request forgery. The ... Read more
- Published: May. 05, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-4096
Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: May. 05, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4052
Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: ... Read more
- Published: May. 05, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
6.3
MEDIUMCVE-2025-4051
Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: ... Read more
- Published: May. 05, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-4050
Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: M... Read more
- Published: May. 05, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-45239
An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.... Read more
- Published: May. 05, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Path Traversal
-
9.1
CRITICALCVE-2025-45238
foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method.... Read more
Affected Products : foxcms- Published: May. 05, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-45237
Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.... Read more
Affected Products : dbsyncer- Published: May. 05, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-45236
A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Nickname parameter.... Read more
Affected Products : dbsyncer- Published: May. 05, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-43848
Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path0 variable takes user input (e.g. a path to a model) and passes it to the change_info ... Read more
Affected Products : retrieval-based-voice-conversion-webui- Published: May. 05, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-43847
Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path2 variable takes user input (e.g. a path to a model) and passes it to the extract_smal... Read more
Affected Products : retrieval-based-voice-conversion-webui- Published: May. 05, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-43846
Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path1 variable takes user input (e.g. a path to a model) and passes it to the show_info fu... Read more
Affected Products : retrieval-based-voice-conversion-webui- Published: May. 05, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-43845
Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to code injection. The ckpt_path2 variable takes user input (e.g. a path to a model) and passes it to change_info_ function, w... Read more
Affected Products : retrieval-based-voice-conversion-webui- Published: May. 05, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-43844
Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, among others, take user input and pass it to the click_train function, which con... Read more
Affected Products : retrieval-based-voice-conversion-webui- Published: May. 05, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2025-45242
Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method in /file/file.admin.controller.php.... Read more
Affected Products : rhymix- Published: May. 05, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal