Latest CVE Feed
-
7.5
HIGHCVE-2025-46560
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.8.0 and prior to 0.8.5 are affected by a critical performance vulnerability in the input preprocessing logic of the multimodal tokenizer. The co... Read more
Affected Products : vllm- Published: Apr. 30, 2025
- Modified: May. 28, 2025
- Vuln Type: Denial of Service
-
10.0
CRITICALCVE-2025-32444
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and prior to 0.8.5, having vLLM integration with mooncake, are vulnerable to remote code execution due to using pickle based serialization o... Read more
Affected Products : vllm- Published: Apr. 30, 2025
- Modified: May. 28, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-30202
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.5.2 and prior to 0.8.5 are vulnerable to denial of service and data exposure via ZeroMQ on multi-node vLLM deployment. In a multi-node vLLM depl... Read more
Affected Products : vllm- Published: Apr. 30, 2025
- Modified: May. 14, 2025
- Vuln Type: Denial of Service
-
6.3
MEDIUMCVE-2025-46552
KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join your organization. In some commits on version 1.2, a vulnerability was identified where user data, including email addresses and Discord ... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Information Disclosure
-
8.6
HIGHCVE-2025-29906
Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authenticati... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-46550
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are vulnerable to cross-site scripting. An attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated... Read more
Affected Products : yeswiki- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-46549
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take ov... Read more
Affected Products : yeswiki- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Cross-Site Scripting
-
10.0
CRITICALCVE-2025-46348
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authentication. The archives are created with a predictable filename, so a malicious user could create and downl... Read more
Affected Products : yeswiki- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Authentication
-
4.9
MEDIUMCVE-2025-46344
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not... Read more
Affected Products : nextjs-auth0- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-3910
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.... Read more
- Published: Apr. 29, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Authentication
-
8.2
HIGHCVE-2025-3501
A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.... Read more
- Published: Apr. 29, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-4080
A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/view-request.php. The manipulation of the argument viewid leads to sql in... Read more
Affected Products : online_nurse_hiring_system- Published: Apr. 29, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-4078
A vulnerability, which was classified as problematic, has been found in Wangshen SecGate 3600 2400. This issue affects some unknown processing of the file ?g=log_export_file. The manipulation of the argument file_name leads to path traversal. The attack m... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Path Traversal
-
9.4
CRITICALCVE-2025-0520
An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.... Read more
Affected Products : showdoc- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-57698
An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without authentication, even after initial configuration and password change. This happens due to excessive exposure of information and the... Read more
Affected Products : modernwms- Published: Apr. 29, 2025
- Modified: May. 28, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-4079
A vulnerability, which was classified as critical, was found in PCMan FTP Server up to 2.0.7. Affected is an unknown function of the component RENAME Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely.... Read more
- Published: Apr. 29, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-4095
Registry Access Management (RAM) is a security feature allowing administrators to restrict access for their developers to only allowed registries. When a MacOS configuration profile is used to enforce organization sign-in, the RAM policies are not being a... Read more
Affected Products : desktop- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2025-4077
A vulnerability classified as critical was found in code-projects School Billing System 1.0. This vulnerability affects the function searchrec. The manipulation of the argument Name leads to stack-based buffer overflow. It is possible to launch the attack... Read more
Affected Products : school_billing_system- Published: Apr. 29, 2025
- Modified: May. 14, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-4076
A vulnerability classified as critical has been found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function easy_uci_set_option_string_0 of the file /cgi-bin/lighttpd.cgi of the component Password Handler. The manipulation of the argument routepwd ... Read more
Affected Products : bl-ac3600_firmware- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-4075
A vulnerability was found in VMSMan up to 20250416. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Email with the input "><script>alert(1)</script> leads to c... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Cross-Site Scripting