Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-64725 |
|
Vulnerability in weblate (CVE-2025-64725)
vulnerability in weblate (CVE-2025-64725). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.15` or later.
|
| CVE-2025-14542 |
|
Vulnerability in utcp (CVE-2025-14542)
vulnerability in utcp (CVE-2025-14542). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.1.0` or later.
|
| CVE-2025-66418 |
|
Vulnerability in urllib3 (CVE-2025-66418)
vulnerability in urllib3 (CVE-2025-66418). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.6.0` or later.
|
| CVE-2025-67720 |
|
Path Traversal in pyrofork (CVE-2025-67720)
path traversal in pyrofork (CVE-2025-67720). Data can be tampered with by attackers. Exploitable via ``download_media``. Mitigation: upgrade to `2.3.69` or later.
|
| CVE-2025-65958 |
|
SSRF (Server-Side Request Forgery) in open-webui (CVE-2025-65958)
SSRF in open-webui (CVE-2025-65958). Confidential information can be exposed externally. Mitigation: upgrade to `0.6.37` or later.
|
| CVE-2025-67747 |
|
Vulnerability in fickling (CVE-2025-67747)
vulnerability in fickling (CVE-2025-67747). Risk of unauthorized operations or information disclosure. Exploitable via ``marshal``. Mitigation: upgrade to `0.1.6` or later.
|
| CVE-2025-56427 |
|
Information Disclosure in composio (CVE-2025-56427)
vulnerability in composio (CVE-2025-56427). Confidential information can be exposed externally.
|
| CVE-2025-66645 |
|
Path Traversal in nicegui (CVE-2025-66645)
path traversal in nicegui (CVE-2025-66645). Confidential information can be exposed externally. Exploitable via ``poc.py``. Mitigation: upgrade to `3.4.0` or later.
|
| CVE-2025-66469 |
|
Cross-Site Scripting (XSS) in nicegui (CVE-2025-66469)
cross-site scripting in nicegui (CVE-2025-66469). Risk of unauthorized operations or information disclosure. Exploitable via ``ui.add_css``. Mitigation: upgrade to `3.4.0` or later.
|
| CVE-2025-66470 |
|
Cross-Site Scripting (XSS) in nicegui (CVE-2025-66470)
cross-site scripting in nicegui (CVE-2025-66470). Risk of unauthorized operations or information disclosure. Exploitable via ``ui.interactive_image``. Mitigation: upgrade to `3.4.0` or later.
|
| CVE-2025-67485 |
|
Vulnerability in mad-proxy (CVE-2025-67485)
vulnerability in mad-proxy (CVE-2025-67485). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-67644 |
|
SQL Injection in langgraph-checkpoint-sqlite (CVE-2025-67644)
SQL injection in langgraph-checkpoint-sqlite (CVE-2025-67644). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.1` or later.
|
| CVE-2025-66422 |
|
Vulnerability in trytond (CVE-2025-66422)
vulnerability in trytond (CVE-2025-66422). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.6.11` or later.
|
| CVE-2025-66423 |
|
Authorization Flaw in trytond (CVE-2025-66423)
vulnerability in trytond (CVE-2025-66423). Confidential information can be exposed externally. Mitigation: upgrade to `7.6.11` or later.
|
| CVE-2025-66424 |
|
Authorization Flaw in trytond (CVE-2025-66424)
vulnerability in trytond (CVE-2025-66424). Confidential information can be exposed externally. Mitigation: upgrade to `7.6.11` or later.
|
| CVE-2025-66040 |
|
Cross-Site Scripting (XSS) in spotipy (CVE-2025-66040)
cross-site scripting in spotipy (CVE-2025-66040). Risk of unauthorized operations or information disclosure. Exploitable via ``error``. Mitigation: upgrade to `2.25.2` or later.
|
| CVE-2025-66221 |
|
Vulnerability in werkzeug (CVE-2025-66221)
vulnerability in werkzeug (CVE-2025-66221). Risk of unauthorized operations or information disclosure. Exploitable via ``safe_join``. Mitigation: upgrade to `3.1.4` or later.
|
| CVE-2025-12060 |
|
Path Traversal in keras (CVE-2025-12060)
path traversal in keras (CVE-2025-12060). Successful exploitation can lead to full system takeover. Exploitable via ``tarfile``. Mitigation: upgrade to `3.12.0` or later.
|
| CVE-2025-65858 |
|
Cross-Site Scripting (XSS) in calibreweb (CVE-2025-65858)
cross-site scripting in calibreweb (CVE-2025-65858). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-66034 |
|
Vulnerability in fonttools (CVE-2025-66034)
vulnerability in fonttools (CVE-2025-66034). Data can be tampered with by attackers. Exploitable via ``fontTools.varLib``. Mitigation: upgrade to `4.60.2` or later.
|
| CVE-2025-66371 |
|
XXE (XML External Entity) in peppol-py (CVE-2025-66371)
vulnerability in peppol-py (CVE-2025-66371). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.1.1` or later.
|
| CVE-2025-66454 |
|
Vulnerability in arcade-mcp-server (CVE-2025-66454)
vulnerability in arcade-mcp-server (CVE-2025-66454). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2025-12763 |
|
OS Command Injection in pgadmin4 (CVE-2025-12763)
OS command injection in pgadmin4 (CVE-2025-12763). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.10` or later.
|
| CVE-2021-4472 |
|
Vulnerability in python-mistralclient (CVE-2021-4472)
vulnerability in python-mistralclient (CVE-2021-4472). Confidential information can be exposed externally. Mitigation: upgrade to `4.3.0` or later.
|
| CVE-2025-64512 |
|
Unsafe Deserialization in pdfminer-six (CVE-2025-64512)
vulnerability in pdfminer-six (CVE-2025-64512). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `20251107` or later.
|
| CVE-2025-70559 |
|
Unsafe Deserialization in pdfminer-six (CVE-2025-70559)
vulnerability in pdfminer-six (CVE-2025-70559). Successful exploitation can lead to full system takeover. Exploitable via ``pickle``. Mitigation: upgrade to `20251230` or later.
|
| CVE-2025-64508 |
|
Vulnerability in bugsink (CVE-2025-64508)
vulnerability in bugsink (CVE-2025-64508). Risk of unauthorized operations or information disclosure. Exploitable via ``DSN``. Mitigation: upgrade to `2.0.5` or later.
|
| CVE-2025-64509 |
|
Vulnerability in bugsink (CVE-2025-64509)
vulnerability in bugsink (CVE-2025-64509). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.6` or later.
|
| CVE-2025-12765 |
|
Vulnerability in pgadmin4 (CVE-2025-12765)
vulnerability in pgadmin4 (CVE-2025-12765). Confidential information can be exposed externally. Mitigation: upgrade to `9.10` or later.
|
| CVE-2025-12764 |
|
Vulnerability in pgadmin4 (CVE-2025-12764)
vulnerability in pgadmin4 (CVE-2025-12764). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.10` or later.
|
| CVE-2025-66019 |
|
Vulnerability in pypdf (CVE-2025-66019)
vulnerability in pypdf (CVE-2025-66019). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.4.0` or later.
|
| CVE-2025-65106 |
|
Vulnerability in langchain-core (CVE-2025-65106)
vulnerability in langchain-core (CVE-2025-65106). Risk of unauthorized operations or information disclosure. Exploitable via ``ChatPromptTemplate``. Mitigation: upgrade to `0.3.80` or later.
|
| CVE-2025-62703 |
|
Unsafe Deserialization in fugue (CVE-2025-62703)
vulnerability in fugue (CVE-2025-62703). Successful exploitation can lead to full system takeover. Exploitable via ``Unpickler``.
|
| CVE-2025-65073 |
|
Authorization Flaw in keystone (CVE-2025-65073)
vulnerability in keystone (CVE-2025-65073). Data can be tampered with by attackers. Mitigation: upgrade to `28.0.0` or later.
|
| CVE-2025-64495 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2025-64495)
cross-site scripting in open-webui (CVE-2025-64495). Confidential information can be exposed externally. Exploitable via ``tempDiv.innerHTML``. Mitigation: upgrade to `0.6.35` or later.
|
| CVE-2025-50736 |
|
Open Redirect in pdf2zh (CVE-2025-50736)
vulnerability in pdf2zh (CVE-2025-50736). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-64496 |
|
Vulnerability in open-webui (CVE-2025-64496)
vulnerability in open-webui (CVE-2025-64496). Confidential information can be exposed externally. Exploitable via `POST /v1/chat/completions`. Mitigation: upgrade to `0.6.35` or later.
|
| CVE-2025-63675 |
|
Unsafe Deserialization in cryptidy (CVE-2025-63675)
vulnerability in cryptidy (CVE-2025-63675). Confidential information can be exposed externally.
|
| CVE-2025-64187 |
|
Cross-Site Scripting (XSS) in octoprint (CVE-2025-64187)
cross-site scripting in octoprint (CVE-2025-64187). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.11.4` or later.
|
| CVE-2025-58337 |
|
Vulnerability in doris-mcp-server (CVE-2025-58337)
vulnerability in doris-mcp-server (CVE-2025-58337). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2025-64184 |
|
Path Traversal in dosage (CVE-2025-64184)
path traversal in dosage (CVE-2025-64184). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.2` or later.
|
| CVE-2025-12695 |
|
Vulnerability in dspy (CVE-2025-12695)
vulnerability in dspy (CVE-2025-12695). Confidential information can be exposed externally.
|
| CVE-2025-64439 |
|
Unsafe Deserialization in langgraph-checkpoint (CVE-2025-64439)
vulnerability in langgraph-checkpoint (CVE-2025-64439). Risk of unauthorized operations or information disclosure. Exploitable via ``JsonPlusSerializer``. Mitigation: upgrade to `3.0.0` or later.
|
| CVE-2025-57698 |
|
Path Traversal in astrbot (CVE-2025-57698)
path traversal in astrbot (CVE-2025-57698). Risk of unauthorized operations or information disclosure. Exploitable via ``file.save``.
|
| CVE-2025-57697 |
|
Out-of-Bounds Read in astrbot (CVE-2025-57697)
vulnerability in astrbot (CVE-2025-57697). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-64168 |
|
Vulnerability in agno (CVE-2025-64168)
vulnerability in agno (CVE-2025-64168). Confidential information can be exposed externally. Exploitable via ``session_state``. Mitigation: upgrade to `2.2.2` or later.
|
| CVE-2025-64100 |
|
Vulnerability in ckan (CVE-2025-64100)
vulnerability in ckan (CVE-2025-64100). Confidential information can be exposed externally. Mitigation: upgrade to `2.11.4` or later.
|
| CVE-2025-54384 |
|
Cross-Site Scripting (XSS) in ckan (CVE-2025-54384)
cross-site scripting in ckan (CVE-2025-54384). Confidential information can be exposed externally. Mitigation: upgrade to `2.10.9` or later.
|
| CVE-2025-61385 |
|
SQL Injection in pg8000 (CVE-2025-61385)
SQL injection in pg8000 (CVE-2025-61385). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.31.5` or later.
|
| CVE-2025-62801 |
|
OS Command Injection in fastmcp (CVE-2025-62801)
OS command injection in fastmcp (CVE-2025-62801). Risk of unauthorized operations or information disclosure. Exploitable via ``n_dice``. Mitigation: upgrade to `2.13.0` or later.
|