Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-62800 |
|
Cross-Site Scripting (XSS) in fastmcp (CVE-2025-62800)
cross-site scripting in fastmcp (CVE-2025-62800). Risk of unauthorized operations or information disclosure. Exploitable via ``create_callback_html``. Mitigation: upgrade to `2.13.0` or later.
|
| CVE-2025-62707 |
|
Vulnerability in pypdf (CVE-2025-62707)
vulnerability in pypdf (CVE-2025-62707). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.1.3` or later.
|
| CVE-2025-62708 |
|
Vulnerability in pypdf (CVE-2025-62708)
vulnerability in pypdf (CVE-2025-62708). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.1.3` or later.
|
| CVE-2025-8709 |
|
SQL Injection in langgraph-checkpoint-sqlite (CVE-2025-8709)
SQL injection in langgraph-checkpoint-sqlite (CVE-2025-8709). Confidential information can be exposed externally. Mitigation: upgrade to `2.0.11` or later.
|
| CVE-2025-64104 |
|
SQL Injection in langgraph-checkpoint-sqlite (CVE-2025-64104)
SQL injection in langgraph-checkpoint-sqlite (CVE-2025-64104). Confidential information can be exposed externally. Exploitable via ``SqliteStore``. Mitigation: upgrade to `2.0.11` or later.
|
| CVE-2025-10282 |
|
Information Disclosure in bbot (CVE-2025-10282)
vulnerability in bbot (CVE-2025-10282). Risk of unauthorized operations or information disclosure. Exploitable via ``gitlab.py``. Mitigation: upgrade to `2.7.2` or later.
|
| CVE-2025-62611 |
|
Vulnerability in aiomysql (CVE-2025-62611)
vulnerability in aiomysql (CVE-2025-62611). Risk of unauthorized operations or information disclosure. Exploitable via ``config.yaml``. Mitigation: upgrade to `0.3.0` or later.
|
| CVE-2025-61773 |
|
Vulnerability in pyload-ng (CVE-2025-61773)
vulnerability in pyload-ng (CVE-2025-61773). Confidential information can be exposed externally. Exploitable via `GET /flash/addcrypted2`. Mitigation: upgrade to `0.5.0b3.dev91` or later.
|
| CVE-2025-11844 |
|
Vulnerability in smolagents (CVE-2025-11844)
vulnerability in smolagents (CVE-2025-11844). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.22.0` or later.
|
| CVE-2025-61911 |
|
Vulnerability in python-ldap (CVE-2025-61911)
vulnerability in python-ldap (CVE-2025-61911). Risk of unauthorized operations or information disclosure. Exploitable via ``ldap.filter.escape_filter_chars``. Mitigation: upgrade to `3.4.5` or later.
|
| CVE-2025-61912 |
|
Vulnerability in python-ldap (CVE-2025-61912)
vulnerability in python-ldap (CVE-2025-61912). Risk of unauthorized operations or information disclosure. Exploitable via ``add_s``. Mitigation: upgrade to `3.4.5` or later.
|
| CVE-2025-62172 |
|
Cross-Site Scripting (XSS) in homeassistant (CVE-2025-62172)
cross-site scripting in homeassistant (CVE-2025-62172). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2025.10.2` or later.
|
| CVE-2025-61783 |
|
Vulnerability in social-auth-app-django (CVE-2025-61783)
vulnerability in social-auth-app-django (CVE-2025-61783). Risk of unauthorized operations or information disclosure. Exploitable via ``associate_by_email``. Mitigation: upgrade to `5.6.0` or later.
|
| CVE-2025-62607 |
|
Vulnerability in nautobot-ssot (CVE-2025-62607)
vulnerability in nautobot-ssot (CVE-2025-62607). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2025-62379 |
|
Open Redirect in reflex (CVE-2025-62379)
vulnerability in reflex (CVE-2025-62379). Risk of unauthorized operations or information disclosure. Exploitable via ``GITHUB_CODESPACES_PORT_FORWARDING_DOMAIN``.
|
| CVE-2025-61672 |
|
Vulnerability in matrix-synapse (CVE-2025-61672)
vulnerability in matrix-synapse (CVE-2025-61672). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.139.1` or later.
|
| CVE-2025-7707 |
|
Vulnerability in llama-index (CVE-2025-7707)
vulnerability in llama-index (CVE-2025-7707). Data can be tampered with by attackers. Mitigation: upgrade to `0.13.0` or later.
|
| CVE-2025-61920 |
|
Vulnerability in authlib (CVE-2025-61920)
vulnerability in authlib (CVE-2025-61920). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.6.5` or later.
|
| CVE-2025-62706 |
|
Vulnerability in authlib (CVE-2025-62706)
vulnerability in authlib (CVE-2025-62706). Risk of unauthorized operations or information disclosure. Exploitable via ``DeflateZipAlgorithm.decompress``. Mitigation: upgrade to `1.6.5` or later.
|
| CVE-2025-11849 |
|
Path Traversal in mammoth (CVE-2025-11849)
path traversal in mammoth (CVE-2025-11849). Confidential information can be exposed externally. Mitigation: upgrade to `1.11.0` or later.
|
| CVE-2025-8406 |
|
Path Traversal in zenml (CVE-2025-8406)
path traversal in zenml (CVE-2025-8406). Successful exploitation can lead to full system takeover. Exploitable via ``PathMaterializer``. Mitigation: upgrade to `0.84.2` or later.
|
| CVE-2025-61765 |
|
Unsafe Deserialization in python-socketio (CVE-2025-61765)
vulnerability in python-socketio (CVE-2025-61765). Confidential information can be exposed externally. Exploitable via ``pickle``. Mitigation: upgrade to `5.14.0` or later.
|
| CVE-2025-57275 |
|
Buffer Overflow in spdk (CVE-2025-57275)
vulnerability in spdk (CVE-2025-57275). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `25.9` or later.
|
| CVE-2025-59940 |
|
Vulnerability in mkdocs-include-markdown-plugin (CVE-2025-59940)
vulnerability in mkdocs-include-markdown-plugin (CVE-2025-59940). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.1.8` or later.
|
| CVE-2025-61677 |
|
Unsafe Deserialization in datachain (CVE-2025-61677)
vulnerability in datachain (CVE-2025-61677). Risk of unauthorized operations or information disclosure. Exploitable via ``DATACHAIN__METASTORE``. Mitigation: upgrade to `0.34.2` or later.
|
| CVE-2025-59152 |
|
Vulnerability in litestar (CVE-2025-59152)
vulnerability in litestar (CVE-2025-59152). Risk of unauthorized operations or information disclosure. Exploitable via ``SECURE_PROXY_SSL_HEADER``. Mitigation: upgrade to `2.18.0` or later.
|
| CVE-2025-8917 |
|
Path Traversal in clearml (CVE-2025-8917)
path traversal in clearml (CVE-2025-8917). Confidential information can be exposed externally. Exploitable via ``safe_extract``. Mitigation: upgrade to `2.0.2` or later.
|
| CVE-2025-61620 |
|
Vulnerability in vllm (CVE-2025-61620)
vulnerability in vllm (CVE-2025-61620). Risk of unauthorized operations or information disclosure. Exploitable via ``chat_template``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2025-6242 |
|
Open Redirect in vllm (CVE-2025-6242)
vulnerability in vllm (CVE-2025-6242). Confidential information can be exposed externally. Exploitable via ``MediaConnector``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2025-53354 |
|
Cross-Site Scripting (XSS) in nicegui (CVE-2025-53354)
cross-site scripting in nicegui (CVE-2025-53354). Risk of unauthorized operations or information disclosure. Exploitable via ``ui.chat_message``. Mitigation: upgrade to `3.0.0` or later.
|
| CVE-2025-61784 |
|
Path Traversal in llamafactory (CVE-2025-61784)
path traversal in llamafactory (CVE-2025-61784). Confidential information can be exposed externally. Mitigation: upgrade to `0.9.4` or later.
|
| CVE-2025-6985 |
|
XXE (XML External Entity) in langchain-text-splitters (CVE-2025-6985)
vulnerability in langchain-text-splitters (CVE-2025-6985). Confidential information can be exposed externally. Mitigation: upgrade to `0.3.9` or later.
|
| CVE-2025-6051 |
|
Vulnerability in transformers (CVE-2025-6051)
vulnerability in transformers (CVE-2025-6051). Risk of unauthorized operations or information disclosure. Exploitable via ``EnglishNormalizer``. Mitigation: upgrade to `4.53.0` or later.
|
| CVE-2025-6921 |
|
Vulnerability in transformers (CVE-2025-6921)
vulnerability in transformers (CVE-2025-6921). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.53.0` or later.
|
| CVE-2025-8869 |
|
Vulnerability in pip (CVE-2025-8869)
vulnerability in pip (CVE-2025-8869). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `25.3` or later.
|
| CVE-2025-10952 |
|
Information Disclosure in ml-logger (CVE-2025-10952)
vulnerability in ml-logger (CVE-2025-10952). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-10951 |
|
Path Traversal in ml-logger (CVE-2025-10951)
path traversal in ml-logger (CVE-2025-10951). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-10950 |
|
Vulnerability in ml-logger (CVE-2025-10950)
vulnerability in ml-logger (CVE-2025-10950). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-59376 |
|
Command Injection in mcp-kubernetes-server (CVE-2025-59376)
command injection in mcp-kubernetes-server (CVE-2025-59376). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-55178 |
|
Vulnerability in llama-stack (CVE-2025-55178)
vulnerability in llama-stack (CVE-2025-55178). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.2.20` or later.
|
| CVE-2025-59420 |
|
Vulnerability in authlib (CVE-2025-59420)
vulnerability in authlib (CVE-2025-59420). Data can be tampered with by attackers. Exploitable via ``crit``. Mitigation: upgrade to `1.6.4` or later.
|
| CVE-2025-7647 |
|
Vulnerability in llama-index-core (CVE-2025-7647)
vulnerability in llama-index-core (CVE-2025-7647). Confidential information can be exposed externally. Mitigation: upgrade to `0.13.0` or later.
|
| CVE-2025-11059 |
|
Path Traversal in xml2rfc (CVE-2025-11059)
path traversal in xml2rfc (CVE-2025-11059). Risk of unauthorized operations or information disclosure. Exploitable via ``link``. Mitigation: upgrade to `3.30.2` or later.
|
| CVE-2025-6638 |
|
Vulnerability in transformers (CVE-2025-6638)
vulnerability in transformers (CVE-2025-6638). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.53.0` or later.
|
| CVE-2025-10164 |
|
Vulnerability in sglang (CVE-2025-10164)
vulnerability in sglang (CVE-2025-10164). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.5.4` or later.
|
| CVE-2025-59042 |
|
Code Injection in pyinstaller (CVE-2025-59042)
code injection in pyinstaller (CVE-2025-59042). Risk of unauthorized operations or information disclosure. Exploitable via ``sys.path``. Mitigation: upgrade to `6.0.0` or later.
|
| CVE-2025-59034 |
|
Vulnerability in indico (CVE-2025-59034)
vulnerability in indico (CVE-2025-59034). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.8` or later.
|
| CVE-2025-58065 |
|
Authentication Bypass in flask-appbuilder (CVE-2025-58065)
authentication bypass in flask-appbuilder (CVE-2025-58065). Data can be tampered with by attackers. Mitigation: upgrade to `4.8.1` or later.
|
| CVE-2025-58753 |
|
Vulnerability in copyparty (CVE-2025-58753)
vulnerability in copyparty (CVE-2025-58753). Risk of unauthorized operations or information disclosure. Exploitable via ``shr``. Mitigation: upgrade to `1.19.8` or later.
|
| CVE-2025-59035 |
|
Cross-Site Scripting (XSS) in indico (CVE-2025-59035)
cross-site scripting in indico (CVE-2025-59035). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.8` or later.
|