CVE-2025-34036 | CRITICAL | 10.0 | 0.26421 | 49.25 | No | No | 2025-06-24 | 2026-04-07 | euvd | An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Se…An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Server" that listens on TCP ports 81 and 82. The web interface fails to sanitize input in the URI path passed to the language extraction functionality. When the server processes a request to /language/[lang]/index.html, it uses the [lang] input unsafely in a tar extraction command without proper escaping. This allows an unauthenticated remote attacker to inject shell commands and achieve arbitrary command execution as root. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC. |
CVE-2024-8353 | CRITICAL | 9.8 | 0.2872 | 49.25 | No | No | 2024-09-28 | 2026-04-08 | euvd | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and …The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and 'card_address'. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files and achieve remote code execution. This is essentially the same vulnerability as CVE-2024-5932, however, it was discovered the the presence of stripslashes_deep on user_info allows the is_serialized check to be bypassed. This issue was mostly patched in 3.16.1, but further hardening was added in 3.16.2. |
CVE-2022-23277 | HIGH | 8.8 | 0.40028 | 49.21 | No | No | 2022-03-09 | 2025-07-08 | euvd | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability |
CVE-2024-0132 | CRITICAL | 9.0 | 0.37749 | 49.21 | No | No | 2024-09-26 | 2024-09-27 | euvd | NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration …NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
CVE-2024-38819 | HIGH | 7.5 | 0.54862 | 49.2 | No | No | 2024-12-19 | 2025-01-10 | euvd | Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks…Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running. |
CVE-2021-4191 | MEDIUM | 5.3 | 0.80004 | 49.2 | No | No | 2022-03-28 | 2024-08-03 | euvd | An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances…An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API. |
CVE-2025-43562 | CRITICAL | 9.1 | 0.36537 | 49.19 | No | No | 2025-05-13 | 2026-02-26 | euvd | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Comman…ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed. |
CVE-2022-37155 | HIGH | 8.8 | 0.39966 | 49.19 | No | No | 2022-12-13 | 2025-04-22 | euvd | RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter. |
CVE-2025-21285 | HIGH | 7.5 | 0.54838 | 49.19 | No | No | 2025-01-14 | 2026-06-09 | euvd | Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityMicrosoft Message Queuing (MSMQ) Denial of Service Vulnerability |
CVE-2024-10443 | CRITICAL | 9.8 | 0.2838 | 49.13 | No | No | 2024-11-15 | 2025-09-16 | euvd | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synolo…Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors. |
CVE-2023-39469 | HIGH | 7.2 | 0.5809 | 49.13 | No | No | 2024-05-03 | 2024-08-02 | euvd | PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a…PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability.
The specific flaw exists within the External User Lookup functionality. The issue results from the lack of proper validation of a user-supplied string before using it to execute Java code. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-21013. |
CVE-2025-29085 | CRITICAL | 9.8 | 0.28338 | 49.12 | No | No | 2025-04-02 | 2025-04-03 | euvd | SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/e…SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component. |
CVE-2024-3429 | CRITICAL | 9.8 | 0.28317 | 49.11 | No | No | 2024-06-06 | 2024-08-01 | euvd | A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitiz…A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` functions in `lollms_core\lollms\security.py`. This vulnerability allows for arbitrary file reading when the application is running on Windows. The issue arises due to insufficient sanitization of user-supplied input, enabling attackers to bypass the path traversal protection mechanisms by crafting malicious input. Successful exploitation could lead to unauthorized access to sensitive files, information disclosure, and potentially a denial of service (DoS) condition by including numerous large or resource-intensive files. This vulnerability affects the latest version prior to 9.6. |
CVE-2021-28635 | HIGH | 7.8 | 0.51184 | 49.11 | No | No | 2021-08-20 | 2024-09-16 | euvd | Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a use…Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a use-after-free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
CVE-2024-4323 | CRITICAL | 9.8 | 0.28309 | 49.11 | No | No | 2024-05-20 | 2024-08-19 | euvd | A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace re…A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution. |
CVE-2023-31222 | CRITICAL | 9.8 | 0.28287 | 49.1 | No | No | 2023-06-29 | 2024-11-26 | euvd | Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows …Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact a healthcare delivery organization’s Paceart Optima system cardiac device causing data to be deleted, stolen, or modified, or the Paceart Optima system being used for further network penetration via network connectivity. |
CVE-2024-24116 | CRITICAL | 9.8 | 0.28214 | 49.07 | No | No | 2024-10-02 | 2025-02-10 | euvd | An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm. |
CVE-2018-15957 | CRITICAL | 9.8 | 0.28211 | 49.07 | No | No | 2018-09-25 | 2025-05-06 | euvd | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untru…Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution. |
CVE-2019-12630 | MEDIUM | 6.5 | 0.65846 | 49.05 | No | No | 2019-10-02 | 2024-11-19 | euvd | A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execu…A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to a specific listener on an affected system. A successful exploit could allow the attacker to execute arbitrary commands on the device with the privileges of casuser. |
CVE-2024-0507 | MEDIUM | 6.5 | 0.658 | 49.03 | No | No | 2024-01-16 | 2024-10-22 | euvd | An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vuln…An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3, 3.10.5, 3.9.8, and 3.8.13 This vulnerability was reported via the GitHub Bug Bounty program. |
CVE-2023-38146 | HIGH | 8.8 | 0.39491 | 49.02 | No | No | 2023-09-12 | 2025-10-30 | euvd | Windows Themes Remote Code Execution VulnerabilityWindows Themes Remote Code Execution Vulnerability |
CVE-2025-27364 | CRITICAL | 10.0 | 0.25717 | 49.0 | No | No | 2025-02-24 | 2025-02-24 | euvd | In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant…In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remote attackers to execute arbitrary code on the server that Caldera is running on via a crafted web request to the Caldera server API used for compiling and downloading of Caldera's Sandcat or Manx agent (implants). This web request can use the gcc -extldflags linker flag with sub-commands. |
CVE-2024-1874 | CRITICAL | 9.4 | 0.32568 | 49.0 | No | No | 2024-04-29 | 2025-11-04 | euvd | In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insuf…In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell. |
CVE-2023-52755 | CRITICAL | 9.8 | 0.27928 | 48.97 | No | No | 2024-05-21 | 2026-08-05 | euvd, nvd | In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix slab out of bounds write in smb_inherit_dacl()
slab out-of-…In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix slab out of bounds write in smb_inherit_dacl()
slab out-of-bounds write is caused by that offsets is bigger than pntsd
allocation size. This patch add the check to validate 3 offsets using
allocation size. |
CVE-2021-39840 | HIGH | 7.8 | 0.50626 | 48.92 | No | No | 2021-09-29 | 2024-09-16 | euvd | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use…Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForms that could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. |
CVE-2026-27760 | CRITICAL | 9.2 | 0.34629 | 48.92 | No | Yes | 2026-04-28 | 2026-07-14 | euvd, packetstorm | OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated atta…OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string context in config.php using a single quote and statement separator to inject malicious PHP code that persists and executes on every subsequent page load when the installation wizard remains incomplete. |
CVE-2022-47878 | CRITICAL | 9.1 | 0.35716 | 48.9 | No | No | 2023-05-02 | 2025-11-06 | euvd | Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify…Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Consecutive file uploads can lead to the execution of arbitrary code. NOTE: The vendor states that the vulnerability affects installations running version 22.2 or earlier. The issue was resolved with the version 22.3 and later versions are not affected. Additionally, the vendor states that this vulnerability affects on-premises deployments only and that it does not impact cloud-hosted or SaaS environments. |
CVE-2025-22954 | CRITICAL | 10.0 | 0.25348 | 48.87 | No | No | 2025-03-12 | 2025-03-18 | euvd | GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or …GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid parameter. |
CVE-2025-34509 | HIGH | 7.5 | 0.53893 | 48.86 | No | No | 2025-06-17 | 2026-02-26 | euvd | Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 …Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP. |
CVE-2021-28165 | HIGH | 7.5 | 0.53861 | 48.85 | No | No | 2021-04-01 | 2025-08-27 | euvd | In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large inva…In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. |
CVE-2023-4415 | HIGH | 7.3 | 0.56147 | 48.85 | No | No | 2023-08-18 | 2024-08-02 | euvd | A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown function…A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The manipulation leads to improper authentication. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-237518 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. |
CVE-2026-49160 | HIGH | 7.5 | 0.53829 | 48.84 | No | Yes | 2026-06-09 | 2026-07-28 | euvd, nvd, packetstorm | Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network. |
CVE-2011-4723 | MEDIUM | 5.7 | 0.02981 | 48.84 | Yes | No | 2011-12-20 | 2025-10-22 | cisa.gov, euvd | The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecifi…The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors. |
CVE-2021-21029 | MEDIUM | 4.8 | 0.84674 | 48.84 | No | No | 2021-02-11 | 2024-09-16 | euvd | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulner…Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Access to the admin console is required for successful exploitation. |
CVE-2023-21690 | CRITICAL | 9.8 | 0.27533 | 48.84 | No | No | 2023-02-14 | 2025-01-01 | euvd | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution VulnerabilityMicrosoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability |
CVE-2023-30591 | HIGH | 7.5 | 0.53804 | 48.83 | No | No | 2023-09-29 | 2024-09-23 | euvd | Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `event…Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name respectively. |
CVE-2019-1622 | MEDIUM | 5.3 | 0.78858 | 48.8 | No | No | 2019-06-27 | 2024-11-19 | euvd | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote att…A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerability is due to improper access controls for certain URLs on affected DCNM software. An attacker could exploit this vulnerability by connecting to the web-based management interface of an affected device and requesting specific URLs. A successful exploit could allow the attacker to download log files and diagnostic information from the affected device. |
CVE-2024-5765 | CRITICAL | 9.8 | 0.27434 | 48.8 | No | No | 2024-07-30 | 2024-08-01 | euvd | The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an …The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection |
CVE-2021-3407 | HIGH | 7.8 | 0.50234 | 48.78 | No | No | 2021-02-23 | 2025-02-13 | euvd | A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences. |
CVE-2021-33548 | HIGH | 7.2 | 0.5705 | 48.77 | No | No | 2021-09-13 | 2024-09-16 | euvd | Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to …Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code. |
CVE-2021-33554 | HIGH | 7.2 | 0.5705 | 48.77 | No | No | 2021-09-13 | 2024-09-17 | euvd | Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to …Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code. |
CVE-2021-33550 | HIGH | 7.2 | 0.5705 | 48.77 | No | No | 2021-09-13 | 2024-09-17 | euvd | Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to …Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code. |
CVE-2026-20805 | MEDIUM | 5.5 | 0.05028 | 48.76 | Yes | No | 2026-01-13 | 2026-01-13 | cisa.gov, euvd, nvd | Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose in…Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally. |
CVE-2023-1578 | MEDIUM | 6.7 | 0.62755 | 48.76 | No | No | 2023-03-22 | 2025-02-25 | euvd | SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19. |
CVE-2023-36177 | CRITICAL | 9.8 | 0.2732 | 48.76 | No | No | 2024-01-23 | 2026-07-09 | euvd | An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information …An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information via crafted request in JSON-RPC-API. |
CVE-2024-34359 | CRITICAL | 9.7 | 0.2842 | 48.75 | No | No | 2024-05-10 | 2024-08-02 | euvd | llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp o…llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and running of the model. Other than `NUMA, LoRa settings`, `loading tokenizers,` and `hardware settings`, `__init__` also loads the `chat template` from targeted `.gguf` 's Metadata and furtherly parses it to `llama_chat_format.Jinja2ChatFormatter.to_chat_handler()` to construct the `self.chat_handler` for this model. Nevertheless, `Jinja2ChatFormatter` parse the `chat template` within the Metadate with sandbox-less `jinja2.Environment`, which is furthermore rendered in `__call__` to construct the `prompt` of interaction. This allows `jinja2` Server Side Template Injection which leads to remote code execution by a carefully constructed payload. |
CVE-2025-13315 | CRITICAL | 9.3 | 0.32941 | 48.73 | No | No | 2025-11-19 | 2025-11-19 | euvd | Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API aut…Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password. |
CVE-2023-39456 | HIGH | 7.5 | 0.53477 | 48.72 | No | No | 2023-10-17 | 2025-06-12 | euvd | Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from…Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2.
Users are recommended to upgrade to version 9.2.3, which fixes the issue. |
CVE-2020-2882 | HIGH | 8.1 | 0.4654 | 48.69 | No | No | 2020-04-15 | 2024-09-27 | euvd | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that a…Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle Human Resources accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). |
CVE-2012-5863 | CRITICAL | 10.0 | 0.24823 | 48.69 | No | No | 2012-11-23 | 2025-07-08 | euvd | These Sinapsi devices do not check for special elements in commands sent
to the system. By accessing certain pages with administrative priv…These Sinapsi devices do not check for special elements in commands sent
to the system. By accessing certain pages with administrative privileges
that do not require authentication within the device, attackers can
execute arbitrary, unexpected, or dangerous commands directly onto the
operating system. |