NA - CVE-2025-3262 - A Regular Expression Denial of Service (ReDoS)...
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient...
NA - CVE-2025-3263 - A Regular Expression Denial of Service (ReDoS)...
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the...
NA - CVE-2025-3264 - A Regular Expression Denial of Service (ReDoS)...
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`....
NA - CVE-2025-3466 - langgenius/dify versions 1.1.0 to 1.1.2 are...
langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbitrary code with full root permissions. The vulnerability arises from the...
NA - CVE-2025-3467 - An XSS vulnerability exists in langgenius/dify...
An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vulnerability allows an attacker to obtain the administrator's token by...
Critical - CVE-2025-3626 - A remote attacker with administrator account...
A remote attacker with administrator account can gain full control of the device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') while...
Medium - CVE-2025-3705 - A physical attacker with no privileges can gain...
A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') when...
NA - CVE-2025-3777 - Hugging Face Transformers versions up to 4.49.0...
Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using...
NA - CVE-2025-4779 - lunary-ai/lunary versions prior to 1.9.24 are...
lunary-ai/lunary versions prior to 1.9.24 are vulnerable to stored cross-site scripting (XSS). An unauthenticated attacker can inject malicious JavaScript into the `v1/runs/ingest` endpoint by...
NA - CVE-2025-5472 - The JSONReader in run-llama/llama_index...
The JSONReader in run-llama/llama_index versions 0.12.28 is vulnerable to a stack overflow due to uncontrolled recursive JSON parsing. This vulnerability allows attackers to trigger a Denial of...