NA - CVE-2025-26486 - Use of a Broken or Risky Cryptographic...
Use of a Broken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash, Use of a One-Way Hash with a Predictable Salt vulnerability in...
NA - CVE-2025-29401 - An arbitrary file upload vulnerability in the...
An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via uploading a crafted PHP file.
NA - CVE-2025-29770 - vLLM is a high-throughput and memory-efficient...
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. The outlines library is one of the backends used by vLLM to support structured output (a.k.a. guided decoding)....
NA - CVE-2025-29783 - vLLM is a high-throughput and memory-efficient...
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Mooncake, unsafe deserialization exposed directly over ZMQ/TCP on all network...
NA - CVE-2025-30144 - fast-jwt provides fast JSON Web Token (JWT)...
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 5.0.6, the fast-jwt library does not properly validate the iss claim based on the RFC 7519. The iss (issuer) claim validation...
NA - CVE-2025-30152 - The Syliud PayPal Plugin is the Sylius Core...
The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. Prior to 1.6.2, 1.7.2, and 2.0.2, a discovered vulnerability allows users to modify their shopping cart...
NA - CVE-2025-30153 - kin-openapi is a Go project for handling...
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a...
NA - CVE-2025-30154 - reviewdog/action-setup is a GitHub action that...
reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps...