NA - CVE-2025-3933 - A Regular Expression Denial of Service (ReDoS)...
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This...
NA - CVE-2025-50121 - CWE-78: Improper Neutralization of Special...
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause unauthenticated remote code execution when a...
NA - CVE-2025-50122 - CWE-331: Insufficient Entropy vulnerability...
CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when the password generation algorithm is reverse engineered with access to installation or upgrade...
NA - CVE-2025-50123 - CWE-94: Improper Control of Generation of Code...
CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote command execution by a privileged account when the server is accessed via a...
NA - CVE-2025-50124 - CWE-269: Improper Privilege Management...
CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation when the server is accessed by a privileged account via a console and through exploitation of a...
NA - CVE-2025-50125 - CWE-918: Server-Side Request Forgery (SSRF)...
CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the server is accessed via the network with knowledge of hidden URLs and...
NA - CVE-2025-6788 - CWE-668: Exposure of Resource to Wrong Sphere...
CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong control sphere, providing other authenticated users with potentially...
Low - CVE-2025-53861 - A flaw was found in Ansible. Sensitive cookies...
A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to...
Low - CVE-2025-53862 - A flaw was found in Ansible. Three API...
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.
NA - CVE-2025-51591 - A Server-Side Request Forgery (SSRF) in JGM...
A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe.