High - CVE-2025-7120 - A vulnerability was found in Campcodes...
A vulnerability was found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /users/check_availability.php....
Medium - CVE-2025-7121 - A vulnerability was found in Campcodes...
A vulnerability was found in Campcodes Complaint Management System 1.0. It has been classified as critical. This affects an unknown part of the file /users/complaint-details.php. The manipulation...
NA - CVE-2024-43334 - Improper Neutralization of Input During Web...
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gavias Halpes allows Reflected XSS.This issue affects Halpes: from n/a before 1.2.5.
NA - CVE-2025-3044 - A vulnerability in the ArxivReader class of the...
A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. This...
NA - CVE-2025-3046 - A vulnerability in the `ObsidianReader` class...
A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allows for arbitrary file read through symbolic links. The `ObsidianReader` fails...
NA - CVE-2025-3225 - An XML Entity Expansion vulnerability, also...
An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version...
NA - CVE-2025-3262 - A Regular Expression Denial of Service (ReDoS)...
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient...
NA - CVE-2025-3263 - A Regular Expression Denial of Service (ReDoS)...
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the...
NA - CVE-2025-3264 - A Regular Expression Denial of Service (ReDoS)...
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`....
NA - CVE-2025-3466 - langgenius/dify versions 1.1.0 to 1.1.2 are...
langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbitrary code with full root permissions. The vulnerability arises from the...