Vulnerabilities (CVE)

Total 398254 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-29770 1 Vllm 1 Vllm 2026-06-17 N/A 6.5 MEDIUM
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. The outlines library is one of the backends used by vLLM to support structured output (a.k.a. guided decoding). Outlines provides an optional cache for its compiled grammars on the local filesystem. This cache has been on by default in vLLM. Outlines is also available by default through the OpenAI compatible API server. The affected code in vLLM is vllm/model_executor/guided_decoding/outlines_logits_processors.py, which unconditionally uses the cache from outlines. A malicious user can send a stream of very short decoding requests with unique schemas, resulting in an addition to the cache for each request. This can result in a Denial of Service if the filesystem runs out of space. Note that even if vLLM was configured to use a different backend by default, it is still possible to choose outlines on a per-request basis using the guided_decoding_backend key of the extra_body field of the request. This issue applies only to the V0 engine and is fixed in 0.8.0.
CVE-2025-29769 2 Debian, Libvips 2 Debian Linux, Libvips 2026-06-17 N/A 5.5 MEDIUM
libvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly determine the presence of an alpha channel in an input when it was not possible to determine the colour interpretation, known internally within libvips as "multiband". There aren't many ways to create a "multiband" input, but it is possible with a well-crafted TIFF image. If a "multiband" TIFF input image had 4 channels and HEIF-based output was requested, this led to libvips creating a 3 channel HEIF image without an alpha channel but then attempting to write 4 channels of data. This caused a heap buffer overflow, which could crash the process. This vulnerability is fixed in 8.16.1.
CVE-2025-29768 2 Netapp, Vim 3 Bootstrap Os, Hci Compute Node, Vim 2026-06-17 N/A 4.4 MEDIUM
Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filename. The issue has been fixed as of Vim patch v9.1.1198.
CVE-2025-29766 1 Enalean 1 Tuleap 2026-06-17 N/A 4.6 MEDIUM
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF protections on artifact submission & edition from the tracker view. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. The vulnerability is fixed in Tuleap Community Edition 16.5.99.1741784483 and Tuleap Enterprise Edition 16.5-3 and 16.4-8.
CVE-2025-29757 2026-06-17 N/A N/A
An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her account.
CVE-2025-29756 2026-06-17 N/A N/A
SunGrow's back end users system iSolarCloud https://isolarcloud.com  uses an MQTT service to transport data from the user's connected devices to the user's web browser.  The MQTT server however did not have sufficient restrictions in place to limit the topics that a user could subscribe to.  While the data that is transmitted through the MQTT server is encrypted and the credentials for the MQTT server are obtained though an API call, the credentials could be used to subscribe to any topic and the encryption key can be used to decrypt all messages received. An attack with an account on iSolarCloud.com could extract MQTT credentials and the decryption key from the browser and then use an external program to subscribe to the topic '#' and thus recieve all messages from all connected devices.
CVE-2025-29746 1 Benjaminjonard 1 Koillection 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Koillection v.1.6.10 allows a remote attacker to escalate privileges via the collection, Wishlist and album components
CVE-2025-29745 2026-06-17 N/A 7.5 HIGH
A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote server to obtain Net-NTLMv2 hash information via a specially created A2S (Emsisoft Custom Scan) extension file.
CVE-2025-29744 1 Vitaly-t 1 Pg-promise 2026-06-17 N/A 5.4 MEDIUM
pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers.
CVE-2025-29743 1 Dlink 2 Dir-816, Dir-816 Firmware 2026-06-17 N/A 6.5 MEDIUM
D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.
CVE-2025-29722 1 Yassmittal 1 Commercify 2026-06-17 N/A 6.3 MEDIUM
A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF protection on sensitive endpoints.
CVE-2025-29720 1 Langgenius 1 Dify 2026-06-17 N/A 4.8 MEDIUM
Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.
CVE-2025-29719 1 Remyandrade 1 Employee Management System 2026-06-17 N/A 6.1 MEDIUM
SourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via the First Name and Address text fields.
CVE-2025-29710 1 Torrahclef 1 Company Website Cms 2026-06-17 N/A 6.1 MEDIUM
SourceCodester Company Website CMS 1.0 is vulnerable to Cross Site Scripting (XSS) via /dashboard/Services.
CVE-2025-29709 1 Torrahclef 1 Company Website Cms 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the "Create portfolio" file /dashboard/portfolio.
CVE-2025-29708 1 Torrahclef 1 Company Website Cms 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Services.
CVE-2025-29705 1 Tanghc 1 Code-gen 2026-06-17 N/A 4.3 MEDIUM
code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone to access such projects.
CVE-2025-29699 1 Netsurf-browser 1 Netsurf 2026-06-17 N/A 6.5 MEDIUM
NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.
CVE-2025-29691 1 Hailey888 1 Oa System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the userName parameter at /login/LoginsController.java.
CVE-2025-29690 1 Hailey888 1 Oa System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the outtype parameter at /address/AddrController.java.