VU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check
Overview A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files …
آسیبپذیریها و تهدیدات روز با رتبهبندی CVSS و شدت — مستقیم از تیم تحلیل تهدیدات سیاره فناوری اطلاعات.
Overview A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files …
Overview Casdoor is an open-source Access Management (IAM) platform used to manage web applications. An authorization bypass vulnerability …
Overview A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). …
Overview An incorrect permissions assignment vulnerability in the amwrtdrv.sys kernel driver, included with AOMEI Backupper 8.4.0, allows an …
Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then …
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can …
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version …
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in …
Overview Firmware versions 2.7.7 and earlier of the Arris BGW210-700 residential gateway contain an authentication bypass vulnerability, tracked …
Overview A vulnerability has been discovered in the OPeNDAP Hyrax software solution. A remote attacker with the ability …