π¨ CVE-2025-27770
UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/create_project` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user that has access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain, which in most cases will be the docker container as suggested by the documentation. As of time of publication, no known patch is available.
π@cveNotify
UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/create_project` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user that has access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain, which in most cases will be the docker container as suggested by the documentation. As of time of publication, no known patch is available.
π@cveNotify
GitHub
uptrain/uptrain/dashboard/backend/app.py at a31cc14eddcb6c0b0b12cbed15f086d98c441c6f Β· uptrain-ai/uptrain
UpTrain is an open-source unified platform to evaluate and improve Generative AI applications. We provide grades for 20+ preconfigured checks (covering language, code, embedding use-cases), perform...
π¨ CVE-2025-27771
UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/add_prompts` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user that has access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain, which in most cases will be the docker container as suggested by the documentation. As of time of publication, no known patch is available.
π@cveNotify
UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/add_prompts` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user that has access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain, which in most cases will be the docker container as suggested by the documentation. As of time of publication, no known patch is available.
π@cveNotify
GitHub
uptrain/uptrain/dashboard/backend/app.py at a31cc14eddcb6c0b0b12cbed15f086d98c441c6f Β· uptrain-ai/uptrain
UpTrain is an open-source unified platform to evaluate and improve Generative AI applications. We provide grades for 20+ preconfigured checks (covering language, code, embedding use-cases), perform...
π¨ CVE-2025-27772
UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/new_run` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user that has access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain, which in most cases will be the docker container as suggested by the documentation. As of time of publication, no known patch is available.
π@cveNotify
UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/new_run` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user that has access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain, which in most cases will be the docker container as suggested by the documentation. As of time of publication, no known patch is available.
π@cveNotify
GitHub
uptrain/uptrain/dashboard/backend/app.py at a31cc14eddcb6c0b0b12cbed15f086d98c441c6f Β· uptrain-ai/uptrain
UpTrain is an open-source unified platform to evaluate and improve Generative AI applications. We provide grades for 20+ preconfigured checks (covering language, code, embedding use-cases), perform...
π¨ CVE-2025-9210
Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via tampering with JWTs
π@cveNotify
Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via tampering with JWTs
π@cveNotify
GitHub
Vulnerability-Disclosures/2026/MNDT-2026-0023.md at master Β· mandiant/Vulnerability-Disclosures
Contribute to mandiant/Vulnerability-Disclosures development by creating an account on GitHub.
π¨ CVE-2025-9211
Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site scripting
π@cveNotify
Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site scripting
π@cveNotify
GitHub
Vulnerability-Disclosures/2026/MNDT-2026-0024.md at master Β· mandiant/Vulnerability-Disclosures
Contribute to mandiant/Vulnerability-Disclosures development by creating an account on GitHub.
π¨ CVE-2025-11729
The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the can_access function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Contributor-level access and above, to retrieve a master-password and access any password-protected content.
π@cveNotify
The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the can_access function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Contributor-level access and above, to retrieve a master-password and access any password-protected content.
π@cveNotify
π¨ CVE-2025-14600
An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access. By manipulating application configuration data, an attacker can force the system to authenticate against an arbitrary LDAP server and provision a new administrative account.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.
π@cveNotify
An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access. By manipulating application configuration data, an attacker can force the system to authenticate against an arbitrary LDAP server and provision a new administrative account.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.
π@cveNotify
GitHub
Advisories/KLSA-00296-Admin-Account-Takeover-via-Path-Traversal-in-vsDesk.md at master Β· klsecservices/Advisories
Contribute to klsecservices/Advisories development by creating an account on GitHub.
π¨ CVE-2025-14603
The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
π@cveNotify
The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
π@cveNotify
GitHub
Advisories/KLSA-00295-Blind-SQLi-via-User-Input-in-vsDesk.md at master Β· klsecservices/Advisories
Contribute to klsecservices/Advisories development by creating an account on GitHub.
π¨ CVE-2025-36254
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authentication due to improperly encoding of DSCLI command output to obtain sensitive information or cause a denial of service.
π@cveNotify
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authentication due to improperly encoding of DSCLI command output to obtain sensitive information or cause a denial of service.
π@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities have been identified with the DS8900F and DS8A00 Hardware Management Console (HMC)
DS8900F and DS8A00 updates have been released to remediate vulnerabilities in various components like IBM Java Quarterly Update, IBM WebSphere Application Server, IBM Power HMC, Linux Kernel, OpenSSL, libsoup, libssh, OpenSSH, net-snmp, Apache HTTP Serverβ¦
π¨ CVE-2025-36398
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename.
π@cveNotify
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename.
π@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities have been identified with the DS8900F and DS8A00 Hardware Management Console (HMC)
DS8900F and DS8A00 updates have been released to remediate vulnerabilities in various components like IBM Java Quarterly Update, IBM WebSphere Application Server, IBM Power HMC, Linux Kernel, OpenSSL, libsoup, libssh, OpenSSH, net-snmp, Apache HTTP Serverβ¦
π¨ CVE-2025-14602
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
π@cveNotify
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
π@cveNotify
GitHub
Advisories/KLSA-00294-Weak-File-Name-Generation-in-vsDesk.md at master Β· klsecservices/Advisories
Contribute to klsecservices/Advisories development by creating an account on GitHub.
π¨ CVE-2025-14601
An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to insufficient input filtering. An attacker can exploit this flaw to disrupt web server operations, expose sensitive data, or potentially achieve full server compromise.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
π@cveNotify
An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to insufficient input filtering. An attacker can exploit this flaw to disrupt web server operations, expose sensitive data, or potentially achieve full server compromise.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
π@cveNotify
GitHub
Advisories/KLSA-00343-vsDesk-Task-Scheduler-OS-Command-Injection.md at master Β· klsecservices/Advisories
Contribute to klsecservices/Advisories development by creating an account on GitHub.
π¨ CVE-2025-62307
HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing.
π@cveNotify
HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing.
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL IntelliOps Event Management (IEM) - Customer Support
HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
π¨ CVE-2025-62299
HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges.
π@cveNotify
HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges.
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL IntelliOps Event Management (IEM) - Customer Support
HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
π¨ CVE-2025-62300
HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior.
π@cveNotify
HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior.
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL IntelliOps Event Management (IEM) - Customer Support
HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
π¨ CVE-2025-62306
HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response.
π@cveNotify
HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response.
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL IntelliOps Event Management (IEM) - Customer Support
HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
π¨ CVE-2025-52182
The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability.
π@cveNotify
The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability.
π@cveNotify
Gist
CVE-2025-52182
GitHub Gist: instantly share code, notes, and snippets.