Security Advisories
open_in_newView CVE open_in_newView allA list of vulnerabilities (CVE / GHSA) publicly disclosed by Tencent Zhuque Lab.
bug_report
Vulnerabilities
69
deployed_code
Products
23
leaderboard
Severity Breakdown
-
open_in_newHigh CVE-2025-61784 CWE-22/CWE-918
LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities
deployed_code Affected: llamafactory <= 0.9.3 calendar_today Published: October 07, 2025 -
open_in_newHigh CVE-2025-6242 CWE-601/CWE-918
vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
deployed_code Affected: vllm >= 0.5.0, < 0.11.0 calendar_today Published: October 07, 2025 -
open_in_newHigh CVE-2025-23312 CWE‑94
NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component
deployed_code Affected: NVIDIA All versions prior to 2.4.0 calendar_today Published: August 29, 2025 -
open_in_newHigh CVE-2025-57801 CWE-347
gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks
deployed_code Affected: gnark < 0.14.0 calendar_today Published: August 22, 2025 -
open_in_newMedium CVE-2025-38524
rxrpc: Fix recv-recv race of completed call
deployed_code Affected: Linux / rxrpc >= 4.9, < 6.6.100; >= 4.9, < 6.12.40; >= 4.9, < 6.15.8; >= 4.9, < 6.16 calendar_today Published: August 16, 2025 -
open_in_newMedium CVE-2025-38525
rxrpc: Fix irq-disabled in local_bh_enable()
deployed_code Affected: Linux / rxrpc >= 6.14, < 6.15.8; >= 6.14, < 6.16 calendar_today Published: August 16, 2025 -
open_in_newMedium CVE-2025-38544
rxrpc: Fix bug due to prealloc collision
deployed_code Affected: Linux / rxrpc >= 4.9, < 6.6.99; >= 4.9, < 6.12.39; >= 4.9, < 6.15.7; >= 4.9, < 6.16 calendar_today Published: August 16, 2025 -
open_in_newMedium CVE-2025-38514
rxrpc: Fix oops due to non-existence of prealloc backlog struct
deployed_code Affected: Linux / rxrpc >= 4.9, < 5.4.296; >= 4.9, < 5.10.240; >= 4.9, < 5.15.189; >= 4.9, < 6.1.146; >= 4.9, < 6.6.99; >= 4.9, < 6.12.39; >= 4.9, < 6.15.7; >= 4.9, < 6.16 calendar_today Published: August 16, 2025 -
open_in_newMedium CVE-2025-48887 CWE-1333
vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`
deployed_code Affected: vllm >= 0.6.4, < 0.9.0 calendar_today Published: May 28, 2025 -
open_in_newMedium GHSA-j828-28rj-hfhp CWE-1333
vLLM vulnerable to Regular Expression Denial of Service
deployed_code Affected: vllm >= 0.6.3, < 0.9.0 calendar_today Published: May 28, 2025
Per page
