| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-48944 | vLLM Tool Schema allows DoS via Malformed pattern and type Fields | vllm-project | vllm | Medium | 6.5 | 2025-05-30 18:38:46 | Deep Dive |
| CVE-2025-48943 | vLLM allows clients to crash the openai server with invalid regex | vllm-project | vllm | Medium | 6.5 | 2025-05-30 18:36:02 | Deep Dive |
| CVE-2025-48942 | vLLM DOS: Remotely kill vllm over http with invalid JSON schema | vllm-project | vllm | Medium | 6.5 | 2025-05-30 18:33:40 | Deep Dive |
| CVE-2025-48887 | vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py` | vllm-project | vllm | Medium | 6.5 | 2025-05-30 17:36:17 | Deep Dive |
| CVE-2025-4985 | Stored Cross-site Scripting (XSS) vulnerability affecting Risk Management in Project Portfolio Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x | Dassault Systèmes | Project Portfolio Manager | High | 8.7 | 2025-05-30 14:19:28 | Deep Dive |
| CVE-2025-48491 | Project AI API Key Exposure in Source Code | aryan6673 | project-ai | - | - | 2025-05-30 03:38:54 | Deep Dive |
| CVE-2025-46722 | vLLM has a Weakness in MultiModalHasher Image Hashing Implementation | vllm-project | vllm | Medium | 4.2 | 2025-05-29 16:36:13 | Deep Dive |
| CVE-2025-46570 | vLLM’s Chunk-Based Prefix Caching Vulnerable to Potential Timing Side-Channel | vllm-project | vllm | Low | 2.6 | 2025-05-29 16:32:43 | Deep Dive |
| CVE-2025-5252 | PHPGurukul News Portal Project edit-subadmin.php sql injection | PHPGurukul | News Portal Project | High | 7.3 | 2025-05-27 17:31:06 | Deep Dive |
| CVE-2025-5251 | PHPGurukul News Portal Project edit-subcategory.php sql injection | PHPGurukul | News Portal Project | High | 7.3 | 2025-05-27 17:00:16 | Deep Dive |
| CVE-2025-5250 | PHPGurukul News Portal Project edit-category.php sql injection | PHPGurukul | News Portal Project | High | 7.3 | 2025-05-27 17:00:13 | Deep Dive |
| CVE-2025-5249 | PHPGurukul News Portal Project add-category.php sql injection | PHPGurukul | News Portal Project | High | 7.3 | 2025-05-27 16:31:05 | Deep Dive |
| CVE-2023-53154 | cJSON 缓冲区错误漏洞 | cJSON project | cJSON | Low | 2.9 | 2025-05-23 00:00:00 | Deep Dive |
| CVE-2025-48374 | zot logs secrets | project-zot | zot | - | - | 2025-05-22 20:43:14 | Deep Dive |
| CVE-2025-47277 | vLLM Allows Remote Code Execution via PyNcclPipe Communication Service | vllm-project | vllm | Critical | 9.8 | 2025-05-20 17:32:27 | Deep Dive |
| CVE-2025-4926 | PHPGurukul Car Rental Project post-avehical.php unrestricted upload | PHPGurukul | Car Rental Project | Medium | 4.7 | 2025-05-19 09:31:05 | Deep Dive |
| CVE-2025-4874 | PHPGurukul News Portal Project contactus.php sql injection | PHPGurukul | News Portal Project | High | 7.3 | 2025-05-18 12:00:10 | Deep Dive |
| CVE-2025-4837 | projectworlds Student Project Allocation System make_group_sql.php sql injection | projectworlds | Student Project Allocation System | High | 7.3 | 2025-05-17 20:31:05 | Deep Dive |
| CVE-2025-47889 | Jenkins plugin WSO2 Oauth 安全漏洞 | Jenkins Project | Jenkins WSO2 Oauth Plugin | - | - | 2025-05-14 20:35:58 | Deep Dive |
| CVE-2025-47888 | Jenkins plugin DingTalk 安全漏洞 | Jenkins Project | Jenkins DingTalk Plugin | - | - | 2025-05-14 20:35:57 | Deep Dive |