Vulnerabilities
Vulnerable Software
Security Vulnerabilities
vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving multimodal models by passing multimodal embedding inputs with correct ndim but incorrect shape (e.g. hidden dimension is wrong), regardless of whether the model is intended to support such inputs (as defined in the Supported Models page). This issue has been patched in version 0.11.1.
CVSS Score
6.5
EPSS Score
0.0
Published
2025-11-21
vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, the /v1/chat/completions and /tokenize endpoints allow a chat_template_kwargs request parameter that is used in the code before it is properly validated against the chat template. With the right chat_template_kwargs parameters, it is possible to block processing of the API server for long periods of time, delaying all other requests. This issue has been patched in version 0.11.1.
CVSS Score
6.5
EPSS Score
0.001
Published
2025-11-21
Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system. This issue has been patched in version 2.0.31.
CVSS Score
9.8
EPSS Score
0.001
Published
2025-11-21
A security flaw has been discovered in itsourcecode Online File Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be exploited.
CVSS Score
7.3
EPSS Score
0.0
Published
2025-11-21
Microsoft Defender Portal Spoofing Vulnerability
CVSS Score
8.3
EPSS Score
0.001
Published
2025-11-20
Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
8.8
EPSS Score
0.001
Published
2025-11-20
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.
CVSS Score
8.0
EPSS Score
0.001
Published
2025-11-20
Azure Monitor Elevation of Privilege Vulnerability
CVSS Score
8.6
EPSS Score
0.001
Published
2025-11-20
Microsoft SharePoint Online Elevation of Privilege Vulnerability
CVSS Score
9.8
EPSS Score
0.005
Published
2025-11-20
IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration allow an authenticated user to execute arbitrary code on the system, caused by the deserialization of untrusted object graphs data.
CVSS Score
8.8
EPSS Score
0.004
Published
2025-11-20


Contact Us

Shodan ® - All rights reserved