CVE-2025-1628 – CVE-2016-0728: Apache Struts Remote Code Execution Vulnerability
The following table lists the changes that have been made to the CVE-2025-1628 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Rejected by [email protected] Mar. 19, 2025 Action Type […]
CVE-2025-30092 – Intrexx Portal Server Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-30092 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2025-27786 – Applio File Deletion Vulnerability (Arbitrary File Removal)
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file removal in core.py. `output_tts_path` in tts.py takes arbitrary user input and passes it to `run_tts_script` function in core.py, which checks if the path in `output_tts_path` exists, and if yes, removes that path, which leads to arbitrary file removal. As of […]
CVE-2025-27785 – Applio Voice Conversion Tool Arbitrary File Read Vulnerability
The following table lists the changes that have been made to the CVE-2025-27785 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2025-27784 – Applio Voice Conversion Tool File Read Vulnerability
The following table lists the changes that have been made to the CVE-2025-27784 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2025-27783 – Applio Voice Conversion Tool Remote Code Execution and Arbitrary File Write Vulnerability
The following table lists the changes that have been made to the CVE-2025-27783 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2025-27782 – Applio Voice Conversion Tool Arbitrary File Write and RCE Vulnerability
The following table lists the changes that have been made to the CVE-2025-27782 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2025-27781 – Applio Remote Code Execution Vulnerability
The following table lists the changes that have been made to the CVE-2025-27781 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2025-27787 – Applio Path Traversal and Denial of Service Vulnerability
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to denial of service (DoS) in restart.py. `model_name` in train.py takes user input, and passes it to the `stop_train` function in restart.py, which uses it construct a path to a folder with `config.json`. That `config.json` is opened and the list of values under […]
CVE-2025-27776 – Applio Voice Conversion Tool SSRF and File Write Vulnerability
Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py` (line 240 in 3.2.7). The blind SSRF allows for sending requests on behalf of Applio server and can be leveraged to probe for other vulnerabilities on the server itself or on other back-end […]