CVE-2025-48475 – FreeScout Unrestricted Client Access Vulnerability

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the System does not provide a check on which “clients” of the System an authorized user can view and edit, and which ones they cannot. As a result, an authorized user who does not have access to any of the existing […]

CVE-2025-46722 – VLLM Image Hash Collision Vulnerability

vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before 0.9.0, in the file vllm/multimodal/hasher.py, the MultiModalHasher class has a security and data integrity issue in its image hashing method. Currently, it serializes PIL.Image.Image objects using only obj.tobytes(), which returns only the raw pixel data, without […]

CVE-2025-46570 – Apache vLLM PageAttention Chunk Prefill Timing Vulnerability

The following table lists the changes that have been made to the CVE-2025-46570 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 29, 2025 Action […]

CVE-2024-51392 – OpenKnowledgeMaps Headstart Remote Privilege Escalation

The following table lists the changes that have been made to the CVE-2024-51392 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0 May. 29, 2025 Action Type […]

CVE-2025-48473 – FreeScout Unauthenticated Message Access Vulnerability

The following table lists the changes that have been made to the CVE-2025-48473 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 29, 2025 Action […]

CVE-2025-48474 – FreeScout Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2025-48474 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 29, 2025 Action […]

CVE-2025-48472 – FreeScout Access Control Bypass

The following table lists the changes that have been made to the CVE-2025-48472 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 29, 2025 Action […]

CVE-2025-48471 – FreeScout Apache Remote Code Execution Vulnerability

The following table lists the changes that have been made to the CVE-2025-48471 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 29, 2025 Action […]

CVE-2025-48390 – FreeScout Remote Code Injection Vulnerability

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to code injection due to insufficient validation of user input in the php_path parameter. The backticks characters are not removed, as well as tabulation is not removed. When checking user input, the file_exists function is also called to […]

CVE-2025-48389 – FreeScout Deserialization Vulnerability (Arbitrary Code Execution)

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deserialization of untrusted data due to insufficient validation. Through the set function, a string with a serialized object can be passed, and when getting an option through the get method, deserialization will occur, which will allow arbitrary […]