Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-63885 1 Aixblock 1 Aixblock 2025-10-31 6.1 Medium
A stored cross-site scripting (XSS) vulnerability in AIxBlock commit 04f305 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the model_desc field.
CVE-2025-60950 1 Aixblock 1 Aixblock 2025-10-31 6.1 Medium
An arbitrary file upload vulnerability in the Data Preparation function of AIxBlock commit f60975 allows attackers to execute arbitrary code via a crafted SVG file.