Open Source Vulnerabilities
io.netty:netty-handler, io.netty:netty-handler
Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
io.netty:netty-handler/ io.netty:netty-handler
Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
io.netty:netty-handler, io.netty:netty-handler
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
io.netty:netty-handler/ io.netty:netty-handler
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
github.com/infracost/infracost
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname
github.com/infracost/infracost
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname
github.com/infracost/infracost
Infracost: Arbitrary file read via config-template readFile symlink traversal
github.com/infracost/infracost
Infracost: Arbitrary file read via config-template readFile symlink traversal
github.com/amir20/dozzle
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
github.com/amir20/dozzle
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
liquidjs
LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process
liquidjs
LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process
prowler, prowler-cloud
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
prowler/ prowler-cloud
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce | Incorrect Authorization (CWE-863)
csv-parse
node-csv: Prototype replacement still reachable via columns path
csv-parse
node-csv: Prototype replacement still reachable via columns path
@swc/html, swc_html_minifier
SWC HTML minifier may allow script element breakout when minifying embedded JSON
@swc/html/ swc_html_minifier
SWC HTML minifier may allow script element breakout when minifying embedded JSON
github.com/semaphoreui/semaphore
Semaphore U: OS Command Injection
github.com/semaphoreui/semaphore
Semaphore U: OS Command Injection
gitea.dev
Gitea: Remote Code Execution via diffpatch Git Hook Installation
gitea.dev
Gitea: Remote Code Execution via diffpatch Git Hook Installation
github.com/siyuan-note/siyuan/kernel
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked
github.com/siyuan-note/siyuan/kernel
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked
io.undertow:undertow-benchmarks, io.undertow:undertow-core, io.undertow:undertow-dist, io.undertow:undertow-examples, io.undertow:undertow-parent, io.undertow:undertow-parser-generator, io.undertow:undertow-servlet, io.undertow:undertow-websockets-jsr
TuxCare security update for io.undertow (1 CVE)
io.undertow:undertow-benchmarks/ io.undertow:undertow-core/ io.undertow:undertow-dist/ io.undertow:undertow-examples/ io.undertow:undertow-parent/ io.undertow:undertow-parser-generator/ io.undertow:undertow-servlet/ io.undertow:undertow-websockets-jsr
TuxCare security update for io.undertow (1 CVE)
github.com/siyuan-note/siyuan/kernel
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
github.com/siyuan-note/siyuan/kernel
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
github.com/siyuan-note/siyuan/kernel
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews
github.com/siyuan-note/siyuan/kernel
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash
aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash
InstantCMS vulnerable to SSRF via upload redirect bypass allows internal network service scanning
InstantCMS vulnerable to SSRF via upload redirect bypass allows internal network service scanning
mongodb, mongodb, mongodb, mongodb
mongodb, mongodb, mongodb, mongodb
mongodb, mongodb, mongodb, mongodb
mongodb, mongodb, mongodb, mongodb
mongodb, mongodb, mongodb, mongodb
mongodb, mongodb, mongodb, mongodb
mongodb, mongodb, mongodb, mongodb
mongodb, mongodb, mongodb, mongodb
mongodb, mongodb, mongodb, mongodb
mongodb, mongodb, mongodb, mongodb
mongodb, mongodb, mongodb, mongodb
mongodb, mongodb, mongodb, mongodb
mongodb, mongodb, mongodb, mongodb
