Open Source Vulnerabilities
github.com/siyuan-note/siyuan/kernel
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password in github.com/siyuan-note/siyuan/kernel
github.com/openchoreo/openchoreo
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation in github.com/openchoreo/openchoreo
github.com/openchoreo/openchoreo
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation in github.com/openchoreo/openchoreo
github.com/siyuan-note/siyuan/kernel
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo in github.com/siyuan-note/siyuan/kernel
code.gitea.io/gitea, gitea.dev
Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev
code.gitea.io/gitea/ gitea.dev
Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev
github.com/siyuan-note/siyuan/kernel
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked in github.com/siyuan-note/siyuan/kernel
github.com/semaphoreui/semaphore
Semaphore U: OS Command Injection in github.com/semaphoreui/semaphore
github.com/semaphoreui/semaphore
Semaphore U: OS Command Injection in github.com/semaphoreui/semaphore
github.com/infracost/infracost
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname in github.com/infracost/infracost
github.com/infracost/infracost
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname in github.com/infracost/infracost
github.com/infracost/infracost
Infracost: Arbitrary file read via config-template readFile symlink traversal in github.com/infracost/infracost
github.com/infracost/infracost
Infracost: Arbitrary file read via config-template readFile symlink traversal in github.com/infracost/infracost
github.com/amir20/dozzle
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher in github.com/amir20/dozzle
github.com/amir20/dozzle
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher in github.com/amir20/dozzle
Traefik HTTP/3 Backend NTLM Connection Reuse
AppFlowy-Cloud 0.7.2 through 0.9.64 Missing Workspace Authorization on Bulk Publish Endpoint
AppFlowy-Cloud 0.7.2 through 0.9.64 Missing Workspace Authorization on Bulk Publish Endpoint
Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String
Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
datadog-agent-7.76, datadog-agent-7.76
Type confusion in Zephyr HL78xx GNSS NMEA driver causes wild-pointer write from GNSS input
Type confusion in Zephyr HL78xx GNSS NMEA driver causes wild-pointer write from GNSS input
Traefik entrypoint header-name sanitization bypassed via request trailers
Traefik entrypoint header-name sanitization bypassed via request trailers
nodemailer
TuxCare security update for nodemailer (7 CVEs)
nodemailer
TuxCare security update for nodemailer (7 CVEs)
kube-arangodb-1.4, kube-arangodb-1.4
kubevela-vela-cli, kubevela-vela-cli
kubescape-operator, kubescape-operator
Suricata lua/tls: null dereference in TlsGetCertInfo
gatekeeper-3.21-gator, gatekeeper-3.21-gator
datadog-agent-7.79, datadog-agent-7.79
datadog-agent-7.79, datadog-agent-7.79
datadog-agent-7.79, datadog-agent-7.79
cluster-api-helm-controller, cluster-api-helm-controller
