Open Source Vulnerabilities
esphome-device-builder
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
esphome-device-builder
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
functype-mcp-server
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
functype-mcp-server
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
github.com/candid82/joker
Joker linter executed project-local .jokerd/linter.* files during linting
github.com/candid82/joker
Joker linter executed project-local .jokerd/linter.* files during linting
github.com/komari-monitor/komari
Komari: Management Interface CSRF
github.com/komari-monitor/komari
Komari: Management Interface CSRF
@yeger/turbo-graph
@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run
@yeger/turbo-graph
@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run
nuxt-ollama
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
nuxt-ollama
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
github.com/ncarlier/webhookd
webhookd: Unrestricted HTTP Header to Shell Variable Injection
github.com/ncarlier/webhookd
webhookd: Unrestricted HTTP Header to Shell Variable Injection
org.geonetwork-opensource:gn-web-app, org.geonetwork-opensource:gn-web-app
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool
org.geonetwork-opensource:gn-web-app/ org.geonetwork-opensource:gn-web-app
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool
