Open Source Vulnerabilities
rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory Prefix
rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory Prefix
UnoPim before 2.1.3 Missing Authorization on Integration Management Routes
UnoPim before 2.1.3 Missing Authorization on Integration Management Routes
python-jose through 3.5.0 Algorithm Confusion via DER-encoded Public Key as HMAC Secret
python-jose through 3.5.0 Algorithm Confusion via DER-encoded Public Key as HMAC Secret
node-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestAlgorithm Padding
node-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestAlgorithm Padding
Peppermint through 0.5.5 Authorization Bypass on the User Logout Endpoint
Peppermint through 0.5.5 Authorization Bypass on the User Logout Endpoint
Peppermint through 0.5.5 Use of Hard-coded JWT Signing Secret in docker-compose.yml
Peppermint through 0.5.5 Use of Hard-coded JWT Signing Secret in docker-compose.yml
Checkmate through 3.11.0 Missing Authorization on Maintenance Window, Notification, and Check Deletion Routes
Checkmate through 3.11.0 Missing Authorization on Maintenance Window, Notification, and Check Deletion Routes
Worklenz before 3.0.0 Authorization Bypass on Task-Scoped Endpoints
Worklenz before 3.0.0 Authorization Bypass on Task-Scoped Endpoints
Worklenz through 3.0.0 SQL Injection via the sort-field Query Parameter
Worklenz through 3.0.0 SQL Injection via the sort-field Query Parameter
c-ares : Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP
c-ares : Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP
crossplane-2.1-crank, crossplane-2.1-crank
crossplane-2.1-crank, crossplane-2.1-crank
orval
Orval: Import-time RCE via array-items default -> zod module-level template literal
orval
Orval: Import-time RCE via array-items default -> zod module-level template literal
knative-kafka-broker-fips-1.23-controller
knative-kafka-broker-fips-1.23-controller
kyverno-background-controller-1.16, kyverno-background-controller-1.16
kyverno-background-controller-1.16/ kyverno-background-controller-1.16
kyverno-background-controller-1.16, kyverno-background-controller-1.16
kyverno-background-controller-1.16/ kyverno-background-controller-1.16
,
Incorrect Authorization in Kibana Leading to Privilege Escalation
/
Incorrect Authorization in Kibana Leading to Privilege Escalation
kyverno-cleanup-controller-1.16, kyverno-cleanup-controller-1.16
kyverno-cleanup-controller-1.16/ kyverno-cleanup-controller-1.16
kyverno-cleanup-controller-1.16, kyverno-cleanup-controller-1.16
kyverno-cleanup-controller-1.16/ kyverno-cleanup-controller-1.16
orval
Orval: Import-time RCE via header-parameter default -> zod module-level template literal
orval
Orval: Import-time RCE via header-parameter default -> zod module-level template literal
orval
Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator
orval
Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator
orval
Orval: Import-time RCE via enum-typed default -> zod module-level template literal
orval
Orval: Import-time RCE via enum-typed default -> zod module-level template literal
kyverno-reports-controller-1.16, kyverno-reports-controller-1.16
kyverno-reports-controller-1.16/ kyverno-reports-controller-1.16
crossplane-2.1-crank, crossplane-2.1-crank
