Open Source Vulnerabilities
astro
Astro's `X-Forwarded-Host` is reflected without validation
astro
Astro's `X-Forwarded-Host` is reflected without validation
kernel-livepatch-SLE15-SP4_Update_34
Security update for the Linux Kernel (Live Patch 34 for SLE 15 SP4)
kernel-livepatch-SLE15-SP4_Update_34
Security update for the Linux Kernel (Live Patch 34 for SLE 15 SP4)
wireshark, wireshark, wireshark
wireshark
CVE-2025-11626 affecting package wireshark 4.4.7-2
wireshark, wireshark, wireshark, wireshark, wireshark, wireshark, wireshark, wireshark
wireshark/ wireshark/ wireshark/ wireshark/ wireshark/ wireshark/ wireshark/ wireshark
poppler, poppler, poppler, poppler
flowise, flowise-components
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
flowise/ flowise-components
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
authlib
Authlib : JWE zip=DEF decompression bomb enables DoS
authlib
Authlib : JWE zip=DEF decompression bomb enables DoS
github.com/ossf/allstar
Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
github.com/ossf/allstar
Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
python-ldap
python-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination
python-ldap
python-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination
python-ldap
python-ldap has sanitization bypass in ldap.filter.escape_filter_chars
python-ldap
python-ldap has sanitization bypass in ldap.filter.escape_filter_chars
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
cel-rust May Panic During Parsing of Invalid CEL Expressions
Facets - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-100
Facets - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-100
Facets - Moderately critical - Information Disclosure - SA-CONTRIB-2025-099
Facets - Moderately critical - Information Disclosure - SA-CONTRIB-2025-099
Authenticator Login - Moderately critical - Access bypass - SA-CONTRIB-2025-098
Authenticator Login - Moderately critical - Access bypass - SA-CONTRIB-2025-098
External Secrets Operator's BeyondTrust Provider has Insecure Secret Retrieval
External Secrets Operator's BeyondTrust Provider has Insecure Secret Retrieval
python-ldap, python-ldap, python-ldap
python-ldap, python-ldap, python-ldap
python-ldap
CVE-2025-61912 affecting package python-ldap 3.4.4-1
python-ldap
CVE-2025-61911 affecting package python-ldap 3.4.4-1
python-ldap
CVE-2025-61911 affecting package python-ldap 3.4.0-1
python-ldap
CVE-2025-61912 affecting package python-ldap 3.4.0-1
python-ldap, python-ldap, python-ldap, python-ldap, python-ldap, python-ldap
python-ldap/ python-ldap/ python-ldap/ python-ldap/ python-ldap/ python-ldap
python-ldap, python-ldap, python-ldap, python-ldap, python-ldap, python-ldap
python-ldap/ python-ldap/ python-ldap/ python-ldap/ python-ldap/ python-ldap
GHSL-2025-042: Poppler has Use-After-Free
python-ldap Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination
python-ldap Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination
python-ldap has sanitization bypass in ldap.filter.escape_filter_chars
python-ldap has sanitization bypass in ldap.filter.escape_filter_chars
com.liferay:com.liferay.change.tracking.web
Liferay Portal is vulnerable to CSRF through publication comments
com.liferay:com.liferay.change.tracking.web
Liferay Portal is vulnerable to CSRF through publication comments
bagisto/bagisto
Bagisto is vulnerable to XSS through Admin Panel's product creation path
bagisto/bagisto
Bagisto is vulnerable to XSS through Admin Panel's product creation path
tech.powerjob:powerjob-server-starter
PowerJob OpenAPIController is missing authorization
tech.powerjob:powerjob-server-starter
PowerJob OpenAPIController is missing authorization
kernel-livepatch-SLE15-SP4_Update_37
Security update for the Linux Kernel (Live Patch 37 for SLE 15 SP4)
kernel-livepatch-SLE15-SP4_Update_37
Security update for the Linux Kernel (Live Patch 37 for SLE 15 SP4)
sinatra
Sinatra is vulnerable to ReDoS through ETag header value generation
sinatra
Sinatra is vulnerable to ReDoS through ETag header value generation
authlib
Authlib is vulnerable to Denial of Service via Oversized JOSE Segments
authlib
Authlib is vulnerable to Denial of Service via Oversized JOSE Segments
ruby-sinatra, ruby-sinatra, ruby-sinatra
python-authlib, python-authlib, python-authlib
ruby-rack, ruby-rack, ruby-rack
ruby-sinatra, ruby-sinatra, ruby-sinatra, ruby-sinatra
