Open Source Vulnerabilities
discourse
Discourse's general category permissions could be set back to default
discourse
Discourse's general category permissions could be set back to default
envoy
Excessive CPU usage in Pomerium
dotnet-sdk
NuGet Client Elevation of Privilege Vulnerability
dotnet-sdk
NuGet Client Elevation of Privilege Vulnerability
moodle
Moodle: xss risk when previewing data in course upload tool
moodle
Moodle: xss risk when previewing data in course upload tool
mongodb
MongoDB Extension for VS Code may unexpectedly store credentials locally in clear text
mongodb
MongoDB Extension for VS Code may unexpectedly store credentials locally in clear text
mlflow
Path Traversal in mlflow/mlflow
apache
mod_proxy_http NULL pointer dereference
minio
Possible DDOS by establishing keep-alive connections with anonymous HTTP clients in MinIO
minio
Possible DDOS by establishing keep-alive connections with anonymous HTTP clients in MinIO
airflow
Format String Vulnerability
gitlab
Execution with Unnecessary Privileges in GitLab
golang
Incorrect calculation on P256 curves in crypto/internal/nistec
golang
Incorrect calculation on P256 curves in crypto/internal/nistec
dotnet
NuGet Client Elevation of Privilege Vulnerability
mysql-client
Mariadb: node crashes with transport endpoint is not connected mysqld got signal 6
mysql-client
Mariadb: node crashes with transport endpoint is not connected mysqld got signal 6
discourse
Discourse Topic Creation Page Allows iFrame Tag without Restrictions
discourse
Discourse Topic Creation Page Allows iFrame Tag without Restrictions
envoy
Incorrect Authorization with specially crafted requests
envoy
Incorrect Authorization with specially crafted requests
moodle
Moodle: cache poisoning risk with endpoint revision numbers
moodle
Moodle: cache poisoning risk with endpoint revision numbers
mongodb
Large aggregation pipelines with a specific stage can crash mongod under default configuration
mongodb
Large aggregation pipelines with a specific stage can crash mongod under default configuration
mlflow
Path Traversal: '\..\filename' in mlflow/mlflow
dotnet-sdk
.NET Denial of Service Vulnerability
minio
Authenticated requests for server update admin API allows path traversal in minio
minio
Authenticated requests for server update admin API allows path traversal in minio
gitlab
Improper Control of Generation of Code ('Code Injection') in GitLab
gitlab
Improper Control of Generation of Code ('Code Injection') in GitLab
