Open Source Vulnerabilities
golang
Excessive memory allocation in net/http and net/textproto
golang
Excessive memory allocation in net/http and net/textproto
discourse
Discourse's canonical url not being used for topic embeddings
discourse
Discourse's canonical url not being used for topic embeddings
dotnet
.NET Denial of Service Vulnerability
mongodb
MongoDB Server (mongod) may crash in response to unexpected requests
mongodb
MongoDB Server (mongod) may crash in response to unexpected requests
moodle
Moodle: insufficient capability checks when updating the parent of a course category
moodle
Moodle: insufficient capability checks when updating the parent of a course category
mlflow
Path Traversal: '\..\filename' in mlflow/mlflow
envoy
Null pointer dereference in envoy
minio
Allowed DELETE on resources on object locked buckets under Governance mode in Minio
minio
Allowed DELETE on resources on object locked buckets under Governance mode in Minio
grafana
Grafana Enterprise datasource network restrictions bypass via HTTP redirects
grafana
Grafana Enterprise datasource network restrictions bypass via HTTP redirects
dotnet-sdk
.NET and Visual Studio Remote Code Execution Vulnerability
dotnet-sdk
.NET and Visual Studio Remote Code Execution Vulnerability
gitlab
Dependency on Vulnerable Third-Party Component in GitLab
gitlab
Dependency on Vulnerable Third-Party Component in GitLab
mastodon
Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP database
mastodon
Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP database
airflow
Apache Airflow Spark Provider RCE that bypass restrictions to read arbitrary files
airflow
Apache Airflow Spark Provider RCE that bypass restrictions to read arbitrary files
mongoose
Prototype Pollution in automattic/mongoose
golang
Excessive resource consumption in net/http, net/textproto and mime/multipart
golang
Excessive resource consumption in net/http, net/textproto and mime/multipart
moodle
Moodle: rce due to lfi risk in some misconfigured shared hosting environments
moodle
Moodle: rce due to lfi risk in some misconfigured shared hosting environments
dotnet
.NET and Visual Studio Remote Code Execution Vulnerability
dotnet
.NET and Visual Studio Remote Code Execution Vulnerability
discourse
Discourse vulnerable to exposure of number of topics recently created in private categories
discourse
Discourse vulnerable to exposure of number of topics recently created in private categories
minio
Minio vulnerable to denial of access by an admin privileged user for root credential
minio
Minio vulnerable to denial of access by an admin privileged user for root credential
grafana
Stored XSS in Grafana's Unified Alerting
gitlab
Incorrect Authorization in GitLab
dotnet-sdk
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
dotnet-sdk
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
mastodon
Mastodon vulnerable to Cross-site Scripting through oEmbed preview cards
mastodon
Mastodon vulnerable to Cross-site Scripting through oEmbed preview cards
apache
mod_auth_digest possible stack overflow by one nul byte
apache
mod_auth_digest possible stack overflow by one nul byte
airflow
Apache Airflow Hive Provider vulnerability (command injection via hive_cli connection)
airflow
Apache Airflow Hive Provider vulnerability (command injection via hive_cli connection)
