Open Source Vulnerabilities
The Oauth2 PKCE implementation is vulnerable
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
cacti, cacti, cacti, cacti, cacti
cacti, cacti, cacti, cacti, cacti
cacti, cacti, cacti, cacti, cacti
cacti, cacti, cacti, cacti, cacti
Blind SSRF in /home/testslack endpoint
Blind SSRF in `/home/testdiscord` endpoint
Deepin Reader RCE vulnerability due to a design flaw
Nautobot missing object-level permissions enforcement when running Job Buttons
Nautobot missing object-level permissions enforcement when running Job Buttons
SQL Injection vulnerability when managing SNMP Notification Receivers
SQL Injection vulnerability when managing SNMP Notification Receivers
Cross-Site Scripting vulnerability when Import xml template file
Cross-Site Scripting vulnerability when Import xml template file
Bruteforce protection can be bypassed with misconfigured proxy
Bruteforce protection can be bypassed with misconfigured proxy
Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)
Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)
Workflows do not require password confirmation on API level
App PIN code can be bypassed in Nextcloud Files iOS
Cacti has incomplete fix for CVE-2023-39515
sudo
CVE-2023-42465 affecting package sudo for versions less than 1.9.15p5-1
sudo
CVE-2023-42465 affecting package sudo for versions less than 1.9.15p5-1
ppp, ppp, ppp, ppp, ppp, ppp, ppp, ppp, ppp
Security update for ppp
ppp/ ppp/ ppp/ ppp/ ppp/ ppp/ ppp/ ppp/ ppp
Security update for ppp
Unauthenticated heap buffer overflow in Gorrila codec decompression
Unauthenticated heap buffer overflow in Gorrila codec decompression
Permission bypass due to incorrect configuration in github.com/dromara/hertzbeat
Permission bypass due to incorrect configuration in github.com/dromara/hertzbeat
Filesystem sandbox not enforced in wasmer-cli
slawkens MyAAC bugtracker.php cross site scripting
github.com/free5gc/amf
free5GC AMF denial of service vulnerability
github.com/free5gc/amf
free5GC AMF denial of service vulnerability
github.com/buildkite/elastic-ci-stack-for-aws/v6
Buildkite Elastic CI for AWS symbolic link following vulnerability
github.com/buildkite/elastic-ci-stack-for-aws/v6
Buildkite Elastic CI for AWS symbolic link following vulnerability
github.com/buildkite/elastic-ci-stack-for-aws/v6
Buildkite Elastic CI for AWS time-of-check-time-of-use race condition vulnerability
github.com/buildkite/elastic-ci-stack-for-aws/v6
Buildkite Elastic CI for AWS time-of-check-time-of-use race condition vulnerability
bit-flags
`bit-flags` was removed from crates.io for malicious code
bit-flags
`bit-flags` was removed from crates.io for malicious code
cacti, cacti, cacti, cacti, cacti
python-twisted
python-twisted security update
