Open Source Vulnerabilities
OS Command Injection in appium/appium-desktop
libwebp, libwebp-devel
Important: libwebp security update
libwebp, libwebp-devel
Important: libwebp security update
emacs, emacs-common, emacs-filesystem, emacs-lucid, emacs-nox
Important: emacs security update
emacs/ emacs-common/ emacs-filesystem/ emacs-lucid/ emacs-nox
Important: emacs security update
libdatetime-timezone-perl
libdatetime-timezone-perl - new timezone database
libdatetime-timezone-perl
libdatetime-timezone-perl - new timezone database
wwbn/avideo
WWBN/AVideo stored XSS vulnerability leads to takeover of any user's account, including admin's account
wwbn/avideo
WWBN/AVideo stored XSS vulnerability leads to takeover of any user's account, including admin's account
Vault Enterprise Vulnerable to Padding Oracle Attacks When Using a CBC-based Encryption Mechanism with a HSM
Vault Enterprise Vulnerable to Padding Oracle Attacks When Using a CBC-based Encryption Mechanism with a HSM
flask, flask
Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
flask/ flask
Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
editor.md
editor.md vulnerable to Cross-site Scripting
org.apache.streampark:streampark
Apache StreamPark LDAP Injection vulnerability
org.apache.streampark:streampark
Apache StreamPark LDAP Injection vulnerability
Apache StreamPark (incubating): Logic error causing any account reset
Apache StreamPark (incubating): Logic error causing any account reset
Apache StreamPark (incubating): LDAP Injection Vulnerability
Apache StreamPark (incubating): Upload any file to any directory
Apache StreamPark (incubating): Upload any file to any directory
hdf5
Heap-buffer-overflow in H5MM_memcpy
wolfssl
Heap-double-free in wolfCrypt_custom_free
flac
Heap-buffer-overflow in flac__analyze_frame
@aedart/support
Possible prototype pollution in metadata record, when using meta decorator
@aedart/support
Possible prototype pollution in metadata record, when using meta decorator
audited
Race Condition leading to logging errors
mlflow
Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs
mlflow
Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs
pimcore/pimcore
Cross-site Scripting (XSS) in pimcore
gradle/gradle-build-action
Data written to GitHub Actions Cache may expose secrets
gradle/gradle-build-action
Data written to GitHub Actions Cache may expose secrets
