Open Source Vulnerabilities
Async and display macro allow displaying and interacting with any document in restricted mode
Async and display macro allow displaying and interacting with any document in restricted mode
Code injection from account through AWM view sheet in xwiki platform
Code injection from account through AWM view sheet in xwiki platform
Multiple SQL injections in sql/instance.py param_edit method in Archery - GHSL-2022-104
Multiple SQL injections in sql/instance.py param_edit method in Archery - GHSL-2022-104
Multiple SQL injections in sql/data_dictionary.py table_list method in Archery - GHSL-2022-105
Multiple SQL injections in sql/data_dictionary.py table_list method in Archery - GHSL-2022-105
SQL injection in data_dictionary.py table_info method in Archery - GHSL-2022-106
SQL injection in data_dictionary.py table_info method in Archery - GHSL-2022-106
SQL injection in sql_optimize.py optimize_sqltuningadvisor method in Archery - GHSL-2022-107
SQL injection in sql_optimize.py optimize_sqltuningadvisor method in Archery - GHSL-2022-107
SQL injection in sql_optimize.py explain method in Archery - GHSL-2022-108
SQL injection in sql_optimize.py explain method in Archery - GHSL-2022-108
SQL injection in sql_api/api_workflow.py endpoint in Archery - GHSL-2022-103
SQL injection in sql_api/api_workflow.py endpoint in Archery - GHSL-2022-103
Multiple SQL injections in sql_api/api_workflow.py endpoint in Archery - GHSL-2022-102
Multiple SQL injections in sql_api/api_workflow.py endpoint in Archery - GHSL-2022-102
SQL injection in sql/instance.py endpoint in Archery - GHSL-2022-101
SQL injection in sql/instance.py endpoint in Archery - GHSL-2022-101
@web3-react/coinbase-wallet, @web3-react/eip1193, @web3-react/metamask, @web3-react/walletconnect
`chainId` may be outdated if user changes chains as part of connection in @web3-react
@web3-react/coinbase-wallet/ @web3-react/eip1193/ @web3-react/metamask/ @web3-react/walletconnect
`chainId` may be outdated if user changes chains as part of connection in @web3-react
@strapi/plugin-users-permissions
Authentication Bypass in @strapi/plugin-users-permissions
@strapi/plugin-users-permissions
Authentication Bypass in @strapi/plugin-users-permissions
slim/psr7, slim/psr7, slim/psr7
Insecure header validation in slim/psr7
slim/psr7/ slim/psr7/ slim/psr7
Insecure header validation in slim/psr7
org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server
Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookies
org.eclipse.jetty:jetty-server/ org.eclipse.jetty:jetty-server/ org.eclipse.jetty:jetty-server/ org.eclipse.jetty:jetty-server
Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookies
Multisite denial of service through unsanitized dynamic dispatch to SiteSetting in Discourse
Multisite denial of service through unsanitized dynamic dispatch to SiteSetting in Discourse
Parser contains an inefficient regular expression in sqlparse
Stored Cross-site Scripting via improper sanitization of svg files in Discourse
Stored Cross-site Scripting via improper sanitization of svg files in Discourse
HTML injection via topic embedding in Discourse
Debug mode leaks confidential data in Cilium
redis
CVE-2023-28856 affecting package redis for versions less than 6.2.12-1
redis
CVE-2023-28856 affecting package redis for versions less than 6.2.12-1
redis, redis, redis, redis, redis
`HINCRBYFLOAT` can be used to crash a redis-server process
Improper neutralization in an SQL query in Shoppingfeed
Denial of service via admin theme import route in Discourse
Denial of service via admin theme import route in Discourse
Cookie parsing of quoted values can exfiltrate values from other cookies in Eclipse Jetty
Cookie parsing of quoted values can exfiltrate values from other cookies in Eclipse Jetty
OutOfMemoryError for large multipart without filename in Eclipse Jetty
OutOfMemoryError for large multipart without filename in Eclipse Jetty
