Open Source Vulnerabilities
nbconvert, nbconvert, nbconvert
postgresql
CVE-2022-2625 affecting package postgresql for versions less than 14.5-1
postgresql
CVE-2022-2625 affecting package postgresql for versions less than 14.5-1
nbconvert, nbconvert, nbconvert
com.github.jlangch:venice
Venice vulnerable to Partial Path Traversal issue within the functions `load-file` and `load-resource`
com.github.jlangch:venice
Venice vulnerable to Partial Path Traversal issue within the functions `load-file` and `load-resource`
oqs
oqs's Post-Quantum Signature scheme Rainbow level I parametersets broken
oqs
oqs's Post-Quantum Signature scheme Rainbow level I parametersets broken
github.com/evmos/ethermint, github.com/evmos/evmos, github.com/crypto-org-chain/cronos, github.com/Kava-Labs/kava
Ethermint vulnerable to DoS through unintended Contract Selfdestruct
github.com/evmos/ethermint/ github.com/evmos/evmos/ github.com/crypto-org-chain/cronos/ github.com/Kava-Labs/kava
Ethermint vulnerable to DoS through unintended Contract Selfdestruct
codeigniter4/shield
CodeIgniter Shield Vulnerable to SameSite Attackers Bypassing the CSRF Protection
codeigniter4/shield
CodeIgniter Shield Vulnerable to SameSite Attackers Bypassing the CSRF Protection
undici
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
undici
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
kubevirt.io/kubevirt
Duplicate Advisory: KubeVirt arbitrary host file read from the VM
kubevirt.io/kubevirt
Duplicate Advisory: KubeVirt arbitrary host file read from the VM
@actions/core
@actions/core has Delimiter Injection Vulnerability in exportVariable
@actions/core
@actions/core has Delimiter Injection Vulnerability in exportVariable
oqs
oqs's Post-Quantum Key Encapsulation Mechanism SIKE broken
oqs
oqs's Post-Quantum Key Encapsulation Mechanism SIKE broken
@openzeppelin/contracts, @openzeppelin/contracts-upgradeable
OpenZeppelin Contracts vulnerable to ECDSA signature malleability
@openzeppelin/contracts/ @openzeppelin/contracts-upgradeable
OpenZeppelin Contracts vulnerable to ECDSA signature malleability
undici
`undici.request` vulnerable to SSRF using absolute URL on `pathname`
undici
`undici.request` vulnerable to SSRF using absolute URL on `pathname`
apollo-server-core
apollo-server-core vulnerable to URL-based XSS attack affecting IE11 on default landing page
apollo-server-core
apollo-server-core vulnerable to URL-based XSS attack affecting IE11 on default landing page
Improper KubeConfig handling allows arbitrary code execution
Improper KubeConfig handling allows arbitrary code execution
@openzeppelin/contracts, @openzeppelin/contracts-upgradeable
OpenZeppelin Contracts's GovernorVotesQuorumFraction updates to quorum may affect past defeated proposals
@openzeppelin/contracts/ @openzeppelin/contracts-upgradeable
OpenZeppelin Contracts's GovernorVotesQuorumFraction updates to quorum may affect past defeated proposals
nvidia390
Updated nvidia390 packages fix security vulnerabilities
nvidia390
Updated nvidia390 packages fix security vulnerabilities
ldetect-lst, nvidia-current
Updated nvidia-current packages fix security vulnerabilities
ldetect-lst/ nvidia-current
Updated nvidia-current packages fix security vulnerabilities
Improper object validation allows for arbitrary code execution in GitOps Tools Extension for VSCode
Improper object validation allows for arbitrary code execution in GitOps Tools Extension for VSCode
postgresql-10, postgresql-12, postgresql-14
postgresql-10, postgresql-12, postgresql-14 vulnerability
postgresql-10/ postgresql-12/ postgresql-14
postgresql-10, postgresql-12, postgresql-14 vulnerability
vim
CVE-2022-2874 affecting package vim for versions less than 9.0.0325-1
vim
CVE-2022-2874 affecting package vim for versions less than 9.0.0325-1
Bots using py-cord as discord api wrapper are vulnerable to shutdowns through remote code execution
Bots using py-cord as discord api wrapper are vulnerable to shutdowns through remote code execution
zlib, zlib, zlib
Security update for zlib
zlib, zlib, zlib, zlib
Security update for zlib
zlib, zlib
Security update for zlib
py-cord
Bots using py-cord as Discord API wrapper are vulnerable to shutdowns through remote code execution
py-cord
Bots using py-cord as Discord API wrapper are vulnerable to shutdowns through remote code execution
ucode-intel, ucode-intel
Security update for ucode-intel
python-PyYAML, python-PyYAML, python-PyYAML, python-PyYAML, python-PyYAML
Security update for python-PyYAML
python-PyYAML/ python-PyYAML/ python-PyYAML/ python-PyYAML/ python-PyYAML
Security update for python-PyYAML
