Open Source Vulnerabilities
Snipe-IT before 8.7.0 Missing Authorization via asset-history CSV importer
Snipe-IT before 8.7.0 Missing Authorization via asset-history CSV importer
kubernetes-dns-node-cache, kubernetes-dns-node-cache
Snipe-IT before 8.7.0 License Key Exposure via CSV Export
Snipe-IT before 8.7.0 Information Disclosure via Custom Fields
Snipe-IT before 8.7.0 Information Disclosure via Custom Fields
Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState
Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState
knative-net-istio-fips-1.20-controller
Snipe-IT 4.2.0 through 8.6.3 Permission Bypass via OAuth
Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients
kubernetes-csi-external-snapshot-controller-8.6, kubernetes-csi-external-snapshot-controller-8.6
kubernetes-csi-external-snapshot-controller-8.6/ kubernetes-csi-external-snapshot-controller-8.6
snipe-it before 8.7.0 Business Logic Bypass via asset_model endpoint
snipe-it before 8.7.0 Business Logic Bypass via asset_model endpoint
snipe-it before 8.7.0 Authorization Bypass via Asset Audit Endpoints
snipe-it before 8.7.0 Authorization Bypass via Asset Audit Endpoints
Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Markdown
Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Markdown
snipe-it before 8.7.0 Authorization Bypass via API User Create/Update
snipe-it before 8.7.0 Authorization Bypass via API User Create/Update
snipe-it before 8.7.0 Data Loss via Failed Image Write
Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive
Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive
snipe-it before 8.7.0 Authorization Bypass via Pivot-Only User
snipe-it before 8.7.0 Authorization Bypass via Pivot-Only User
calico-felix-3.32, calico-felix-3.32
Snipe-IT before 8.7.0 Authorization Bypass via Livewire Snapshot Replay
Snipe-IT before 8.7.0 Authorization Bypass via Livewire Snapshot Replay
calico-felix-3.32, calico-felix-3.32
calico-felix-3.32, calico-felix-3.32
calico-felix-3.32, calico-felix-3.32
Snipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping Export
Snipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping Export
snipe-it before 8.7.0 Race Condition in Asset Checkout
Snipe-IT before 8.7.0 Authorization Bypass via Asset Acceptance Report
Snipe-IT before 8.7.0 Authorization Bypass via Asset Acceptance Report
k3s-multicall-1.35, k3s-multicall-1.35
Snipe-IT before 8.7.0 CSV Formula Injection via Asset Acceptance Report
Snipe-IT before 8.7.0 CSV Formula Injection via Asset Acceptance Report
Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Category EULA
Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Category EULA
Snipe-IT before 8.7.0 Attachment Deletion Reports Success While File Remains
Snipe-IT before 8.7.0 Attachment Deletion Reports Success While File Remains
Snipe-IT before 8.7.0 Acceptance Finalization Without Stored Evidence
Snipe-IT before 8.7.0 Acceptance Finalization Without Stored Evidence
PocketMine-MP before 5.39.2 Denial of Service via ModalFormResponsePacket
PocketMine-MP before 5.39.2 Denial of Service via ModalFormResponsePacket
kubernetes-csi-external-provisioner-fips
PocketMine-MP before 5.39.2 Item Duplication via Despawn State
PocketMine-MP before 5.39.2 Item Duplication via Despawn State
PocketMine-MP before 5.39.2 Network Amplification via ActorEventPacket
PocketMine-MP before 5.39.2 Network Amplification via ActorEventPacket
commercial-kyverno-background-controller-1.14
commercial-kyverno-background-controller-1.14
argo-workflow-controller-4.0, argo-workflow-controller-4.0
argo-workflow-controller-4.0/ argo-workflow-controller-4.0
PocketMine-MP before 5.41.1 LogDoS via LoginPacket clientData
PocketMine-MP before 5.42.1 LogDoS via LoginPacket clientData JWT
PocketMine-MP before 5.42.1 LogDoS via LoginPacket clientData JWT
PocketMine-MP before 5.43.1 Denial of Service via unauthenticated login
PocketMine-MP before 5.43.1 Denial of Service via unauthenticated login
