Open Source Vulnerabilities
open-webui
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
open-webui
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
ua-parser-js, @rootio/ua-parser-js
CVE-2022-25927 in ua-parser-js - Patched by Root
ua-parser-js/ @rootio/ua-parser-js
CVE-2022-25927 in ua-parser-js - Patched by Root
open-webui
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
open-webui
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
open-webui
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
open-webui
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
open-webui
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
open-webui
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
github.com/xuri/excelize/v2, github.com/xuri/excelize
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
github.com/xuri/excelize/v2/ github.com/xuri/excelize
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
github.com/xuri/excelize/v2, github.com/xuri/excelize
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
github.com/xuri/excelize/v2/ github.com/xuri/excelize
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
@koa/cors, koajs_cors
TuxCare security update for 2 packages (2 CVEs)
@koa/cors/ koajs_cors
TuxCare security update for 2 packages (2 CVEs)
@eigenpal/docx-editor-core, @eigenpal/docx-editor-react
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
@eigenpal/docx-editor-core/ @eigenpal/docx-editor-react
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
nodemailer
TuxCare security update for nodemailer (6 CVEs)
nodemailer
TuxCare security update for nodemailer (6 CVEs)
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
cilium-fips-1.19-operator-azure
datadog-agent-7.76, datadog-agent-7.76
code.gitea.io/gitea
Gitea tracked-time deletion is not scoped to the requested issue in code.gitea.io/gitea
code.gitea.io/gitea
Gitea tracked-time deletion is not scoped to the requested issue in code.gitea.io/gitea
code.gitea.io/gitea
Gitea LFS mirror operations bypass migration HTTP transport protections in code.gitea.io/gitea
code.gitea.io/gitea
Gitea LFS mirror operations bypass migration HTTP transport protections in code.gitea.io/gitea
code.gitea.io/gitea
Gitea forwarded-proto validation allows canonical URL spoofing in code.gitea.io/gitea
code.gitea.io/gitea
Gitea forwarded-proto validation allows canonical URL spoofing in code.gitea.io/gitea
code.gitea.io/gitea
Gitea pre-receive hook scanner errors allow branch-protection bypass in code.gitea.io/gitea
code.gitea.io/gitea
Gitea pre-receive hook scanner errors allow branch-protection bypass in code.gitea.io/gitea
code.gitea.io/gitea
Gitea draft releases and attachments are exposed without write permission in code.gitea.io/gitea
code.gitea.io/gitea
Gitea draft releases and attachments are exposed without write permission in code.gitea.io/gitea
github.com/siyuan-note/siyuan/kernel
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db in github.com/siyuan-note/siyuan/kernel
github.com/seaweedfs/seaweedfs
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control in github.com/seaweedfs/seaweedfs
github.com/seaweedfs/seaweedfs
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control in github.com/seaweedfs/seaweedfs
github.com/siyuan-note/siyuan/kernel
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content in github.com/siyuan-note/siyuan/kernel
github.com/openchoreo/openchoreo
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods in github.com/openchoreo/openchoreo
github.com/openchoreo/openchoreo
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods in github.com/openchoreo/openchoreo
github.com/openchoreo/openchoreo
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints in github.com/openchoreo/openchoreo
github.com/openchoreo/openchoreo
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints in github.com/openchoreo/openchoreo
github.com/axllent/mailpit
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit
github.com/axllent/mailpit
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit
github.com/openchoreo/openchoreo
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) in github.com/openchoreo/openchoreo
github.com/openchoreo/openchoreo
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) in github.com/openchoreo/openchoreo
github.com/seaweedfs/seaweedfs
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths in github.com/seaweedfs/seaweedfs
github.com/seaweedfs/seaweedfs
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths in github.com/seaweedfs/seaweedfs
github.com/openchoreo/openchoreo
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs in github.com/openchoreo/openchoreo
github.com/openchoreo/openchoreo
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs in github.com/openchoreo/openchoreo
github.com/axllent/mailpit
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit
github.com/axllent/mailpit
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit
github.com/siyuan-note/siyuan/kernel
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f) in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f) in github.com/siyuan-note/siyuan/kernel
github.com/cilium/cilium
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match in github.com/cilium/cilium
github.com/cilium/cilium
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match in github.com/cilium/cilium
github.com/OpenListTeam/OpenList, github.com/OpenListTeam/OpenList/v3, github.com/OpenListTeam/OpenList/v4
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList
github.com/OpenListTeam/OpenList/ github.com/OpenListTeam/OpenList/v3/ github.com/OpenListTeam/OpenList/v4
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList
github.com/ffuf/ffuf, github.com/ffuf/ffuf/v2
ffuf denial of service (OOM) via HTTP response decompression bomb in github.com/ffuf/ffuf
github.com/ffuf/ffuf/ github.com/ffuf/ffuf/v2
ffuf denial of service (OOM) via HTTP response decompression bomb in github.com/ffuf/ffuf
github.com/semaphoreui/semaphore
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation in github.com/semaphoreui/semaphore
github.com/semaphoreui/semaphore
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation in github.com/semaphoreui/semaphore
github.com/semaphoreui/semaphore
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision in github.com/semaphoreui/semaphore
github.com/semaphoreui/semaphore
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision in github.com/semaphoreui/semaphore
github.com/siyuan-note/siyuan/kernel
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered in github.com/siyuan-note/siyuan/kernel
