Open Source Vulnerabilities
Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards
Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards
moltis-org moltis vault.rs vault_recovery_handler missing authentication
moltis-org moltis vault.rs vault_recovery_handler missing authentication
opengeos GeoLibre _is_within_roots server-side request forgery
opengeos GeoLibre _is_within_roots server-side request forgery
seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization
seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization
Cesanta mJS mjs_tok.c skip_spaces_and_comments heap-based overflow
Cesanta mJS mjs_tok.c skip_spaces_and_comments heap-based overflow
gitpython
GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
gitpython
GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
gitpython
GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()
gitpython
GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()
gitpython
GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
gitpython
GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
@astrojs/prism, @astrojs/webapi, astro, create-astro
TuxCare security update for 4 packages (1 CVE)
@astrojs/prism/ @astrojs/webapi/ astro/ create-astro
TuxCare security update for 4 packages (1 CVE)
gitpython
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
gitpython
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
Microsoft.DiaSymReader.Native
Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft.DiaSymReader.Native
Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft.DiaSymReader.Native
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft.DiaSymReader.Native
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft.DiaSymReader.Native
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
Microsoft.DiaSymReader.Native
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
Microsoft.AspNetCore.Server.IISIntegration, Microsoft.AspNetCore.Server.IISIntegration, Microsoft.AspNetCore.Server.IISIntegration, Microsoft.AspNetCore.Server.IISIntegration
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
Microsoft.AspNetCore.Server.IISIntegration/ Microsoft.AspNetCore.Server.IISIntegration/ Microsoft.AspNetCore.Server.IISIntegration/ Microsoft.AspNetCore.Server.IISIntegration
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
imagemagick, imagemagick, imagemagick, imagemagick, imagemagick, imagemagick
imagemagick vulnerabilities
imagemagick/ imagemagick/ imagemagick/ imagemagick/ imagemagick/ imagemagick
imagemagick vulnerabilities
io.netty:netty-handler, io.netty:netty-handler
Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
io.netty:netty-handler/ io.netty:netty-handler
Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
io.netty:netty-handler, io.netty:netty-handler
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
io.netty:netty-handler/ io.netty:netty-handler
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
github.com/infracost/infracost
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname
github.com/infracost/infracost
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname
github.com/infracost/infracost
Infracost: Arbitrary file read via config-template readFile symlink traversal
github.com/infracost/infracost
Infracost: Arbitrary file read via config-template readFile symlink traversal
github.com/amir20/dozzle
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
github.com/amir20/dozzle
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
liquidjs
LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process
liquidjs
LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process
prowler, prowler-cloud
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
prowler/ prowler-cloud
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce | Incorrect Authorization (CWE-863)
csv-parse
node-csv: Prototype replacement still reachable via columns path
csv-parse
node-csv: Prototype replacement still reachable via columns path
@swc/html, swc_html_minifier
SWC HTML minifier may allow script element breakout when minifying embedded JSON
@swc/html/ swc_html_minifier
SWC HTML minifier may allow script element breakout when minifying embedded JSON
github.com/semaphoreui/semaphore
Semaphore U: OS Command Injection
github.com/semaphoreui/semaphore
Semaphore U: OS Command Injection
gitea.dev
Gitea: Remote Code Execution via diffpatch Git Hook Installation
gitea.dev
Gitea: Remote Code Execution via diffpatch Git Hook Installation
github.com/siyuan-note/siyuan/kernel
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked
github.com/siyuan-note/siyuan/kernel
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked
io.undertow:undertow-benchmarks, io.undertow:undertow-core, io.undertow:undertow-dist, io.undertow:undertow-examples, io.undertow:undertow-parent, io.undertow:undertow-parser-generator, io.undertow:undertow-servlet, io.undertow:undertow-websockets-jsr
TuxCare security update for io.undertow (1 CVE)
io.undertow:undertow-benchmarks/ io.undertow:undertow-core/ io.undertow:undertow-dist/ io.undertow:undertow-examples/ io.undertow:undertow-parent/ io.undertow:undertow-parser-generator/ io.undertow:undertow-servlet/ io.undertow:undertow-websockets-jsr
TuxCare security update for io.undertow (1 CVE)
