Open Source Vulnerabilities
github.com/siyuan-note/siyuan/kernel
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
github.com/siyuan-note/siyuan/kernel
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
github.com/siyuan-note/siyuan/kernel
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews
github.com/siyuan-note/siyuan/kernel
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash
aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash
InstantCMS vulnerable to SSRF via upload redirect bypass allows internal network service scanning
InstantCMS vulnerable to SSRF via upload redirect bypass allows internal network service scanning
InstantCMS has Remote Code Execution in package installer
org.thymeleaf.extras:thymeleaf-extras-springsecurity5, org.thymeleaf.extras:thymeleaf-extras-springsecurity6, org.thymeleaf.testing:thymeleaf-testing, org.thymeleaf.testing:thymeleaf-testing-lib, org.thymeleaf.testing:thymeleaf-testing-spring5, org.thymeleaf.testing:thymeleaf-testing-spring6, org.thymeleaf:thymeleaf-lib, org.thymeleaf:thymeleaf-parent, org.thymeleaf:thymeleaf-spring5, org.thymeleaf:thymeleaf-spring6
TuxCare security update for 10 packages (1 CVE)
org.thymeleaf.extras:thymeleaf-extras-springsecurity5/ org.thymeleaf.extras:thymeleaf-extras-springsecurity6/ org.thymeleaf.testing:thymeleaf-testing/ org.thymeleaf.testing:thymeleaf-testing-lib/ org.thymeleaf.testing:thymeleaf-testing-spring5/ org.thymeleaf.testing:thymeleaf-testing-spring6/ org.thymeleaf:thymeleaf-lib/ org.thymeleaf:thymeleaf-parent/ org.thymeleaf:thymeleaf-spring5/ org.thymeleaf:thymeleaf-spring6
TuxCare security update for 10 packages (1 CVE)
aircheng-org iWebShop-5 systemseller.php login improper authentication
aircheng-org iWebShop-5 systemseller.php login improper authentication
Microsoft.OpenApi.YamlReader/Readers vulnerable to denial of service via YAML alias expansion
Microsoft.OpenApi.YamlReader/Readers vulnerable to denial of service via YAML alias expansion
grafana-cloudmonitoring-datasource
jinja2
TuxCare security update for jinja2 (2 CVEs)
scikit-learn
TuxCare security update for scikit-learn (1 CVE)
scikit-learn
TuxCare security update for scikit-learn (1 CVE)
n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing
DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing
nltk
NLTK: Corpus Reader Sandbox Bypass
nltk
NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
nltk
NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
govulncheck-vulndb
Security update for govulncheck-vulndb
govulncheck-vulndb
Security update for govulncheck-vulndb
Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass
Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass
aircheng-org iWebShop-5 pic.php uploadFile cross site scripting
aircheng-org iWebShop-5 pic.php uploadFile cross site scripting
nltk
NLTK: Allowlisted pickle loaders still permit code execution in current source
nltk
NLTK: Allowlisted pickle loaders still permit code execution in current source
AshLua eval read operations can read field-policy-protected fields via aggregates
AshLua eval read operations can read field-policy-protected fields via aggregates
ash_lua,
AshLua eval read operations can read field-policy-protected fields via aggregates
ash_lua/
AshLua eval read operations can read field-policy-protected fields via aggregates
nltk
NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses
nltk
NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses
AshAi aggregate tool can read field-policy-protected fields
ash_ai,
AshAi aggregate tool can read field-policy-protected fields
ash_ai/
AshAi aggregate tool can read field-policy-protected fields
nltk
NLTK: pathsec SSRF protection can be bypassed when a proxy is configured
nltk
NLTK: pathsec SSRF protection can be bypassed when a proxy is configured
nltk
NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution
nltk
NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution
nltk
NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely
nltk
NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely
nltk
NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)
nltk
NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)
nltk
NLTK: Stable FrameNet and NKJP readers parse outside-root XML
nltk
NLTK: Stable FrameNet and NKJP readers parse outside-root XML
multipath-tools
Security update for multipath-tools
libzypp, zypper
Security update for libzypp, zypper
aircheng-org iWebShop-5 member.php member_list sql injection
aircheng-org iWebShop-5 member.php member_list sql injection
aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload
aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload
grafana-cloudmonitoring-datasource
Workload identity attestation generated before login host validation in Snowflake drivers
Workload identity attestation generated before login host validation in Snowflake drivers
