Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: package-ecosystems Clear
ID Title
CVE-2025-69263 pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve differe...
pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when a lockfile is committed. An attacker who publishes a package w...
CVE-2025-51741 Vulnerability in dos (CVE-2025-51741)
vulnerability in dos (CVE-2025-51741). Risk of unauthorized operations or information disclosure.
CVE-2024-9355 Vulnerability in github.com/golang-fips/openssl (CVE-2024-9355)
vulnerability in github.com/golang-fips/openssl (CVE-2024-9355). Confidential information can be exposed externally.
CVE-2024-1394 Vulnerability in CVE-2024-1394 (CVE-2024-1394)
vulnerability in CVE-2024-1394 (CVE-2024-1394). Risk of unauthorized operations or information disclosure.
CVE-2024-27289 pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: the non-default simple protocol is used; a placeholder for...
pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: the non-default simple protocol is used; a placeholder for a numeric value must be immediately preceded by a minus; there must be a second placeholder for a s...
CVE-2023-48795 Vulnerability in russh (CVE-2023-48795)
vulnerability in russh (CVE-2023-48795). Data can be tampered with by attackers. Mitigation: upgrade to `0.40.2` or later.
CVE-2023-42917 KEV [KEV] Out-of-Bounds Write in Apple java (CVE-2023-42917)
out-of-bounds write in Apple java (CVE-2023-42917). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.8.0, 8.0.411` or later.
CVE-2023-44487 KEV [KEV] Vulnerability in Ietf golang.org/x/net (CVE-2023-44487)
vulnerability in Ietf golang.org/x/net (CVE-2023-44487). Risk of unauthorized operations or information disclosure. Exploitable via ``Channel``. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `0.17.0` or later.
CVE-2023-41993 KEV [KEV] Vulnerability in Apple java (CVE-2023-41993)
vulnerability in Apple java (CVE-2023-41993). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.8.0, 8.0.411` or later.
CVE-2022-41064 .NET Framework Information Disclosure Vulnerability
.NET Framework Information Disclosure Vulnerability
CVE-2021-3572 Vulnerability in pypa (CVE-2021-3572)
vulnerability in pypa (CVE-2021-3572). Data can be tampered with by attackers.
CVE-2019-11840 Vulnerability in c (CVE-2019-11840)
vulnerability in c (CVE-2019-11840). Confidential information can be exposed externally.
CVE-2017-10891 Vulnerability in sony (CVE-2017-10891)
vulnerability in sony (CVE-2017-10891). Successful exploitation can lead to full system takeover.
CVE-2015-5739 Vulnerability in golang (CVE-2015-5739)
vulnerability in golang (CVE-2015-5739). Successful exploitation can lead to full system takeover.
CVE-2015-5740 Vulnerability in golang (CVE-2015-5740)
vulnerability in golang (CVE-2015-5740). Successful exploitation can lead to full system takeover.
CVE-2017-0903 Unsafe Deserialization in deserialization (CVE-2017-0903)
vulnerability in deserialization (CVE-2017-0903). Successful exploitation can lead to full system takeover.
CVE-2008-7315 UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.
UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.
CVE-2017-15041 Vulnerability in golang (CVE-2017-15041)
vulnerability in golang (CVE-2017-15041). Successful exploitation can lead to full system takeover.
CVE-2017-15042 Vulnerability in golang (CVE-2017-15042)
vulnerability in golang (CVE-2017-15042). Confidential information can be exposed externally.
CVE-2017-1000097 Vulnerability in golang (CVE-2017-1000097)
vulnerability in golang (CVE-2017-1000097). Data can be tampered with by attackers.
CVE-2017-1000098 Vulnerability in golang (CVE-2017-1000098)
vulnerability in golang (CVE-2017-1000098). Risk of unauthorized operations or information disclosure.
CVE-2017-0899 Vulnerability in rubygems (CVE-2017-0899)
vulnerability in rubygems (CVE-2017-0899). Successful exploitation can lead to full system takeover.
CVE-2017-0900 Vulnerability in dos (CVE-2017-0900)
vulnerability in dos (CVE-2017-0900). Risk of unauthorized operations or information disclosure. Exploitable via ``query``.
CVE-2017-0901 Path Traversal in rubygems (CVE-2017-0901)
path traversal in rubygems (CVE-2017-0901). Data can be tampered with by attackers.
CVE-2017-0902 Vulnerability in rubygems (CVE-2017-0902)
vulnerability in rubygems (CVE-2017-0902). Successful exploitation can lead to full system takeover.
CVE-2017-8932 Vulnerability in golang (CVE-2017-8932)
vulnerability in golang (CVE-2017-8932). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →