Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-69263 |
|
pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve differe...
pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when a lockfile is committed. An attacker who publishes a package w...
|
| CVE-2025-51741 |
|
Vulnerability in dos (CVE-2025-51741)
vulnerability in dos (CVE-2025-51741). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-9355 |
|
Vulnerability in github.com/golang-fips/openssl (CVE-2024-9355)
vulnerability in github.com/golang-fips/openssl (CVE-2024-9355). Confidential information can be exposed externally.
|
| CVE-2024-1394 |
|
Vulnerability in CVE-2024-1394 (CVE-2024-1394)
vulnerability in CVE-2024-1394 (CVE-2024-1394). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-27289 |
|
pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: the non-default simple protocol is used; a placeholder for...
pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: the non-default simple protocol is used; a placeholder for a numeric value must be immediately preceded by a minus; there must be a second placeholder for a s...
|
| CVE-2023-48795 |
|
Vulnerability in russh (CVE-2023-48795)
vulnerability in russh (CVE-2023-48795). Data can be tampered with by attackers. Mitigation: upgrade to `0.40.2` or later.
|
| CVE-2023-42917 KEV |
|
[KEV] Out-of-Bounds Write in Apple java (CVE-2023-42917)
out-of-bounds write in Apple java (CVE-2023-42917). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.8.0, 8.0.411` or later.
|
| CVE-2023-44487 KEV |
|
[KEV] Vulnerability in Ietf golang.org/x/net (CVE-2023-44487)
vulnerability in Ietf golang.org/x/net (CVE-2023-44487). Risk of unauthorized operations or information disclosure. Exploitable via ``Channel``. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `0.17.0` or later.
|
| CVE-2023-41993 KEV |
|
[KEV] Vulnerability in Apple java (CVE-2023-41993)
vulnerability in Apple java (CVE-2023-41993). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.8.0, 8.0.411` or later.
|
| CVE-2022-41064 |
|
.NET Framework Information Disclosure Vulnerability
.NET Framework Information Disclosure Vulnerability
|
| CVE-2021-3572 |
|
Vulnerability in pypa (CVE-2021-3572)
vulnerability in pypa (CVE-2021-3572). Data can be tampered with by attackers.
|
| CVE-2019-11840 |
|
Vulnerability in c (CVE-2019-11840)
vulnerability in c (CVE-2019-11840). Confidential information can be exposed externally.
|
| CVE-2017-10891 |
|
Vulnerability in sony (CVE-2017-10891)
vulnerability in sony (CVE-2017-10891). Successful exploitation can lead to full system takeover.
|
| CVE-2015-5739 |
|
Vulnerability in golang (CVE-2015-5739)
vulnerability in golang (CVE-2015-5739). Successful exploitation can lead to full system takeover.
|
| CVE-2015-5740 |
|
Vulnerability in golang (CVE-2015-5740)
vulnerability in golang (CVE-2015-5740). Successful exploitation can lead to full system takeover.
|
| CVE-2017-0903 |
|
Unsafe Deserialization in deserialization (CVE-2017-0903)
vulnerability in deserialization (CVE-2017-0903). Successful exploitation can lead to full system takeover.
|
| CVE-2008-7315 |
|
UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.
UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.
|
| CVE-2017-15041 |
|
Vulnerability in golang (CVE-2017-15041)
vulnerability in golang (CVE-2017-15041). Successful exploitation can lead to full system takeover.
|
| CVE-2017-15042 |
|
Vulnerability in golang (CVE-2017-15042)
vulnerability in golang (CVE-2017-15042). Confidential information can be exposed externally.
|
| CVE-2017-1000097 |
|
Vulnerability in golang (CVE-2017-1000097)
vulnerability in golang (CVE-2017-1000097). Data can be tampered with by attackers.
|
| CVE-2017-1000098 |
|
Vulnerability in golang (CVE-2017-1000098)
vulnerability in golang (CVE-2017-1000098). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-0899 |
|
Vulnerability in rubygems (CVE-2017-0899)
vulnerability in rubygems (CVE-2017-0899). Successful exploitation can lead to full system takeover.
|
| CVE-2017-0900 |
|
Vulnerability in dos (CVE-2017-0900)
vulnerability in dos (CVE-2017-0900). Risk of unauthorized operations or information disclosure. Exploitable via ``query``.
|
| CVE-2017-0901 |
|
Path Traversal in rubygems (CVE-2017-0901)
path traversal in rubygems (CVE-2017-0901). Data can be tampered with by attackers.
|
| CVE-2017-0902 |
|
Vulnerability in rubygems (CVE-2017-0902)
vulnerability in rubygems (CVE-2017-0902). Successful exploitation can lead to full system takeover.
|
| CVE-2017-8932 |
|
Vulnerability in golang (CVE-2017-8932)
vulnerability in golang (CVE-2017-8932). Confidential information can be exposed externally.
|