Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2023-46960 |
|
Vulnerability in pypxe (CVE-2023-46960)
vulnerability in pypxe (CVE-2023-46960). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-1000 |
|
Command Injection in dcnnt (CVE-2023-1000)
command injection in dcnnt (CVE-2023-1000). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.1` or later.
|
| CVE-2024-30251 |
|
Vulnerability in aiohttp (CVE-2024-30251)
vulnerability in aiohttp (CVE-2024-30251). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.9.4` or later.
|
| CVE-2024-28717 |
|
Vulnerability in storlets (CVE-2024-28717)
vulnerability in storlets (CVE-2024-28717). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `13.0.0.0rc1` or later.
|
| CVE-2024-32474 |
|
Vulnerability in sentry (CVE-2024-32474)
vulnerability in sentry (CVE-2024-32474). Confidential information can be exposed externally. Exploitable via ``INFO``. Mitigation: upgrade to `24.4.1` or later.
|
| CVE-2024-1561 |
|
Vulnerability in gradio (CVE-2024-1561)
vulnerability in gradio (CVE-2024-1561). Confidential information can be exposed externally. Exploitable via ``Component``. Mitigation: upgrade to `4.13.0` or later.
|
| CVE-2024-3571 |
|
Path Traversal in langchain (CVE-2024-3571)
path traversal in langchain (CVE-2024-3571). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.353` or later.
|
| CVE-2024-29733 |
|
Vulnerability in apache-airflow-providers-ftp (CVE-2024-29733)
vulnerability in apache-airflow-providers-ftp (CVE-2024-29733). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.7.0` or later.
|
| CVE-2024-27306 |
|
Cross-Site Scripting (XSS) in aiohttp (CVE-2024-27306)
cross-site scripting in aiohttp (CVE-2024-27306). Risk of unauthorized operations or information disclosure. Exploitable via ``show_index``. Mitigation: upgrade to `3.9.4` or later.
|
| CVE-2024-3772 |
|
Vulnerability in pydantic (CVE-2024-3772)
vulnerability in pydantic (CVE-2024-3772). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.10.13, 2.4.0` or later.
|
| CVE-2024-4340 |
|
Vulnerability in sqlparse (CVE-2024-4340)
vulnerability in sqlparse (CVE-2024-4340). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.5.0` or later.
|
| CVE-2024-1183 |
|
Open Redirect in gradio (CVE-2024-1183)
vulnerability in gradio (CVE-2024-1183). Confidential information can be exposed externally. Mitigation: upgrade to `4.10.0` or later.
|
| CVE-2024-1135 |
|
Vulnerability in gunicorn (CVE-2024-1135)
vulnerability in gunicorn (CVE-2024-1135). Data can be tampered with by attackers. Mitigation: upgrade to `22.0.0` or later.
|
| CVE-2024-32005 |
|
Path Traversal in nicegui (CVE-2024-32005)
path traversal in nicegui (CVE-2024-32005). Confidential information can be exposed externally. Mitigation: upgrade to `1.4.21` or later.
|
| CVE-2024-2196 |
|
Cross-Site Request Forgery (CSRF) in aim (CVE-2024-2196)
vulnerability in aim (CVE-2024-2196). Successful exploitation can lead to full system takeover.
|
| CVE-2024-28718 |
|
Vulnerability in magnum (CVE-2024-28718)
vulnerability in magnum (CVE-2024-28718). Confidential information can be exposed externally. Mitigation: upgrade to `15.0.2` or later.
|
| CVE-2024-30265 |
|
Vulnerability in voila (CVE-2024-30265)
vulnerability in voila (CVE-2024-30265). Confidential information can be exposed externally. Exploitable via ``tornado.web.StaticFileHandler``. Mitigation: upgrade to `0.2.17` or later.
|
| CVE-2024-3568 |
|
Unsafe Deserialization in transformers (CVE-2024-3568)
vulnerability in transformers (CVE-2024-3568). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.38.0` or later.
|
| CVE-2024-30248 |
|
Cross-Site Scripting (XSS) in piccolo-admin (CVE-2024-30248)
cross-site scripting in piccolo-admin (CVE-2024-30248). Confidential information can be exposed externally. Exploitable via ``app.py``. Mitigation: upgrade to `1.3.2` or later.
|
| CVE-2024-22423 |
|
OS Command Injection in yt-dlp (CVE-2024-22423)
OS command injection in yt-dlp (CVE-2024-22423). Successful exploitation can lead to full system takeover. Exploitable via ``cmd.exe``. Mitigation: upgrade to `2024.04.09` or later.
|
| CVE-2024-3116 |
|
Command Injection in pgadmin4 (CVE-2024-3116)
command injection in pgadmin4 (CVE-2024-3116). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.5` or later.
|
| CVE-2024-31215 |
|
SSRF (Server-Side Request Forgery) in mobsf (CVE-2024-31215)
SSRF in mobsf (CVE-2024-31215). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.9.8` or later.
|
| CVE-2024-28732 |
|
Vulnerability in ryu (CVE-2024-28732)
vulnerability in ryu (CVE-2024-28732). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-29905 |
|
Vulnerability in dirac (CVE-2024-29905)
vulnerability in dirac (CVE-2024-29905). Confidential information can be exposed externally. Exploitable via ``X509_USER_PROXY``. Mitigation: upgrade to `8.0.41` or later.
|
| CVE-2024-1603 |
|
PaddlePaddle allows arbitrary file read via paddle.vision.ops.read_file
PaddlePaddle allows arbitrary file read via paddle.vision.ops.read_file
|
| CVE-2024-2206 |
|
SSRF (Server-Side Request Forgery) in gradio (CVE-2024-2206)
SSRF in gradio (CVE-2024-2206). Risk of unauthorized operations or information disclosure. Exploitable via ``self.replica_urls``. Mitigation: upgrade to `4.18.0` or later.
|
| CVE-2024-29199 |
|
Information Disclosure in nautobot (CVE-2024-29199)
vulnerability in nautobot (CVE-2024-29199). Risk of unauthorized operations or information disclosure. Exploitable via ``EXEMPT_VIEW_PERMISSIONS``. Mitigation: upgrade to `2.1.9` or later.
|
| CVE-2024-1455 |
|
Vulnerability in langchain-core (CVE-2024-1455)
vulnerability in langchain-core (CVE-2024-1455). Risk of unauthorized operations or information disclosure. Exploitable via ``XMLOutputParser``. Mitigation: upgrade to `0.1.35` or later.
|
| CVE-2024-29019 |
|
Cross-Site Request Forgery (CSRF) in esphome (CVE-2024-29019)
vulnerability in esphome (CVE-2024-29019). Confidential information can be exposed externally. Mitigation: upgrade to `2024.3.0` or later.
|
| CVE-2024-29189 |
|
OS Command Injection in ansys-geometry-core (CVE-2024-29189)
OS command injection in ansys-geometry-core (CVE-2024-29189). Successful exploitation can lead to full system takeover. Exploitable via ``args``. Mitigation: upgrade to `0.4.12` or later.
|
| CVE-2024-29156 |
|
Vulnerability in yaql (CVE-2024-29156)
vulnerability in yaql (CVE-2024-29156). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.0` or later.
|
| CVE-2024-29032 |
|
Unsafe Deserialization in qiskit-ibm-runtime (CVE-2024-29032)
vulnerability in qiskit-ibm-runtime (CVE-2024-29032). Risk of unauthorized operations or information disclosure. Exploitable via ``qiskit_ibm_runtime.RuntimeDecoder``. Mitigation: upgrade to `0.21.2` or later.
|
| CVE-2024-24770 |
|
Vulnerability in vantage6 (CVE-2024-24770)
vulnerability in vantage6 (CVE-2024-24770). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.3.0` or later.
|
| CVE-2024-28865 |
|
Vulnerability in wiki (CVE-2024-28865)
vulnerability in wiki (CVE-2024-28865). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.10.1` or later.
|
| CVE-2024-27097 |
|
Vulnerability in ckan (CVE-2024-27097)
vulnerability in ckan (CVE-2024-27097). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.10.4` or later.
|
| CVE-2024-22513 |
|
Privilege Escalation in djangorestframework-simplejwt (CVE-2024-22513)
vulnerability in djangorestframework-simplejwt (CVE-2024-22513). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.5.1` or later.
|
| CVE-2023-41334 |
|
Vulnerability in astropy (CVE-2023-41334)
vulnerability in astropy (CVE-2023-41334). Successful exploitation can lead to full system takeover. Exploitable via ``savelayout``. Mitigation: upgrade to `5.3.3` or later.
|
| CVE-2024-22889 |
|
Vulnerability in plone (CVE-2024-22889)
vulnerability in plone (CVE-2024-22889). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-0815 |
|
OS Command Injection in paddlepaddle (CVE-2024-0815)
OS command injection in paddlepaddle (CVE-2024-0815). Successful exploitation can lead to full system takeover.
|
| CVE-2024-28102 |
|
Vulnerability in jwcrypto (CVE-2024-28102)
vulnerability in jwcrypto (CVE-2024-28102). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.6` or later.
|
| CVE-2024-26164 |
|
Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server
Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server
|
| CVE-2024-0817 |
|
PaddlePaddle command injection vulnerability
PaddlePaddle command injection vulnerability
|
| CVE-2024-52288 |
|
Vulnerability in libosdp (CVE-2024-52288)
vulnerability in libosdp (CVE-2024-52288). Confidential information can be exposed externally. Mitigation: upgrade to `298576d9214b48214092eebdd892ec7` or later.
|
| CVE-2024-52296 |
|
Vulnerability in libosdp (CVE-2024-52296)
vulnerability in libosdp (CVE-2024-52296). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `24409e98a260176765956ec766a04cb` or later.
|
| CVE-2024-27287 |
|
Cross-Site Scripting (XSS) in esphome (CVE-2024-27287)
cross-site scripting in esphome (CVE-2024-27287). Confidential information can be exposed externally. Exploitable via `POST /edit`. Mitigation: upgrade to `2024.2.2` or later.
|
| CVE-2024-27081 |
|
Path Traversal in esphome (CVE-2024-27081)
path traversal in esphome (CVE-2024-27081). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2024.2.1` or later.
|
| CVE-2024-2319 |
|
Cross-Site Scripting (XSS) in django-markdownx (CVE-2024-2319)
cross-site scripting in django-markdownx (CVE-2024-2319). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-28184 |
|
Vulnerability in weasyprint (CVE-2024-28184)
vulnerability in weasyprint (CVE-2024-28184). Risk of unauthorized operations or information disclosure. Exploitable via ``url_fetcher``. Mitigation: upgrade to `61.2` or later.
|
| CVE-2024-25723 |
|
Vulnerability in zenml (CVE-2024-25723)
vulnerability in zenml (CVE-2024-25723). Data can be tampered with by attackers. Mitigation: upgrade to `0.44.4` or later.
|
| CVE-2024-27083 |
|
Cross-Site Scripting (XSS) in flask-appbuilder (CVE-2024-27083)
cross-site scripting in flask-appbuilder (CVE-2024-27083). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.2.1` or later.
|