Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2024-25169 |
|
Vulnerability in mezzanine (CVE-2024-25169)
vulnerability in mezzanine (CVE-2024-25169). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-25170 |
|
Vulnerability in mezzanine (CVE-2024-25170)
vulnerability in mezzanine (CVE-2024-25170). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`.
|
| CVE-2024-27290 |
|
Cross-Site Scripting (XSS) in docassemble-webapp (CVE-2024-27290)
cross-site scripting in docassemble-webapp (CVE-2024-27290). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.4.97` or later.
|
| CVE-2024-27291 |
|
Open Redirect in docassemble-webapp (CVE-2024-27291)
vulnerability in docassemble-webapp (CVE-2024-27291). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.4.97` or later.
|
| CVE-2024-24808 |
|
Open Redirect in pyload-ng (CVE-2024-24808)
vulnerability in pyload-ng (CVE-2024-24808). Risk of unauthorized operations or information disclosure. Exploitable via ``get_redirect_url``. Mitigation: upgrade to `0.5.0b3.dev79` or later.
|
| CVE-2024-3572 |
|
Vulnerability in scrapy (CVE-2024-3572)
vulnerability in scrapy (CVE-2024-3572). Risk of unauthorized operations or information disclosure. Exploitable via ``DOWNLOAD_MAXSIZE``. Mitigation: upgrade to `1.8.4` or later.
|
| CVE-2024-3574 |
|
Information Disclosure in scrapy (CVE-2024-3574)
vulnerability in scrapy (CVE-2024-3574). Confidential information can be exposed externally. Exploitable via ``Authorization``. Mitigation: upgrade to `1.8.4` or later.
|
| CVE-2024-26151 |
|
Vulnerability in mjml (CVE-2024-26151)
vulnerability in mjml (CVE-2024-26151). Data can be tampered with by attackers. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2024-1729 |
|
Vulnerability in gradio (CVE-2024-1729)
vulnerability in gradio (CVE-2024-1729). Confidential information can be exposed externally. Mitigation: upgrade to `4.19.2` or later.
|
| CVE-2023-50782 |
|
Vulnerability in cryptography (CVE-2023-50782)
vulnerability in cryptography (CVE-2023-50782). Confidential information can be exposed externally. Mitigation: upgrade to `42.0.0` or later.
|
| CVE-2024-24590 |
|
Unsafe Deserialization in clearml (CVE-2024-24590)
vulnerability in clearml (CVE-2024-24590). Successful exploitation can lead to full system takeover.
|
| CVE-2024-24591 |
|
Path Traversal in clearml (CVE-2024-24591)
path traversal in clearml (CVE-2024-24591). Successful exploitation can lead to full system takeover.
|
| CVE-2024-24595 |
|
Vulnerability in clearml (CVE-2024-24595)
vulnerability in clearml (CVE-2024-24595). Confidential information can be exposed externally.
|
| CVE-2024-1314 |
|
Vulnerability in kinto-attachment (CVE-2024-1314)
vulnerability in kinto-attachment (CVE-2024-1314). Data can be tampered with by attackers. Mitigation: upgrade to `6.4.0` or later.
|
| CVE-2024-1141 |
|
Vulnerability in glance-store (CVE-2024-1141)
vulnerability in glance-store (CVE-2024-1141). Confidential information can be exposed externally.
|
| CVE-2024-0960 |
|
Unsafe Deserialization in ai-flow (CVE-2024-0960)
vulnerability in ai-flow (CVE-2024-0960). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-6395 |
|
Vulnerability in templated-dictionary (CVE-2023-6395)
vulnerability in templated-dictionary (CVE-2023-6395). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.4.1` or later.
|
| CVE-2024-0669 |
|
Vulnerability in plone (CVE-2024-0669)
vulnerability in plone (CVE-2024-0669). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.0.7` or later.
|
| CVE-2023-52288 |
|
Path Traversal in flaskcode (CVE-2023-52288)
path traversal in flaskcode (CVE-2023-52288). Confidential information can be exposed externally.
|
| CVE-2023-52289 |
|
Path Traversal in flaskcode (CVE-2023-52289)
path traversal in flaskcode (CVE-2023-52289). Data can be tampered with by attackers.
|
| CVE-2024-23342 |
|
Vulnerability in ecdsa (CVE-2024-23342)
vulnerability in ecdsa (CVE-2024-23342). Confidential information can be exposed externally.
|
| CVE-2024-22415 |
|
Path Traversal in jupyter-lsp (CVE-2024-22415)
path traversal in jupyter-lsp (CVE-2024-22415). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.2.2` or later.
|
| CVE-2024-21645 |
|
Vulnerability in pyload-ng (CVE-2024-21645)
vulnerability in pyload-ng (CVE-2024-21645). Risk of unauthorized operations or information disclosure. Exploitable via ``pyload``. Mitigation: upgrade to `0.5.0b3.dev77` or later.
|
| CVE-2024-21644 |
|
Vulnerability in pyload-ng (CVE-2024-21644)
vulnerability in pyload-ng (CVE-2024-21644). Confidential information can be exposed externally. Exploitable via ``SECRET_KEY``. Mitigation: upgrade to `0.5.0b3.dev77` or later.
|
| CVE-2023-45139 |
|
XXE (XML External Entity) in fonttools (CVE-2023-45139)
vulnerability in fonttools (CVE-2023-45139). Confidential information can be exposed externally. Mitigation: upgrade to `4.43.0` or later.
|
| CVE-2024-21642 |
|
SSRF (Server-Side Request Forgery) in dtale (CVE-2024-21642)
SSRF in dtale (CVE-2024-21642). Confidential information can be exposed externally. Mitigation: upgrade to `3.9.0` or later.
|
| CVE-2024-22195 |
|
Cross-Site Scripting (XSS) in jinja2 (CVE-2024-22195)
cross-site scripting in jinja2 (CVE-2024-22195). Risk of unauthorized operations or information disclosure. Exploitable via ``xmlattr``. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2023-50715 |
|
Information Disclosure in homeassistant (CVE-2023-50715)
vulnerability in homeassistant (CVE-2023-50715). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2023.12.3` or later.
|
| CVE-2023-50248 |
|
Vulnerability in ckan (CVE-2023-50248)
vulnerability in ckan (CVE-2023-50248). Risk of unauthorized operations or information disclosure. Exploitable via ``Authorization``. Mitigation: upgrade to `2.10.3` or later.
|
| CVE-2023-35625 |
|
Exposure of Sensitive Information in mltable
Exposure of Sensitive Information in mltable
|
| CVE-2023-49277 |
|
Cross-Site Scripting (XSS) in dpaste (CVE-2023-49277)
cross-site scripting in dpaste (CVE-2023-49277). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.8` or later.
|
| CVE-2023-48311 |
|
Vulnerability in dockerspawner (CVE-2023-48311)
vulnerability in dockerspawner (CVE-2023-48311). Risk of unauthorized operations or information disclosure. Exploitable via ``DockerSpawner.allowed_images``. Mitigation: upgrade to `13.0.0` or later.
|
| CVE-2023-48299 |
|
Path Traversal in torchserve (CVE-2023-48299)
path traversal in torchserve (CVE-2023-48299). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2023-6022 |
|
Cross-Site Request Forgery (CSRF) in prefect (CVE-2023-6022)
vulnerability in prefect (CVE-2023-6022). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.16.5` or later.
|
| CVE-2023-48224 |
|
Vulnerability in ethyca-fides (CVE-2023-48224)
vulnerability in ethyca-fides (CVE-2023-48224). Risk of unauthorized operations or information disclosure. Exploitable via ``subject_identity_verification_required``. Mitigation: upgrade to `2.24.0` or later.
|
| CVE-2023-46121 |
|
Vulnerability in yt-dlp (CVE-2023-46121)
vulnerability in yt-dlp (CVE-2023-46121). Risk of unauthorized operations or information disclosure. Exploitable via ``Referer``. Mitigation: upgrade to `2023.11.14` or later.
|
| CVE-2023-46250 |
|
Vulnerability in pypdf (CVE-2023-46250)
vulnerability in pypdf (CVE-2023-46250). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.17.0` or later.
|
| CVE-2023-32786 |
|
Vulnerability in langchain (CVE-2023-32786)
vulnerability in langchain (CVE-2023-32786). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.329` or later.
|
| CVE-2023-47114 |
|
Cross-Site Scripting (XSS) in ethyca-fides (CVE-2023-47114)
cross-site scripting in ethyca-fides (CVE-2023-47114). Risk of unauthorized operations or information disclosure. Exploitable via ``TBC``. Mitigation: upgrade to `2.23.3` or later.
|
| CVE-2023-46134 |
|
Cross-Site Scripting (XSS) in dtale (CVE-2023-46134)
cross-site scripting in dtale (CVE-2023-46134). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.7.0` or later.
|
| CVE-2023-5189 |
|
Path Traversal in galaxy-importer (CVE-2023-5189)
path traversal in galaxy-importer (CVE-2023-5189). Data can be tampered with by attackers.
|
| CVE-2023-46125 |
|
Information Disclosure in ethyca-fides (CVE-2023-46125)
vulnerability in ethyca-fides (CVE-2023-46125). Confidential information can be exposed externally. Mitigation: upgrade to `2.22.1` or later.
|
| CVE-2023-46124 |
|
SSRF (Server-Side Request Forgery) in ethyca-fides (CVE-2023-46124)
SSRF in ethyca-fides (CVE-2023-46124). Confidential information can be exposed externally. Exploitable via ``CONNECTOR_TEMPLATE_REGISTER``. Mitigation: upgrade to `2.22.1` or later.
|
| CVE-2023-46126 |
|
Cross-Site Scripting (XSS) in ethyca-fides (CVE-2023-46126)
cross-site scripting in ethyca-fides (CVE-2023-46126). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.22.1` or later.
|
| CVE-2023-44464 |
|
pretix allows Pillow to parse EPS files
pretix allows Pillow to parse EPS files
|
| CVE-2023-45813 |
|
Vulnerability in torbot (CVE-2023-45813)
vulnerability in torbot (CVE-2023-45813). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.0.0` or later.
|
| CVE-2023-40581 |
|
OS Command Injection in yt-dlp (CVE-2023-40581)
OS command injection in yt-dlp (CVE-2023-40581). Successful exploitation can lead to full system takeover. Exploitable via ``cmd``. Mitigation: upgrade to `2023.09.24` or later.
|
| CVE-2023-45805 |
|
Vulnerability in pdm (CVE-2023-45805)
vulnerability in pdm (CVE-2023-45805). Successful exploitation can lead to full system takeover. Exploitable via ``pdm.lock``.
|
| CVE-2023-36566 |
|
Microsoft Common Data Model SDK Denial of Service Vulnerability
Microsoft Common Data Model SDK Denial of Service Vulnerability
|
| CVE-2023-4570 |
|
Vulnerability in ni-measurementlink-service (CVE-2023-4570)
vulnerability in ni-measurementlink-service (CVE-2023-4570). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.2.0` or later.
|