Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2024-10550 |
|
Vulnerability in h2o (CVE-2024-10550)
vulnerability in h2o (CVE-2024-10550). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-10572 |
|
Vulnerability in h2o (CVE-2024-10572)
vulnerability in h2o (CVE-2024-10572). Risk of unauthorized operations or information disclosure. Exploitable via ``run_tool``.
|
| CVE-2025-27154 |
|
Vulnerability in spotipy (CVE-2025-27154)
vulnerability in spotipy (CVE-2025-27154). Risk of unauthorized operations or information disclosure. Exploitable via ``CacheHandler``. Mitigation: upgrade to `2.25.1` or later.
|
| CVE-2025-26623 |
|
Use-After-Free in exiv2 (CVE-2025-26623)
vulnerability in exiv2 (CVE-2025-26623). Risk of unauthorized operations or information disclosure. Exploitable via ``fixiso``. Mitigation: upgrade to `0.28.5` or later.
|
| CVE-2025-1300 |
|
Open Redirect in codechecker (CVE-2025-1300)
vulnerability in codechecker (CVE-2025-1300). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.24.6` or later.
|
| CVE-2025-27145 |
|
Cross-Site Scripting (XSS) in copyparty (CVE-2025-27145)
cross-site scripting in copyparty (CVE-2025-27145). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.16.15` or later.
|
| CVE-2025-25362 |
|
Vulnerability in spacy-llm (CVE-2025-25362)
vulnerability in spacy-llm (CVE-2025-25362). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.7.3` or later.
|
| CVE-2025-27516 |
|
Vulnerability in jinja2 (CVE-2025-27516)
vulnerability in jinja2 (CVE-2025-27516). Risk of unauthorized operations or information disclosure. Exploitable via ``str.format``. Mitigation: upgrade to `3.1.6` or later.
|
| CVE-2024-27763 |
|
Command Injection in basicsr (CVE-2024-27763)
command injection in basicsr (CVE-2024-27763). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-27018 |
|
SQL Injection in apache-airflow-providers-mysql (CVE-2025-27018)
SQL injection in apache-airflow-providers-mysql (CVE-2025-27018). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.2.0` or later.
|
| CVE-2025-25305 |
|
Vulnerability in homeassistant (CVE-2025-25305)
vulnerability in homeassistant (CVE-2025-25305). Confidential information can be exposed externally. Exploitable via ``request``. Mitigation: upgrade to `2024.1.6` or later.
|
| CVE-2024-12797 |
|
Vulnerability in cryptography (CVE-2024-12797)
vulnerability in cryptography (CVE-2024-12797). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `44.0.1` or later.
|
| CVE-2025-24372 |
|
Cross-Site Scripting (XSS) in ckan (CVE-2025-24372)
cross-site scripting in ckan (CVE-2025-24372). Confidential information can be exposed externally. Mitigation: upgrade to `2.11.2` or later.
|
| CVE-2025-24804 |
|
Vulnerability in mobsf (CVE-2025-24804)
vulnerability in mobsf (CVE-2025-24804). Risk of unauthorized operations or information disclosure. Exploitable via ``Info.plist``. Mitigation: upgrade to `4.3.1` or later.
|
| CVE-2025-25296 |
|
Cross-Site Scripting (XSS) in label-studio (CVE-2025-25296)
cross-site scripting in label-studio (CVE-2025-25296). Risk of unauthorized operations or information disclosure. Exploitable via ``GET``. Mitigation: upgrade to `1.16.0` or later.
|
| CVE-2025-25297 |
|
SSRF (Server-Side Request Forgery) in label-studio (CVE-2025-25297)
SSRF in label-studio (CVE-2025-25297). Confidential information can be exposed externally. Mitigation: upgrade to `1.16.0` or later.
|
| CVE-2025-25295 |
|
Path Traversal in label-studio-sdk (CVE-2025-25295)
path traversal in label-studio-sdk (CVE-2025-25295). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/projects/1/export`. Mitigation: upgrade to `1.0.10` or later.
|
| CVE-2025-24359 |
|
Vulnerability in asteval (CVE-2025-24359)
vulnerability in asteval (CVE-2025-24359). Successful exploitation can lead to full system takeover. Exploitable via ``asteval``. Mitigation: upgrade to `1.0.6` or later.
|
| CVE-2025-23205 |
|
Vulnerability in nbgrader (CVE-2025-23205)
vulnerability in nbgrader (CVE-2025-23205). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.5` or later.
|
| CVE-2025-24803 |
|
Cross-Site Scripting (XSS) in mobsf (CVE-2025-24803)
cross-site scripting in mobsf (CVE-2025-24803). Confidential information can be exposed externally. Exploitable via ``dynamic_analysis.html``. Mitigation: upgrade to `4.3.1` or later.
|
| CVE-2025-24805 |
|
Privilege Escalation in mobsf (CVE-2025-24805)
vulnerability in mobsf (CVE-2025-24805). Confidential information can be exposed externally. Mitigation: upgrade to `4.3.1` or later.
|
| CVE-2025-23217 |
|
Vulnerability in mitmproxy (CVE-2025-23217)
vulnerability in mitmproxy (CVE-2025-23217). Risk of unauthorized operations or information disclosure. Exploitable via ``block_global``. Mitigation: upgrade to `11.1.2` or later.
|
| CVE-2025-22153 |
|
Vulnerability in restrictedpython (CVE-2025-22153)
vulnerability in restrictedpython (CVE-2025-22153). Confidential information can be exposed externally. Mitigation: upgrade to `8.0` or later.
|
| CVE-2025-22151 |
|
Vulnerability in strawberry-graphql (CVE-2025-22151)
vulnerability in strawberry-graphql (CVE-2025-22151). Risk of unauthorized operations or information disclosure. Exploitable via ``node``. Mitigation: upgrade to `0.257.0` or later.
|
| CVE-2024-53995 |
|
Open Redirect in sickchill (CVE-2024-53995)
vulnerability in sickchill (CVE-2024-53995). Risk of unauthorized operations or information disclosure. Exploitable via ``login``.
|
| CVE-2024-50633 |
|
Vulnerability in indico (CVE-2024-50633)
vulnerability in indico (CVE-2024-50633). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.3` or later.
|
| CVE-2024-56509 |
|
Information Disclosure in changedetection-io (CVE-2024-56509)
vulnerability in changedetection-io (CVE-2024-56509). Confidential information can be exposed externally. Mitigation: upgrade to `0.48.05` or later.
|
| CVE-2023-1907 |
|
Vulnerability in pgadmin4 (CVE-2023-1907)
vulnerability in pgadmin4 (CVE-2023-1907). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.0` or later.
|
| CVE-2025-21618 |
|
Authentication Bypass in nicegui (CVE-2025-21618)
authentication bypass in nicegui (CVE-2025-21618). Data can be tampered with by attackers. Mitigation: upgrade to `2.9.1` or later.
|
| CVE-2024-39025 |
|
Authorization Flaw in letta (CVE-2024-39025)
vulnerability in letta (CVE-2024-39025). Confidential information can be exposed externally.
|
| CVE-2024-52294 |
|
Vulnerability in khoj (CVE-2024-52294)
vulnerability in khoj (CVE-2024-52294). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /api/subscription`. Mitigation: upgrade to `1.29.0` or later.
|
| CVE-2024-45033 |
|
Vulnerability in apache-airflow-providers-fab (CVE-2024-45033)
vulnerability in apache-airflow-providers-fab (CVE-2024-45033). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.2` or later.
|
| CVE-2024-55655 |
|
Vulnerability in sigstore (CVE-2024-55655)
vulnerability in sigstore (CVE-2024-55655). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.0` or later.
|
| CVE-2024-9774 |
|
A vulnerability was found in python-sql where unary operators do not escape non-Expression.
python-sql SQL injection vulnerability
|
| CVE-2024-56142 |
|
Path Traversal in pghoard (CVE-2024-56142)
path traversal in pghoard (CVE-2024-56142). Confidential information can be exposed externally. Mitigation: upgrade to `2.6.1-rc` or later.
|
| CVE-2024-55587 |
|
Path Traversal in python-libarchive (CVE-2024-55587)
path traversal in python-libarchive (CVE-2024-55587). Successful exploitation can lead to full system takeover.
|
| CVE-2024-12745 |
|
SQL Injection in redshift-connector (CVE-2024-12745)
SQL injection in redshift-connector (CVE-2024-12745). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.1.5` or later.
|
| CVE-2024-9427 |
|
Vulnerability in koji (CVE-2024-9427)
vulnerability in koji (CVE-2024-9427). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.33.2` or later.
|
| CVE-2024-56327 |
|
Vulnerability in pyrage (CVE-2024-56327)
vulnerability in pyrage (CVE-2024-56327). Successful exploitation can lead to full system takeover. Exploitable via ``pyrage``. Mitigation: upgrade to `1.2.3` or later.
|
| CVE-2024-56201 |
|
Vulnerability in jinja2 (CVE-2024-56201)
vulnerability in jinja2 (CVE-2024-56201). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.1.5` or later.
|
| CVE-2024-55890 |
|
Cross-Site Scripting (XSS) in dtale (CVE-2024-55890)
cross-site scripting in dtale (CVE-2024-55890). Risk of unauthorized operations or information disclosure. Exploitable via ``enable_custom_filters``. Mitigation: upgrade to `3.16.1` or later.
|
| CVE-2024-56326 |
|
Vulnerability in jinja2 (CVE-2024-56326)
vulnerability in jinja2 (CVE-2024-56326). Successful exploitation can lead to full system takeover. Exploitable via ``str.format``. Mitigation: upgrade to `3.1.5` or later.
|
| CVE-2024-53865 |
|
Vulnerability in zhmcclient (CVE-2024-53865)
vulnerability in zhmcclient (CVE-2024-53865). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.18.1` or later.
|
| CVE-2024-53981 |
|
Vulnerability in python-multipart (CVE-2024-53981)
vulnerability in python-multipart (CVE-2024-53981). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.0.18` or later.
|
| CVE-2024-53861 |
|
Vulnerability in pyjwt (CVE-2024-53861)
vulnerability in pyjwt (CVE-2024-53861). Risk of unauthorized operations or information disclosure. Exploitable via ``iss``. Mitigation: upgrade to `2.10.1` or later.
|
| CVE-2024-39163 |
|
Cross-Site Request Forgery (CSRF) in pyspider (CVE-2024-39163)
vulnerability in pyspider (CVE-2024-39163). Successful exploitation can lead to full system takeover.
|
| CVE-2024-53999 |
|
Cross-Site Scripting (XSS) in mobsf (CVE-2024-53999)
cross-site scripting in mobsf (CVE-2024-53999). Confidential information can be exposed externally. Exploitable via ``test.zip``. Mitigation: upgrade to `4.2.9` or later.
|
| CVE-2024-52815 |
|
Vulnerability in matrix-synapse (CVE-2024-52815)
vulnerability in matrix-synapse (CVE-2024-52815). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.120.1` or later.
|
| CVE-2024-53867 |
|
Vulnerability in matrix-synapse (CVE-2024-53867)
vulnerability in matrix-synapse (CVE-2024-53867). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.120.1` or later.
|
| CVE-2024-53863 |
|
Unrestricted File Upload in matrix-synapse (CVE-2024-53863)
vulnerability in matrix-synapse (CVE-2024-53863). Risk of unauthorized operations or information disclosure. Exploitable via ``dynamic_thumbnails``. Mitigation: upgrade to `1.120.1` or later.
|