Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2024-2206 |
|
SSRF (Server-Side Request Forgery) in gradio (CVE-2024-2206)
SSRF in gradio (CVE-2024-2206). Risk of unauthorized operations or information disclosure. Exploitable via ``self.replica_urls``. Mitigation: upgrade to `4.18.0` or later.
|
| CVE-2024-29199 |
|
Information Disclosure in nautobot (CVE-2024-29199)
vulnerability in nautobot (CVE-2024-29199). Risk of unauthorized operations or information disclosure. Exploitable via ``EXEMPT_VIEW_PERMISSIONS``. Mitigation: upgrade to `2.1.9` or later.
|
| CVE-2024-1455 |
|
Vulnerability in langchain-core (CVE-2024-1455)
vulnerability in langchain-core (CVE-2024-1455). Risk of unauthorized operations or information disclosure. Exploitable via ``XMLOutputParser``. Mitigation: upgrade to `0.1.35` or later.
|
| CVE-2024-29019 |
|
Cross-Site Request Forgery (CSRF) in esphome (CVE-2024-29019)
vulnerability in esphome (CVE-2024-29019). Confidential information can be exposed externally. Mitigation: upgrade to `2024.3.0` or later.
|
| CVE-2024-29189 |
|
OS Command Injection in ansys-geometry-core (CVE-2024-29189)
OS command injection in ansys-geometry-core (CVE-2024-29189). Successful exploitation can lead to full system takeover. Exploitable via ``args``. Mitigation: upgrade to `0.4.12` or later.
|
| CVE-2024-29156 |
|
Vulnerability in yaql (CVE-2024-29156)
vulnerability in yaql (CVE-2024-29156). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.0` or later.
|
| CVE-2024-29032 |
|
Unsafe Deserialization in qiskit-ibm-runtime (CVE-2024-29032)
vulnerability in qiskit-ibm-runtime (CVE-2024-29032). Risk of unauthorized operations or information disclosure. Exploitable via ``qiskit_ibm_runtime.RuntimeDecoder``. Mitigation: upgrade to `0.21.2` or later.
|
| CVE-2024-24770 |
|
Vulnerability in vantage6 (CVE-2024-24770)
vulnerability in vantage6 (CVE-2024-24770). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.3.0` or later.
|
| CVE-2024-28865 |
|
Vulnerability in wiki (CVE-2024-28865)
vulnerability in wiki (CVE-2024-28865). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.10.1` or later.
|
| CVE-2024-27097 |
|
Vulnerability in ckan (CVE-2024-27097)
vulnerability in ckan (CVE-2024-27097). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.10.4` or later.
|
| CVE-2024-22513 |
|
Privilege Escalation in djangorestframework-simplejwt (CVE-2024-22513)
vulnerability in djangorestframework-simplejwt (CVE-2024-22513). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.5.1` or later.
|
| CVE-2023-41334 |
|
Vulnerability in astropy (CVE-2023-41334)
vulnerability in astropy (CVE-2023-41334). Successful exploitation can lead to full system takeover. Exploitable via ``savelayout``. Mitigation: upgrade to `5.3.3` or later.
|
| CVE-2024-22889 |
|
Vulnerability in plone (CVE-2024-22889)
vulnerability in plone (CVE-2024-22889). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-0815 |
|
OS Command Injection in paddlepaddle (CVE-2024-0815)
OS command injection in paddlepaddle (CVE-2024-0815). Successful exploitation can lead to full system takeover.
|
| CVE-2024-28102 |
|
Vulnerability in jwcrypto (CVE-2024-28102)
vulnerability in jwcrypto (CVE-2024-28102). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.6` or later.
|
| CVE-2024-26164 |
|
Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server
Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server
|
| CVE-2024-0817 |
|
PaddlePaddle command injection vulnerability
PaddlePaddle command injection vulnerability
|
| CVE-2024-52288 |
|
Vulnerability in libosdp (CVE-2024-52288)
vulnerability in libosdp (CVE-2024-52288). Confidential information can be exposed externally. Mitigation: upgrade to `298576d9214b48214092eebdd892ec7` or later.
|
| CVE-2024-52296 |
|
Vulnerability in libosdp (CVE-2024-52296)
vulnerability in libosdp (CVE-2024-52296). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `24409e98a260176765956ec766a04cb` or later.
|
| CVE-2024-27287 |
|
Cross-Site Scripting (XSS) in esphome (CVE-2024-27287)
cross-site scripting in esphome (CVE-2024-27287). Confidential information can be exposed externally. Exploitable via `POST /edit`. Mitigation: upgrade to `2024.2.2` or later.
|
| CVE-2024-27081 |
|
Path Traversal in esphome (CVE-2024-27081)
path traversal in esphome (CVE-2024-27081). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2024.2.1` or later.
|
| CVE-2024-2319 |
|
Cross-Site Scripting (XSS) in django-markdownx (CVE-2024-2319)
cross-site scripting in django-markdownx (CVE-2024-2319). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-28184 |
|
Vulnerability in weasyprint (CVE-2024-28184)
vulnerability in weasyprint (CVE-2024-28184). Risk of unauthorized operations or information disclosure. Exploitable via ``url_fetcher``. Mitigation: upgrade to `61.2` or later.
|
| CVE-2024-25723 |
|
Vulnerability in zenml (CVE-2024-25723)
vulnerability in zenml (CVE-2024-25723). Data can be tampered with by attackers. Mitigation: upgrade to `0.44.4` or later.
|
| CVE-2024-27083 |
|
Cross-Site Scripting (XSS) in flask-appbuilder (CVE-2024-27083)
cross-site scripting in flask-appbuilder (CVE-2024-27083). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.2.1` or later.
|
| CVE-2024-25169 |
|
Vulnerability in mezzanine (CVE-2024-25169)
vulnerability in mezzanine (CVE-2024-25169). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-25170 |
|
Vulnerability in mezzanine (CVE-2024-25170)
vulnerability in mezzanine (CVE-2024-25170). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`.
|
| CVE-2024-27290 |
|
Cross-Site Scripting (XSS) in docassemble-webapp (CVE-2024-27290)
cross-site scripting in docassemble-webapp (CVE-2024-27290). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.4.97` or later.
|
| CVE-2024-27291 |
|
Open Redirect in docassemble-webapp (CVE-2024-27291)
vulnerability in docassemble-webapp (CVE-2024-27291). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.4.97` or later.
|
| CVE-2024-24808 |
|
Open Redirect in pyload-ng (CVE-2024-24808)
vulnerability in pyload-ng (CVE-2024-24808). Risk of unauthorized operations or information disclosure. Exploitable via ``get_redirect_url``. Mitigation: upgrade to `0.5.0b3.dev79` or later.
|
| CVE-2024-3572 |
|
Vulnerability in scrapy (CVE-2024-3572)
vulnerability in scrapy (CVE-2024-3572). Risk of unauthorized operations or information disclosure. Exploitable via ``DOWNLOAD_MAXSIZE``. Mitigation: upgrade to `1.8.4` or later.
|
| CVE-2024-3574 |
|
Information Disclosure in scrapy (CVE-2024-3574)
vulnerability in scrapy (CVE-2024-3574). Confidential information can be exposed externally. Exploitable via ``Authorization``. Mitigation: upgrade to `1.8.4` or later.
|
| CVE-2024-26151 |
|
Vulnerability in mjml (CVE-2024-26151)
vulnerability in mjml (CVE-2024-26151). Data can be tampered with by attackers. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2024-1729 |
|
Vulnerability in gradio (CVE-2024-1729)
vulnerability in gradio (CVE-2024-1729). Confidential information can be exposed externally. Mitigation: upgrade to `4.19.2` or later.
|
| CVE-2023-50782 |
|
Vulnerability in cryptography (CVE-2023-50782)
vulnerability in cryptography (CVE-2023-50782). Confidential information can be exposed externally. Mitigation: upgrade to `42.0.0` or later.
|
| CVE-2024-24590 |
|
Unsafe Deserialization in clearml (CVE-2024-24590)
vulnerability in clearml (CVE-2024-24590). Successful exploitation can lead to full system takeover.
|
| CVE-2024-24591 |
|
Path Traversal in clearml (CVE-2024-24591)
path traversal in clearml (CVE-2024-24591). Successful exploitation can lead to full system takeover.
|
| CVE-2024-24595 |
|
Vulnerability in clearml (CVE-2024-24595)
vulnerability in clearml (CVE-2024-24595). Confidential information can be exposed externally.
|
| CVE-2024-1314 |
|
Vulnerability in kinto-attachment (CVE-2024-1314)
vulnerability in kinto-attachment (CVE-2024-1314). Data can be tampered with by attackers. Mitigation: upgrade to `6.4.0` or later.
|
| CVE-2024-1141 |
|
Vulnerability in glance-store (CVE-2024-1141)
vulnerability in glance-store (CVE-2024-1141). Confidential information can be exposed externally.
|
| CVE-2024-0960 |
|
Unsafe Deserialization in ai-flow (CVE-2024-0960)
vulnerability in ai-flow (CVE-2024-0960). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-6395 |
|
Vulnerability in templated-dictionary (CVE-2023-6395)
vulnerability in templated-dictionary (CVE-2023-6395). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.4.1` or later.
|
| CVE-2024-0669 |
|
Vulnerability in plone (CVE-2024-0669)
vulnerability in plone (CVE-2024-0669). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.0.7` or later.
|
| CVE-2023-52288 |
|
Path Traversal in flaskcode (CVE-2023-52288)
path traversal in flaskcode (CVE-2023-52288). Confidential information can be exposed externally.
|
| CVE-2023-52289 |
|
Path Traversal in flaskcode (CVE-2023-52289)
path traversal in flaskcode (CVE-2023-52289). Data can be tampered with by attackers.
|
| CVE-2024-23342 |
|
Vulnerability in ecdsa (CVE-2024-23342)
vulnerability in ecdsa (CVE-2024-23342). Confidential information can be exposed externally.
|
| CVE-2024-22415 |
|
Path Traversal in jupyter-lsp (CVE-2024-22415)
path traversal in jupyter-lsp (CVE-2024-22415). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.2.2` or later.
|
| CVE-2024-21645 |
|
Vulnerability in pyload-ng (CVE-2024-21645)
vulnerability in pyload-ng (CVE-2024-21645). Risk of unauthorized operations or information disclosure. Exploitable via ``pyload``. Mitigation: upgrade to `0.5.0b3.dev77` or later.
|
| CVE-2024-21644 |
|
Vulnerability in pyload-ng (CVE-2024-21644)
vulnerability in pyload-ng (CVE-2024-21644). Confidential information can be exposed externally. Exploitable via ``SECRET_KEY``. Mitigation: upgrade to `0.5.0b3.dev77` or later.
|
| CVE-2023-45139 |
|
XXE (XML External Entity) in fonttools (CVE-2023-45139)
vulnerability in fonttools (CVE-2023-45139). Confidential information can be exposed externally. Mitigation: upgrade to `4.43.0` or later.
|