Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2024-21642 |
|
SSRF (Server-Side Request Forgery) in dtale (CVE-2024-21642)
SSRF in dtale (CVE-2024-21642). Confidential information can be exposed externally. Mitigation: upgrade to `3.9.0` or later.
|
| CVE-2024-22195 |
|
Cross-Site Scripting (XSS) in jinja2 (CVE-2024-22195)
cross-site scripting in jinja2 (CVE-2024-22195). Risk of unauthorized operations or information disclosure. Exploitable via ``xmlattr``. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2023-50715 |
|
Information Disclosure in homeassistant (CVE-2023-50715)
vulnerability in homeassistant (CVE-2023-50715). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2023.12.3` or later.
|
| CVE-2023-50248 |
|
Vulnerability in ckan (CVE-2023-50248)
vulnerability in ckan (CVE-2023-50248). Risk of unauthorized operations or information disclosure. Exploitable via ``Authorization``. Mitigation: upgrade to `2.10.3` or later.
|
| CVE-2023-35625 |
|
Exposure of Sensitive Information in mltable
Exposure of Sensitive Information in mltable
|
| CVE-2023-49277 |
|
Cross-Site Scripting (XSS) in dpaste (CVE-2023-49277)
cross-site scripting in dpaste (CVE-2023-49277). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.8` or later.
|
| CVE-2023-48311 |
|
Vulnerability in dockerspawner (CVE-2023-48311)
vulnerability in dockerspawner (CVE-2023-48311). Risk of unauthorized operations or information disclosure. Exploitable via ``DockerSpawner.allowed_images``. Mitigation: upgrade to `13.0.0` or later.
|
| CVE-2023-48299 |
|
Path Traversal in torchserve (CVE-2023-48299)
path traversal in torchserve (CVE-2023-48299). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2023-6022 |
|
Cross-Site Request Forgery (CSRF) in prefect (CVE-2023-6022)
vulnerability in prefect (CVE-2023-6022). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.16.5` or later.
|
| CVE-2023-48224 |
|
Vulnerability in ethyca-fides (CVE-2023-48224)
vulnerability in ethyca-fides (CVE-2023-48224). Risk of unauthorized operations or information disclosure. Exploitable via ``subject_identity_verification_required``. Mitigation: upgrade to `2.24.0` or later.
|
| CVE-2023-46121 |
|
Vulnerability in yt-dlp (CVE-2023-46121)
vulnerability in yt-dlp (CVE-2023-46121). Risk of unauthorized operations or information disclosure. Exploitable via ``Referer``. Mitigation: upgrade to `2023.11.14` or later.
|
| CVE-2023-46250 |
|
Vulnerability in pypdf (CVE-2023-46250)
vulnerability in pypdf (CVE-2023-46250). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.17.0` or later.
|
| CVE-2023-32786 |
|
Vulnerability in langchain (CVE-2023-32786)
vulnerability in langchain (CVE-2023-32786). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.329` or later.
|
| CVE-2023-47114 |
|
Cross-Site Scripting (XSS) in ethyca-fides (CVE-2023-47114)
cross-site scripting in ethyca-fides (CVE-2023-47114). Risk of unauthorized operations or information disclosure. Exploitable via ``TBC``. Mitigation: upgrade to `2.23.3` or later.
|
| CVE-2023-46134 |
|
Cross-Site Scripting (XSS) in dtale (CVE-2023-46134)
cross-site scripting in dtale (CVE-2023-46134). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.7.0` or later.
|
| CVE-2023-5189 |
|
Path Traversal in galaxy-importer (CVE-2023-5189)
path traversal in galaxy-importer (CVE-2023-5189). Data can be tampered with by attackers.
|
| CVE-2023-46125 |
|
Information Disclosure in ethyca-fides (CVE-2023-46125)
vulnerability in ethyca-fides (CVE-2023-46125). Confidential information can be exposed externally. Mitigation: upgrade to `2.22.1` or later.
|
| CVE-2023-46124 |
|
SSRF (Server-Side Request Forgery) in ethyca-fides (CVE-2023-46124)
SSRF in ethyca-fides (CVE-2023-46124). Confidential information can be exposed externally. Exploitable via ``CONNECTOR_TEMPLATE_REGISTER``. Mitigation: upgrade to `2.22.1` or later.
|
| CVE-2023-46126 |
|
Cross-Site Scripting (XSS) in ethyca-fides (CVE-2023-46126)
cross-site scripting in ethyca-fides (CVE-2023-46126). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.22.1` or later.
|
| CVE-2023-44464 |
|
pretix allows Pillow to parse EPS files
pretix allows Pillow to parse EPS files
|
| CVE-2023-45813 |
|
Vulnerability in torbot (CVE-2023-45813)
vulnerability in torbot (CVE-2023-45813). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.0.0` or later.
|
| CVE-2023-40581 |
|
OS Command Injection in yt-dlp (CVE-2023-40581)
OS command injection in yt-dlp (CVE-2023-40581). Successful exploitation can lead to full system takeover. Exploitable via ``cmd``. Mitigation: upgrade to `2023.09.24` or later.
|
| CVE-2023-45805 |
|
Vulnerability in pdm (CVE-2023-45805)
vulnerability in pdm (CVE-2023-45805). Successful exploitation can lead to full system takeover. Exploitable via ``pdm.lock``.
|
| CVE-2023-36566 |
|
Microsoft Common Data Model SDK Denial of Service Vulnerability
Microsoft Common Data Model SDK Denial of Service Vulnerability
|
| CVE-2023-4570 |
|
Vulnerability in ni-measurementlink-service (CVE-2023-4570)
vulnerability in ni-measurementlink-service (CVE-2023-4570). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.2.0` or later.
|
| CVE-2023-1633 |
|
Vulnerability in barbican (CVE-2023-1633)
vulnerability in barbican (CVE-2023-1633). Confidential information can be exposed externally.
|
| CVE-2023-43810 |
|
Vulnerability in opentelemetry-instrumentation (CVE-2023-43810)
vulnerability in opentelemetry-instrumentation (CVE-2023-43810). Risk of unauthorized operations or information disclosure. Exploitable via ``http_method``. Mitigation: upgrade to `0.41b0` or later.
|
| CVE-2023-4237 |
|
Vulnerability in ansible-core (CVE-2023-4237)
vulnerability in ansible-core (CVE-2023-4237). Successful exploitation can lead to full system takeover.
|
| CVE-2023-42458 |
|
Cross-Site Scripting (XSS) in zope (CVE-2023-42458)
cross-site scripting in zope (CVE-2023-42458). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.8.5` or later.
|
| CVE-2023-5002 |
|
OS Command Injection in pgadmin4 (CVE-2023-5002)
OS command injection in pgadmin4 (CVE-2023-5002). Data can be tampered with by attackers. Mitigation: upgrade to `7.7` or later.
|
| CVE-2023-4785 |
|
Vulnerability in grpcio (CVE-2023-4785)
vulnerability in grpcio (CVE-2023-4785). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.53.2` or later.
|
| CVE-2023-41626 |
|
Unrestricted File Upload in gradio (CVE-2023-41626)
vulnerability in gradio (CVE-2023-41626). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-1636 |
|
Vulnerability in barbican (CVE-2023-1636)
vulnerability in barbican (CVE-2023-1636). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-1625 |
|
Information Disclosure in openstack-heat (CVE-2023-1625)
vulnerability in openstack-heat (CVE-2023-1625). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `20.0.0` or later.
|
| CVE-2023-41267 |
|
Vulnerability in apache-airflow-providers-apache-hdfs (CVE-2023-41267)
vulnerability in apache-airflow-providers-apache-hdfs (CVE-2023-41267). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.1.1` or later.
|
| CVE-2023-41057 |
|
Path Traversal in hyper-bump-it (CVE-2023-41057)
path traversal in hyper-bump-it (CVE-2023-41057). Risk of unauthorized operations or information disclosure. Exploitable via ``show_confirm_prompt``. Mitigation: upgrade to `0.5.1` or later.
|
| CVE-2023-40587 |
|
Path Traversal in pyramid (CVE-2023-40587)
path traversal in pyramid (CVE-2023-40587). Risk of unauthorized operations or information disclosure. Exploitable via ``index.html``. Mitigation: upgrade to `2.0.2` or later.
|
| CVE-2023-41319 |
|
Vulnerability in ethyca-fides (CVE-2023-41319)
vulnerability in ethyca-fides (CVE-2023-41319). Successful exploitation can lead to full system takeover. Exploitable via ``root``. Mitigation: upgrade to `2.19.0` or later.
|
| CVE-2023-27604 |
|
Vulnerability in apache-airflow-providers-apache-sqoop (CVE-2023-27604)
vulnerability in apache-airflow-providers-apache-sqoop (CVE-2023-27604). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.0.0` or later.
|
| CVE-2023-39531 |
|
Authentication Bypass in sentry (CVE-2023-39531)
authentication bypass in sentry (CVE-2023-39531). Confidential information can be exposed externally. Mitigation: upgrade to `23.7.2` or later.
|
| CVE-2023-40024 |
|
Cross-Site Scripting (XSS) in scancodeio (CVE-2023-40024)
cross-site scripting in scancodeio (CVE-2023-40024). Risk of unauthorized operations or information disclosure. Exploitable via ``license_details_view``. Mitigation: upgrade to `32.5.2` or later.
|
| CVE-2023-39660 |
|
Code Injection in pandasai (CVE-2023-39660)
code injection in pandasai (CVE-2023-39660). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.8.1` or later.
|
| CVE-2023-33953 |
|
Vulnerability in grpcio (CVE-2023-33953)
vulnerability in grpcio (CVE-2023-33953). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.56.2` or later.
|
| CVE-2020-35141 |
|
Vulnerability in ryu (CVE-2020-35141)
vulnerability in ryu (CVE-2020-35141). Risk of unauthorized operations or information disclosure. Exploitable via ``OFPQueueGetConfigReply``.
|
| CVE-2020-35139 |
|
Vulnerability in ryu (CVE-2020-35139)
vulnerability in ryu (CVE-2020-35139). Risk of unauthorized operations or information disclosure. Exploitable via ``OFPBundleCtrlMsg``.
|
| CVE-2023-40272 |
|
Vulnerability in apache-airflow-providers-apache-spark (CVE-2023-40272)
vulnerability in apache-airflow-providers-apache-spark (CVE-2023-40272). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.3` or later.
|
| CVE-2023-39349 |
|
Vulnerability in sentry (CVE-2023-39349)
vulnerability in sentry (CVE-2023-39349). Confidential information can be exposed externally. Mitigation: upgrade to `23.7.2` or later.
|
| CVE-2023-39523 |
|
Command Injection in scancodeio (CVE-2023-39523)
command injection in scancodeio (CVE-2023-39523). Risk of unauthorized operations or information disclosure. Exploitable via ``docker_reference``. Mitigation: upgrade to `32.5.1` or later.
|
| CVE-2023-3637 |
|
Vulnerability in neutron (CVE-2023-3637)
vulnerability in neutron (CVE-2023-3637). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-4138 |
|
Vulnerability in rdiffweb (CVE-2023-4138)
vulnerability in rdiffweb (CVE-2023-4138). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.8.1` or later.
|