Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Minder does not sandbox http.send in Rego programs
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability
An issue was discovered in Ankitects Anki through 25.02
In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability
In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability
In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811
OMERO.web JSONP callback vulnerability
Teltonika’s Remote Management System versions prior to 4.10.0 have a feature allowing users to access managed devices’ local secure shell (SSH)/web...
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run