Supported Tests by SmartScanner 365 tests foundGet StartedDownload SmartScanner Free →Test all vulnerabilities with our free versionLearn MoreRead Security Guides →In-depth articles on vulnerability remediationVulnerability NameSeverityCWECross-Site Scripting in dojo - dojoVersions of dojo prior to 1.2.0 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize HTML code in user-controlled input, allowing attackers to...MediumCWE-79Read the Docs vulnerable to Cross-Site Scripting (XSS)This vulnerability allowed a malicious user to serve arbitrary HTML files from the main application domain (readthedocs[.]org/readthedocs[.]com) by exploiting a vulnerability in the code that...MediumCWE-79Incorrect default cookie name and recommendationThe default cookie name (and documentation recommendation) was prefixed with Host__ instead of __Host-. The point of this prefix is for additional security, to ensure...LowCross-Site Scripting in simditorVersions of simditor prior to 2.3.22 are vulnerable to Cross-Site Scripting. The package does not sanitize user input that is rendered with innerHTML, allowing attackers...MediumCWE-79Cross-Site Scripting in bootboxAll version of bootbox are vulnerable to Cross-Site Scripting. The package does not sanitize user input in the provided dialog boxes, allowing attackers to inject...MediumCWE-79Reflected Cross-Site Scripting in jquery.terminalVersions of jquery.terminal prior to 1.21.0 are vulnerable to Reflected Cross-Site Scripting. If the application has either of the options anyLinks or invokeMethods set to...MediumCWE-79Cross-Site Scripting in react-svgVersions of react-svg before 2.2.18 are vulnerable to cross-site scripting (xss). This is due to the fact that scripts found in SVG files are run...HighCWE-79Memory Exposure in tunnel-agentVersions of tunnel-agent before 0.6.0 are vulnerable to memory exposure.MediumCWE-200Cross-Site Scripting in shaveVersions of shave prior to 2.5.3 are vulnerable to Cross-Site Scripting. The shave package overwrites HTML elements and in doing so fails to properly encode...MediumCWE-79Cross-Site Scripting in bracket-templateAll versions of bracket-template are vulnerable to stored cross-site scripting (XSS). This is exploitable when a variable passed in via a GET parameter is used...HighCWE-79Prototype Pollution in deapVersions of deap before 1.0.1 are vulnerable to prototype pollution.HighCWE-400Denial of Service in canvasVersions of canvas prior to 1.6.10 are vulnerable to Denial of Service. Processing malicious JPEGs or GIFs could crash the node process.MediumRegular Expression Denial of ServiceA flaw was found in nodejs-marked versions from 0.5.0 to before 0.6.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service...MediumPath Traversal in localhost-now - localhost-nowAll versions of localhost-now are vulnerable to path traversal. This vulnerability is a bypass to the path traversal fix introduced in version 1.0.2HighCWE-22Regular Expression Denial of Service - nwmatcherA Regular Expression vulnerability was found in nwmatcher before 1.4.4. The fix replacing multiple repeated instances of the “\s*” pattern.MediumCWE-400Cross-Site Scripting in ids-enterprise - ids-enterpriseVersions of ids-enterprise prior to 4.18.2 are vulnerable to Cross-Site Scripting (XSS). The modal component fails to sanitize input to the title attribute, which may...HighCWE-79Cross-Site Scripting in ids-enterpriseVersions of ids-enterprise prior to 4.18.2 are vulnerable to Cross-Site Scripting (XSS). The soho-dropdown component does not properly encode its output and may allow attackers...HighCWE-79Remote code execution in Handlebars.jsHandlebars.js before 4.1.0 has Remote Code Execution (RCE)MediumSandbox Bypass Leading to Arbitrary Code Execution in constantinopleVersions of constantinople prior to 3.1.1 are vulnerable to a sandbox bypass which can lead to arbitrary code execution.HighHTML tag injectionServe Handler, before 5.0.3, has a XSS via HTML tag injection in directory lisiting page.MediumInsecure Default Configuration in tesseract.jsVersions of tesseract.js prior to 1.0.19 default to using a third-party proxy. Requests may be proxied through crossorigin.me which clearly states is not suitable for...MediumCWE-829Prototype Pollution in lutils-mergeAll versions of lutils-merge are vulnerable to Prototype Pollution. The merge() function fails to prevent user input to alter an Object’s prototype, allowing attackers to...MediumCWE-400Prototype Pollution in upmergeAll versions of upmerge are vulnerable to Prototype Pollution. The merge() function fails to prevent user input to alter an Object’s prototype, allowing attackers to...MediumCWE-400Failure to sanitize quotes which can lead to sql injection in squelAll versions of squel are vulnerable to sql injection.HighCWE-89Regular Expression Denial of Service in underscore.stringVersions of underscore.string prior to 3.3.5 are vulnerable to Regular Expression Denial of Service (ReDoS).MediumCWE-400Cross-Site Scripting in markedVersions 0.3.7 and earlier of marked unescape only lowercase while owsers support both lowercase and uppercase x in hexadecimal form of HTML character entityMediumCross-Site Scripting (XSS) in cloudcmdVersions of cloudcmd before 9.1.6 are vulnerable to cross-site scripting (XSS) when listing files in a directory. The attacker must control the name of a...HighCWE-79Denial of Service in url-relativeAll versions of url-relative are vulnerable to Denial of Service. If the values to and from are equal, the function hangs and never returns. This...MediumCWE-400Content injection in markedVersions 0.3.7 and earlier of marked When mangling is disabled via option mangle don’t escape target href. This allow attacker to inject arbitrary html-event into...MediumCommand Injection in dotAll versions of dot are vulnerable to Command Injection. The template compilation may execute arbitrary commands if an attacker can inject code in the template...MediumCWE-77Reverse Tabnapping in swagger-uiVersions of swagger-ui prior to 3.18.0 are vulnerable to Reverse Tabnapping. The package uses target='_blank' in anchor tags, allowing attackers to access window.opener for the...MediumCWE-1022Cross-Site Scripting in ids-enterprise - ids-enterprise - GHSA-crfx-5phg-hmw9Versions of ids-enterprise prior to 4.18.2 are vulnerable to Cross-Site Scripting (XSS). Script tags in the soho-autocomplete component are not properly encoded and may allow...HighCWE-79Cross-Site Scripting in @nuxt/devalueVersions of @nuxt/devalue prior to 1.2.3 are vulnerable to Cross-Site Scripting. Due to insufficient input sanitization attacker may inject arbitrary JavaScript code through object keys....MediumCWE-79Cross-Site Scripting via JSONPJSONP allows untrusted resource URLs, which provides a vector for attack by malicious actors.MediumCWE-79Denial of Service in memVersions of mem prior to 4.0.0 are vulnerable to Denial of Service (DoS). The package fails to remove old values from the cache even after...MediumCWE-400Cross-Site Scripting in cyberchefVersions of cyberchef prior to 8.31.3 are vulnerable to Cross-Site Scripting. In Text Encoding Brute Force the table rows are created by concatenating the value...MediumCWE-79Cross-Site Scripting in dojo - dojo - GHSA-536q-8gxx-m782Versions of dojo prior to 1.4.2 are vulnerable to DOM-based Cross-Site Scripting (XSS). The package does not sanitize URL parameters in the _testCommon.js and runner.html...MediumCWE-79Message Signature Bypass in openpgpVersions of openpgp prior to 4.2.0 are vulnerable to Message Signature Bypass. The package fails to verify that a message signature is of type text....HighCWE-347Prototype Pollution in deeplyVersions of deeply prior to 1.0.1 are vulnerable to Prototype Pollution. The package fails to validate which Object properties it updates. This allows attackers to...HighCWE-400Cross-Site Scripting in iobroker.webVersions of iobroker.web prior to 2.4.10 are vulnerable to Cross-Site Scripting. The package fails to escape URL parameters that may be reflected in the server...MediumCWE-79Remote Code Execution in Angular ExpressionsThe vulnerability, reported by GoSecure Inc, allows Remote Code Execution, if you call expressions.compile(userControlledInput) where userControlledInput is text that comes from user input.HighCWE-74Validation bypass is possible in Json Pattern ValidatorIn jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes can be overwritten via a conflicting name, as demonstrated...MediumCWE-287Cross-Site Scripting in selectize-plugin-a11yVersions of selectize-plugin-a11y prior to 1.1.0 are vulnerable to Cross-Site Scripting. The accessibility.liveRegion.speak function does not sanitize the msg variable before rendering it as HTML....MediumCWE-79Denial of Service in rgb2hexAll versions of rgb2hex are vulnerable to Regular Expression Denial of Service (ReDoS) when an attacker can pass in a specially crafted invalid color value....MediumCWE-400Improper Key Verification in openpgpVersions of openpgp prior to 4.2.0 are vulnerable to Improper Key Verification. The OpenPGP standard allows signature packets to have subpackets which may be hashed...HighCWE-347Cross-Site Scripting in vantVersions of vant prior to 2.1.8 are vulnerable to Cross-Site Scripting. The text value of the Picker component column is not sanitized, which may allow...HighCWE-79Incorrect Account Used for Signing - eth-ledger-bridge-keyringAnybody using this library to sign with a BIP44 account other than the first account may be affected. If a user is signing with the...HighCWE-287Incorrect Account Used for SigningAnybody using this library to sign with a BIP44 account other than the first account may be affected. If a user is signing with the...HighCWE-287OS Command Injection in devcert-sanscachedevcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable commonName controlled by user...HighCWE-78Regular Expression Denial of Service in AcornAffected versions of acorn are vulnerable to Regular Expression Denial of Service.A regex in the form of /[x-\ud800]/u causes the parser to enter an infinite...HighCWE-400Sandbox bypass in constantinopleconstantinople before 3.1.1 affected by a sandbox bypass.MediumCommand Injection in hot-formula-parserVersions of hot-formula-parser prior to 3.0.1 are vulnerable to Command Injection. The package fails to sanitize values passed to the parse function and concatenates it...HighCWE-94False-negative validation results in MINT transactions with invalid baton - slpjsUsers could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result...HighCWE-697False-negative validation results in MINT transactions with invalid batonUsers could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result...HighCWE-697discord-html not escaping HTML code blocks when lacking a language identifierAny website using discord-markdown with user-generated markdown is vulnerable to having code injected into the page where the markdown is displayed.HighDownloads Resources over HTTP in rs-brightcoveAffected versions of rs-brightcove insecurely download an executable over an unencrypted HTTP connection.HighCWE-311Prototype Pollution in DojoxThe Dojox jQuery wrapper jqMix mixin method is vulnerable to Prototype Pollution.LowCWE-94XSS in dojox due to insufficient escape in dojox.xmpp.util.xmlEncodePotential XSS vulnerability for users of dojox/xmpp and dojox/dtl.MediumCWE-79Cross-Site Scripting in seeftlAll versions of seeftl are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize filenames, allowing attackers to execute arbitrary JavaScript in the victim’s...HighCWE-79XSS in TinyMCEA cross-site scripting (XSS) vulnerability was discovered in: the core parser and media plugin. The vulnerability allowed arbitrary JavaScript execution when inserting a specially crafted...MediumCWE-79Holder can generate proof of ownership for credentials it does not control in vp-toolkitThe verifyVerifiablePresentation() method check the cryptographic integrity of the Verifiable Presentation, but it does not check if the credentialSubject.id DID matches the signer of the...HighHolder can (re)create authentic credentials after receiving a credential in vp-toolkitThe verifyVerifiableCredential() method check the cryptographic integrity of the Verifiable Credential, but it does not check if the credential.issuer DID matches the signer of the...HighCross-Site Scripting in fileviewAll versions of fileview are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize filenames, allowing attackers to execute arbitrary JavaScript in the victim’s...HighCWE-79Cross-Site Scripting in sanitize-html - sanitize-html - GHSA-3j7m-hmh3-9jmpAffected versions of sanitize-html do not sanitize input recursively, which may allow an attacker to execute arbitrary Javascript.MediumCWE-79Information disclosure through error object in auth0.jsBetween versions 8.0.0 and 9.13.1(inclusive), in the case of an (authentication) error, the error object returned by the library contains the original request of the...HighCWE-522Introspection in schema validation in Apollo ServerWe encourage all users of Apollo Server to read this advisory in its entirety to understand the impact. The Resolution section contains details on patched...MediumValidation Bypass in slp-validateVersions of slp-validate prior to 1.0.1 are vulnerable to a validation bypass. Bitcoin scripts may cause the validation result from slp-validate to differ from the...HighCWE-20Resources Downloaded over Insecure Protocol in igniteuiAffected versions of igniteui download Javascript and CSS resources over an unencrypted HTTP connection. An attacker with a privileged network position can intercept and view...LowCWE-311Sandbox Breakout in realms-shimVersions of realms-shim prior to 1.2.1 are vulnerable to a Sandbox Breakout. The Realms evaluation function has an option to apply Babel-like transformations to the...HighCross-Site Scripting in editor.mdAll versions of editor.md are vulnerable to Cross-Site Scripting. User input is insufficiently sanitized, allowing attackers to inject malicious code in payloads containing base64-encoded content....MediumCWE-79Cross Site Scripting (XSS) in plotly.jsAffected versions of plotly.js are vulnerable to cross-site scripting if an attacker can convince a user to visit a malicious plot on a site using...MediumCWE-79Missing Origin Validation in parcel-bundler - parcel-bundlerVersions of parcel-bundler before 1.10.0 are missing origin validation on the websocket server. This vulnerability allows a remote attacker to steal a developer’s source code...HighCWE-200Denial of Service in nesAffected versions of nes are vulnerable to denial of service when given an invalid cookie header, and websocket authentication is set to cookie. Submitting an...HighCWE-400Critical severity vulnerability that affects slpjsNo description available.HighCWE-20Downloads Resources over HTTP in jser-statAffected versions of jser-stat insecurely downloads resources over HTTP.MediumCWE-311Moderate severity vulnerability that affects validator - validator - GHSA-552w-rqg8-gxxmThe validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via vectors related to UI redressing.MediumCWE-79Regular Expression Denial of Service in ssriVersion of ssri prior to 5.2.2 are vulnerable to regular expression denial of service (ReDoS) when using strict mode.MediumCWE-400Sandbox Breakout in realms-shim - realms-shimVersions of realms-shim prior to 1.2.0 are vulnerable to a Sandbox Breakout. Reflect.construct can be used on the sandboxed Function constructor to reach the prototypes...HighDefault Express middleware security check is ignored in productionNo description available.HighXSS Filter Bypass via Encoded URL in validatorVersions of validator prior to 2.0.0 contained an xss filter method that is affected by several filter bypasses. This may result in a cross-site scripting...MediumCWE-79Cross-Site Scripting in nunjucksAffected versions of nunjucks do not properly escape specially structured user input in template vars when in auto-escape mode, resulting in a cross-site scripting vulnerability....MediumCWE-79Cross-Site Scripting in handlebarsVersions of handlebars prior to 4.0.0 are affected by a cross-site scripting vulnerability when attributes in handlebar templates are not quoted.MediumCWE-79Arbitrary Code Injection in pouchdbAffected versions of pouchdb do not properly sandbox the code execution engine which executes the map/reduce functions for temporary views and design documents. Under certain...HighCWE-94High severity vulnerability that affects gunThe static file server module included with GUN had a serious vulnerability:HighCWE-22VBScript Content Injection in markedVersions 0.3.2 and earlier of marked are affected by a cross-site scripting vulnerability even when sanitize:true is set.MediumCWE-79Moderate severity vulnerability that affects markedThis advisory has been withdrawn, per NVD: “This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.”MediumPrototype Pollution in async merge-objectThe utilities function in all versions of the merge-object node module can be tricked into modifying the prototype of Object when the attacker can control...HighCWE-20Cross-Site Scripting in serialize-javascriptVersions of serialize-javascript prior to 2.1.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize serialized regular expressions. This vulnerability does not affect...MediumCWE-79Low severity vulnerability that affects eye.jsNo description available.LowDownloads Resources over HTTP in strider-sauceAffected versions of strider-sauce insecurely download an executable over an unencrypted HTTP connection.HighCWE-311Prototype Pollution in merge-optionsAll versions of merge-options are vulnerable to Prototype PollutionHighCWE-20Downloads Resources over HTTP in openframe-glslviewerAffected versions of openframe-glslviewer insecurely download an executable over an unencrypted HTTP connection.HighCWE-311Downloads Resources over HTTP in product-monitorAffected versions of product-monitor insecurely download an executable over an unencrypted HTTP connection.HighCWE-311Multiple XSS Filter Bypasses in validatorVersions of validator prior to 1.1.0 are affected by several cross-site scripting vulnerabilities due to bypasses discovered in the blacklist-based filter.MediumCWE-79ReDoS via long UserAgent header in ua-parserAffected versions of ua-parser are vulnerable to regular expression denial of service when given a specially crafted User-Agent header.HighCWE-400Cross-Site Scripting in mustacheVersions of mustache prior to 2.2.1 are affected by a cross-site scripting vulnerability when attributes in mustache templates are not quoted.HighCWE-79Regular Expression Denial of Service in parsejsonAffected versions of parsejson are vulnerable to a regular expression denial of service when parsing untrusted user input.HighCWE-400Path Traversal in socket.io-fileAll versions of socket.io-file are vulnerable to Path Traversal. The package fails to sanitize user input and uses it to generate the file upload paths....HighCWE-22Regular expression denial of service in url-regexall versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a Denial...HighCWE-400ECDSA signature vulnerability of Minerva timing attack in jsrsasignECDSA side-channel attack named Minerava have been found and it was found that it affects to jsrsasign.MediumCWE-362Stored XSS in TimelineJS3TimelineJS renders some user data as HTML. An attacker could implement an XSS exploit with maliciously crafted content in a number of data fields. This...HighCWE-79Storing Password in Local StorageThe setPassword method (http://parseplatform.org/Parse-SDK-JS/api/2.9.1/Parse.User.html#setPassword) stores the user’s password in localStorage as raw text making it vulnerable to anyone with access to your localStorage. We believe...MediumCWE-256Unrestricted Upload of File with Dangerous Type in blueimp-file-uploadUnauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0HighCWE-434Cross-Site Scripting in @progress/kendo-angular-editorKendo UI for Angular Editor Component (npm package @progress/kendo-angular-editor) before version 1.2.3 is vulnerable to Cross-Site Scripting. When the Editor content contains potentially malicious scripts...HighCWE-79False-positive validity for NFT1 genesis transactions in SLPJSIn the npm package named “slpjs”, versions prior to 0.27.4 are vulnerable to false-positive validation outcomes for the NFT1 Child Genesis transaction type.HighCWE-697Cross-Site Scripting in bootstrap-tagsinputAll versions of bootstrap-tagsinput are vulnerable to cross-site scripting when user input is passed into the itemTitle parameter unmodified, as the package fails to properly...HighCWE-79Cross-Site Scripting in jqtreeAffected versions of jqtree are vulnerable to cross-site scripting in the drag and drop functionality for modifying tree data.HighCWE-79Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-p239-93f7-h6xfAffected versions of swagger-ui contain a cross-site scripting vulnerability in the key names of a specific nested object in the JSON document.HighCWE-79Cross-Site Scripting (XSS) in pivottableAffected versions of pivottable are vulnerable to cross-site scripting, due to a new mechanism used to render JSON elements.HighCWE-79DOM-based XSS in auth0-lockVersions before and including 11.25.1 are using dangerouslySetInnerHTML to display an informational message when used with a Passwordless or Enterprise connection.LowCWE-79Multiple Content Injection Vulnerabilities in markedVersions 0.3.0 and earlier of marked are affected by two cross-site scripting vulnerabilities, even when sanitize: true is set.MediumCWE-79Authentication Bypass in console-ioAffected versions of the console-io package do not configure the underlying websocket library to require authentication, resulting in an authentication bypass vulnerability. As console-io allows...HighCWE-287Insecure randomness in socket.ioAffected versions of socket.io depend on Math.random() to create socket IDs, and therefore the IDs are predictable. With enough information on prior IDs, an attacker...HighCWE-330Moderate severity vulnerability that affects validatorThe validator module before 1.1.0 for Node.js allows remote attackers to bypass the XSS filter via a nested tag.MediumCWE-79Sensitive Data Exposure in msrcryptoVersions of msrcrypto prior to 1.4.1 are vulnerable to Sensitive Data Exposure. The package’s Elliptic Curve Cryptography (ECC) implementation may leak information about a server’s...HighCWE-682Downloads Resources over HTTP in js-givenAffected versions of js-given insecurely download an executable over an unencrypted HTTP connection.HighCWE-311Moderate severity vulnerability that affects validator - validatorThe validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via a crafted javascript URI.MediumCWE-79Command Injection in wxchangbaAll versions of wxchangba are vulnerable to Command Injection. The package does not validate user input on the reqPostMaterial function, passing contents of the file...MediumCWE-77Cross-Site Scripting in @berslucas/liljsVersions of @berslucas/liljs prior to 1.0.2 are vulnerable to Cross-Site Scripting (XSS). The package uses the unsafe innerHTML function without sanitizing input, which may allow...MediumCWE-79Malicious Package in rpc-websocketVersions of rpc-websocket >= 0.7.6 contained malicious code. The package opens a backdoor to a remote server and executes arbitrary commands, effectively acting as a...HighCWE-506Arbitrary Code Execution in mathjs - mathjsmath.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary...HighCWE-94Auth0-js bypasses CSRF checksThe Auth0.js library has a vulnerability affecting versions below 9.3 that allows an attacker to bypass the CSRF check from the state parameter if it’s...HighCWE-352False-positive validity for NFT1 genesis transactionsIn the npm package named “slp-validate”, versions prior to 1.2.2 are vulnerable to false-positive validation outcomes for the NFT1 Child Genesis transaction type.HighCWE-697XSS via JQLite DOM manipulation functions in AngularJSXSS may be triggered in AngularJS applications that sanitize user-controlled HTML snippets before passing them to JQLite methods like JQLite.prepend, JQLite.after, JQLite.append, JQLite.replaceWith, JQLite.append, new...MediumCWE-79Command Injection in ungit - ungitVersions of ungit prior to 0.9.0 are affected by a command injection vulnerability in the url parameter.HighCWE-77Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-7f59-x49p-v8mqAffected versions of swagger-ui are vulnerable to cross-site scripting in both the consumes and produces parameters of the swagger JSON document for a given API....HighCWE-79Cross-Site Scripting in mrk.jsVersions of mrk.js before 2.0.1 are vulnerable to cross-site scripting (XSS) when markdown is converted to HTML.HighCWE-79Cross-Site Scripting in react-marked-markdownAll versions of react-marked-markdown are vulnerable to cross-site scripting (XSS) via href attributes. This is exploitable if user is provided to react-marked-markdownHighCWE-79Denial of Service in ethereumjs-vmethereumjs-vm 2.4.0 allows attackers to cause a denial of service (vm.runCode failure and REVERT) via a “code: Buffer.from(my_code, ‘hex’)” attribute.HighCWE-119Malicious Package in angular-material-sidenav-rndVersion 0.1.1 of angular-material-sidenav-rnd contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the...HighCWE-506Malicious Package in cordova-plugin-china-pickerVersion 1.0.910 of cordova-plugin-china-picker contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the...HighCWE-506Arbitrary JavaScript Execution in typed-functionVersions of typed-function prior to 0.10.6 are vulnerable to Arbitrary JavaScript Execution. Function names are not properly sanitized and may allow an attacker to execute...HighCWE-94Cross-Site Scripting in semantic-ui-searchAll versions of semantic-ui-search are vulnerable to Cross-Site Scripting. Lack of output encoding on the selection dropdowns can lead to user input being executed instead...HighCWE-79HTML Injection in preactVersions of preact 10.x on prerelease tags alpha and beta prior to 10.0.0-beta.1 are vulnerable to HTML Injection. Due to insufficient input validation the package...MediumCWE-74Cross-Site Scripting in cmmn-js-properties-panelVersions of cmmn-js-properties-panel prior to 0.8.0 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize input in specially configured diagrams, which may allow...HighCWE-79Prototype Pollution in lodash.defaultsdeep - lodash.defaultsdeepVersions of lodash.defaultsdeep before 4.6.1 are vulnerable to prototype pollution. The function mergeWith may allow a malicious user to modify the prototype of Object via...HighCWE-1321Command Injection in marsdbAll versions of marsdb are vulnerable to Command Injection. In the DocumentMatcher class, selectors on $where clauses are passed to a Function constructor unsanitized. This...HighCWE-77Cross-Site Scripting in fomantic-uiVersions of fomantic-ui are vulnerable to Cross-Site Scripting. Lack of output encoding on the selection dropdowns can lead to user input being executed instead of...HighCWE-79Cross-Site Scripting in google-closure-libraryVersions of google-closure-library prior to 20190301.0.0 are vulnerable to Cross-Site Scripting. The safedomtreeprocessor.processToString() function improperly processed empty elements, which could allow attackers to execute arbitrary...MediumCWE-79Cross-Site Scripting in hexo-adminAll versions of hexo-admin are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize rendered markdown, allowing attackers to execute arbitrary JavaScript in a...HighCWE-79Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-388g-jwpg-x6j4Versions of swagger-ui prior to 3.0.13 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize YAML files imported from URLs or copied-pasted. This...MediumCWE-79Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-vp93-gcx5-4w52Versions of swagger-ui prior to 2.2.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize JSON schemas, allowing attackers to execute arbitrary JavaScript...MediumCWE-79Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-w992-2gmj-9xxjVersions of swagger-ui prior to 2.2.1 are vulnerable to Cross-Site Scripting (XSS). The package allows HTML code in the swagger.apiInfo.description value without proper sanitization, which...MediumCWE-79DOM-based XSS in gmail-jsAffected versions of gmail-js are vulnerable to cross-site scripting in the tools.parse_response, helper.get.visible_emails_post, and helper.get.email_data_post functions, which pass user input directly into the Function constructor....HighCWE-79Incorrect Calculation in bigint-moneyVersions of bigint-money prior to 0.6.2 are vulnerable to an Incorrect Calculation. The package incorrectly rounded certain numbers, which could have drastic consequences due to...LowCWE-682Malicious Package in bmapVersion 1.0.3 of bmap contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the...HighCWE-506Regular Expression Denial of Service in ansi2htmlThe ansi2html package is affected by a regular expression denial of service vulnerability when certain types of user input is passed in.HighCWE-400Regular Expression Denial of Service in validatorVersions of validator prior to 3.22.1 are affected by a regular expression denial of service vulnerability in the isURL method.HighCWE-400Reverse Tabnabbing in quillVersions of quill prior to 1.3.7 are vulnerable to Reverse Tabnabbing. The package uses target='_blank' in anchor tags, allowing attackers to access window.opener for the...MediumCWE-1022User Impersonation in converse.jsVersions of converse.js prior to 1.0.7 for 1.x or 2.0.5 for 2.x are vulnerable to User Impersonation. The package provides an incorrect implementation of XEP-0280:...MediumCWE-346XSS in client rendered block templates in rendrAffected versions of rendr are vulnerable to cross-site scripting when client side rendering is done inside a _block.HighCWE-79Denial of Service in handlebarsAffected versions of handlebars are vulnerable to Denial of Service. The package’s parser may be forced into an endless loop while processing specially-crafted templates. This...MediumCWE-400Prototype Pollution in sahmatAll versions of sahmat are vulnerable to prototype pollution. The package does not restrict the modification of an Object’s prototype, which may allow an attacker...HighCWE-1321Cross-Site Scripting in atlasboard-atlassian-packageAll versions of atlasboard-atlassian-package prior to 0.4.2 are vulnerable to Cross-Site Scripting (XSS). The package fails to properly sanitize user input that is rendered as...HighCWE-79Cross-Site Scripting in bootstrap-select - bootstrap-selectVersions of bootstrap-select prior to 1.13.6 are vulnerable to Cross-Site Scripting (XSS). The package does not escape title values on <option> tags. This may allow...HighCWE-79HTML Injection in marky-markdown - marky-markdownAll versions of marky-markdown are vulnerable to HTML Injection. The package fails to sanitize style attributes in img tags of the markdown input. This may...HighCWE-79Improper Authorization in react-oauth-flowAll versions of react-oauth-flow fail to properly implement the OAuth protocol. The package stores secrets in the front-end code. Instead of using a public OAuth...HighCWE-285Improper Authorization in @sap-cloud-sdk/coreAffected versions of @sap-cloud-sdk/core do not properly validate JWTs. The verifyJwt() function does not properly validate the URL from where the public verification key for...HighCWE-285Cross-Site Scripting in mermaid - mermaidVersions of mermaid prior to 8.2.3 are vulnerable to Cross-Site Scripting. If malicious input such as A["<img src=invalid onerror=alert('XSS')></img>"] is provided to the application, it...HighCWE-79Denial of Service in serialize-to-jsVersions of serialize-to-js prior to 2.0.0 are vulnerable to Denial of Service. User input is not properly validated, allowing attackers to provide inputs that lead...HighMissing Origin Validation in browserify-hmrVersions of browserify-hmr prior to 0.4.0 are missing origin validation on the websocket server.HighCWE-200Prototype Pollution in smart-extendAll versions of smart-extend are vulnerable to Prototype Pollution. The deep() function allows attackers to modify the prototype of Object causing the addition or modification...MediumCWE-1321Command Injection in soletta-dev-appAll versions of soletta-dev-app are vulnerable to Command Injection. The package does not validate user input on the /api/service/status API endpoint, passing contents of the...HighCWE-77Malicious Package in react-datepicker-plusVersions 2.4.3 and 2.4.2 of react-datepicker-plus contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms...HighCWE-506Malicious Package in vue-backboneVersion 0.1.2 of vue-backbone contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send...HighCWE-506Cross-Site Scripting in diagram-js-direct-editingVersions of diagram-js-direct-editing prior to 1.4.3 are vulnerable to Cross-Site Scripting. The package fails to sanitize input from the clipboard, allowing attackers to execute arbitrary...MediumCWE-79Cross-Site Scripting in graylog-web-interfaceAll versions of graylog-web-interface are vulnerable to Cross-Site Scripting (XSS). The package fails to escape output on the TypeAhead and QueryInput components, which may allow...HighCWE-79Cross-Site Scripting in @ionic/coreVersions of @ionic/core prior to 4.0.3, 4.1.3, 4.2.1 or 4.3.1 are vulnerable to Cross-Site Scripting (XSS). The package uses the unsafe innerHTML function without sanitizing...HighCWE-79Cross-Site Scripting in jquery.json-viewer - jquery.json-viewerVersions of jquery.json-viewer prior to 1.3.0 are vulnerable to Cross-Site Scripting (XSS). The package insufficiently sanitizes user input when creating links, and concatenates the user...HighCWE-79Path Traversal in zeroVersions of zero prior to 1.0.6 are vulnerable to Path Traversal. Due to insufficient input sanitization in URLs, attackers can access server files by using...HighCWE-22Cross-Site Scripting in dmn-js-properties-panelVersions of dmn-js-properties-panel prior to 0.8.0 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize input in specially configured diagrams, which may allow...HighCWE-79Cross-Site Scripting in Prism - prismjsThe easing preview of the Previewers plugin has an XSS vulnerability that allows attackers to execute arbitrary code in Safari and Internet Explorer.HighCWE-79Prototype Pollution in lodash.mergeVersions of lodash.merge before 4.6.1 are vulnerable to Prototype Pollution. The function ‘merge’ may allow a malicious user to modify the prototype of Object via...HighCWE-1321Cross-Site Scripting in snekserveAll versions of snekserve are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize filenames, allowing attackers to execute arbitrary JavaScript in the victim’s...HighCWE-79CSRF Vulnerability in jquery-ujsVersions 1.0.3 and earlier of jquery-ujs are vulnerable to an information leakage attack that may enable attackers to launch CSRF attacks, as it allows attackers...MediumCWE-352Cross-Site Scripting in yuiAffected versions of yui are vulnerable to cross-site scripting in the uploader.swf and io.swf utilities, via script injection in the url.MediumCWE-79Arbitrary File Write in iobroker.adminVersions of iobroker.admin prior to 3.6.12 are vulnerable to Path Traversal. The package fails to restrict access to folders outside of the intended folder in...HighCWE-22Prototype Pollution in get-setterAll versions of get-setter are vulnerable to prototype pollution. The function set does not restrict the modification of an Object’s prototype, which may allow an...HighCWE-1321Prototype Pollution in getsetdeepAll versions of getsetdeep are vulnerable to prototype pollution. The setDeep() function does not restrict the modification of an Object’s prototype, which may allow an...HighCWE-1321Prototype Pollution in handlebars - handlebars - GHSA-g9r4-xpmj-mj65Versions of handlebars prior to 3.0.8 or 4.5.3 are vulnerable to prototype pollution. It is possible to add or modify properties to the Object prototype...HighCWE-1321Malicious Package in awesome_react_utilityVersion 1.0.2 of awesome_react_utility contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the...HighCWE-506Malicious Package in codifyVersion 0.3.1 of codify contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the...HighCWE-506Malicious Package in json-serializer - json-serializerVersion 2.0.10 of json-serializer contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the...HighCWE-506Command Injection in ascii-artVersions of ascii-art before 1.4.4 are vulnerable to command injection. This is exploitable when user input is passed into the argument of the ascii-art preview...LowCWE-77Cross-Site Scripting in buefyVersions of buefy prior to 0.7.2 are vulnerable to Cross-Site Scripting, allowing attackers to manipulate the DOM and execute remote code. The autocomplete list renders...HighCWE-79Cross-Site Scripting in markdown-it-katexAll versions of markdown-it-katex are vulnerable to Cross-Site Scripting (XSS). The package fails to properly escape error messages, which may allow attackers to execute arbitrary...HighCWE-79Cross-Site Scripting in md-data-tableAll versions of md-data-table are vulnerable to cross-site scripting (XSS). This vulnerability is exploitable if an attacker has control over data that is rendered by...HighCWE-79HTML Injection in marky-markdownAll versions of marky-markdown are vulnerable to HTML Injection due to a validation bypass. The package only allows iframes where the source is youtube.com but...MediumCWE-79Insecure Cryptography Algorithm in parselAll versions of parsel use an insecure cryptography algorithm. The package uses aes-256-cbc without integrity checks, which renders the ciphertext vulnerable to bit-flipping attacks.HighCWE-327Insufficient Entropy in parselAll versions of parsel use an insecure key derivation function. The package runs keys of arbitrary lengths through one round of SHA256 hashing for key...HighCWE-331Cross-Site Scripting in htmrVersions of htmr prior to 0.8.7 are vulnerable to Cross-Site Scripting (XSS). The package uses innerHTML to unescape HTML entities. This may lead to DOM-based...HighCWE-79Cross-Site Scripting in wangeditorAll versions of wangeditor are vulnerable to Cross-Site Scripting. The package fails to properly encode output, allowing arbitrary JavaScript to be inserted in links and...HighCWE-79Cross-Site Request Forgery (CSRF) in Auth0CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.HighCWE-352Malicious Package in motiv.scssVersion 0.4.20 of motiv.scss contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send...HighCWE-506Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-22q9-hqm5-mhmcVersions of swagger-ui prior to 2.2.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to encode output in GET requests.MediumCWE-79Malicious Package in zemenVersion 0.0.5 of zemen contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the...HighCWE-506Path Traversal in ponseVersions of ponse prior to 2.0.2 are vulnerable to Path Traversal. The package fails to sanitize URLs, allowing attackers to access server files outside of...HighCWE-22Prototype Pollution in lodash.defaultsdeepVersions of lodash.defaultsdeep before 4.6.1 are vulnerable to Prototype Pollution. The function ‘defaultsDeep’ may allow a malicious user to modify the prototype of Object via...HighCWE-1321Prototype Pollution in mergifyAll versions of mergify are vulnerable to Prototype Pollution. The mergify() function allows attackers to modify the prototype of Object causing the addition or modification...MediumCWE-1321Prototype Pollution in mithrilAffected versions of mithrilare vulnerable to prototype pollution. The function parseQueryString may allow a malicious user to modify the prototype of Object, causing the addition...HighCWE-1321Unauthorized File Access in atompmVersions of atompm prior to 0.8.2 are vulnerable to Unauthorized File Access. The package fails to sanitize relative paths in the URL for file downloads,...HighCWE-200Configuration Override in helmet-cspVersions of helmet-csp before to 2.9.1 are vulnerable to a Configuration Override affecting the application’s Content Security Policy (CSP). The package’s browser sniffing for Firefox...MediumCross-Site Scripting in ecoAll versions of eco are vulnerable to Cross-Site Scripting (XSS). The package’s default __escape implementation fails to escape single quotes, which may allow attackers to...HighCWE-79ReDOS vulnerabities: multiple grammars - highlight.jsoswasp:MediumCWE-400ReDOS vulnerabities: multiple grammarsoswasp:MediumCWE-400Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-876r-hj45-fw7gAll versions of safer-eval are vulnerable to Sandbox Escape leading to Remote Code Execution. It is possible to escape the sandbox by forcing exceptions recursively...HighCross-Site Scripting in reactVersions of react prior to 0.14.0 are vulnerable to Cross-Site Scripting (XSS). The package’s createElement function fails to properly validate its input object, allowing attackers...HighCWE-79Prototype Pollution in flat-wrapAll versions of flat-wrap are vulnerable to prototype pollution. The function unflatten does not restrict the modification of an Object’s prototype, which may allow an...HighCWE-1321Prototype Pollution in safe-object2 - safe-object2All versions of safe-object2 are vulnerable to prototype pollution. The settter() function does not restrict the modification of an Object’s prototype, which may allow an...HighCWE-1321Prototype Pollution in unflattenAll versions of unflatten are vulnerable to prototype pollution. The function unflatten does not restrict the modification of an Object’s prototype, which may allow an...HighCWE-1321Client TLS credentials sent raw to server in npm package natsNats is a Node.js client for the NATS messaging system.HighCWE-522Cross-Site Scripting in ngx-mdVersions of ngx-md prior to 6.0.3 are vulnerable to Cross-Site Scripting. Links are not properly restricted to http/https and can contain JavaScript which may lead...HighCWE-79Path Traversal in sapperVersions of sapper prior to 0.27.11 are vulnerable to Path Traversal. It is possible to access sensitive files on the server through HTTP requests containing...HighCWE-22Potential XSS in jQuery dependency in MiradorMirador users less than v3.0.0 (alpha-rc) versions that have an unpatched jQuery. When adopters update jQuery they will find some of Mirador functionality to be...MediumCWE-79Prototype Pollution in json-logic-jsVersions of json-logic-js prior to 2.0.0 are vulnerable to Prototype Pollution. The method operation allows a malicious user to modify the prototype of Object through...HighCWE-471Unrestricted Upload of File with Dangerous Type in jquery-file-uploadArbitrary file upload in jQuery Upload File <= 4.0.2HighCWE-434Authentication Bypass in otpauthVersions of otpauth prior to 3.2.8 are vulnerable to Authentication Bypass. The package’s totp.validate() function may return positive values for single digit tokens even if...HighCWE-287Cross-Site Scripting in console-feedVersions of console-feed prior to 2.8.10 are vulnerable to Cross-Site Scripting (XSS). The package fails to properly escape the rendered output. If an application uses...HighCWE-79Malicious Package in rate-mapVersion 1.0.3 of rate-map contains malicious code. The malware breaks functionality of the purescript-installer package by rewriting code of the dl-tar dependency.HighCWE-506Prototype Pollution in lodash.merge - lodash.mergeVersions of lodash.merge before 4.6.2 are vulnerable to prototype pollution. The function merge may allow a malicious user to modify the prototype of Object via...HighCWE-1321Prototype Pollution in lodash.mergewith - lodash.mergewithVersions of lodash.mergewith before 4.6.1 are vulnerable to Prototype Pollution. The function ‘mergeWith’ may allow a malicious user to modify the prototype of Object via...HighCWE-1321Prototype Pollution in lodash.mergewithVersions of lodash.mergewith before 4.6.2 are vulnerable to prototype pollution. The function mergeWith may allow a malicious user to modify the prototype of Object via...HighCWE-1321Cross-Site Scripting in mavon-editorAll versions of mavon-editor are vulnerable to Cross-Site Scripting. The package fails to sanitize entered input, allowing attackers to execute arbitrary JavaScript in a victim’s...MediumCWE-79Malicious Package in json-serializerVersion 2.0.10 of json-serializer contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the...HighCross-Site Scripting in markdown-to-jsx - markdown-to-jsxVersions of markdown-to-jsx prior to 6.11.4 are vulnerable to Cross-Site Scripting. Due to insufficient input sanitization the package may render output containing malicious JavaScript. This...HighCWE-79Machine-In-The-Middle in airtableAffected versions of airtable are vulnerable to Machine-In-The-Middle. The package has SSL certificate validation disabled by default unintentionally. This may allow attackers in a privileged...HighArbitrary Code Execution in handlebars - handlebars - GHSA-q2c6-c6pm-g3ghVersions of handlebars prior to 3.0.8 or 4.5.3 are vulnerable to Arbitrary Code Execution. The package’s lookup helper fails to properly validate templates, allowing attackers...HighRegular Expression Denial of Service in markdownAll versions of markdown are vulnerable to Regular Expression Denial of Service (ReDoS). The markdown.toHTML() function has significantly degraded performance when parsing long strings containing...LowCWE-400Cross-Site Scripting in nextcloud-vue-collectionsVersions of nextcloud-vue-collections prior to 0.4.2 are vulnerable to Cross-Site Scripting (XSS). The v-tooltip component has an insecure defaultHTML configuration that allows arbitrary JavaScript to...HighCWE-79Outdated Static Dependency in vue-momentVersions of vue-moment prior to 4.1.0 contain an Outdated Static Dependency. The package depends on moment and has it loaded statically instead of as a...MediumCWE-1104Regex denial of service vulnerability in codesample pluginA regex denial of service (ReDoS) vulnerability was discovered in a dependency of the codesample plugin. The vulnerability allowed poorly formed ruby code samples to...LowCWE-400Signatures are mistakenly recognized to be valid in jsrsasignIn the jsrsasign package through 10.1.13 for Node.js, some invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized to be valid. NOTE: there is no known...MediumCWE-347Hardcoded Initialization Vector in parselAll versions of parsel have a default hardcoded initialization vector. In cases where the IV is not provided, the package defaults to a hardcoded IV...HighServer-Side Request Forgery in @uppy/companion - @uppy/companionVersions of @uppy/companion prior to 1.9.3 are vulnerable to Server-Side Request Forgery (SSRF). The get route passes the user-controlled variable req.body.url to a GET request...HighCWE-918Verification flaw in Solid identity-token-verifierNo description available.MediumCWE-290Improperly Controlled Modification of Object Prototype AttributesThe software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not...HighCWE-1321Cross-site scripting vulnerability in TinyMCE - tinymce - GHSA-5vm8-hhgr-jcjpA cross-site scripting (XSS) vulnerability was discovered in the URL sanitization logic of the core parser for form elements. The vulnerability allowed arbitrary JavaScript execution...MediumCWE-79Improper Verification of Cryptographic Signature in aws-encryption-sdk-javascriptThis advisory addresses several LOW severity issues with streaming signed messages and restricting processing of certain types of invalid messages.MediumCWE-347Regular Expression Denial of Service in millisecondVersions of millisecond prior to 0.1.2 are affected by a regular expression denial of service vulnerability when extremely long version strings are parsed.MediumCWE-400Execution with Unnecessary Privileges in arc-electronWhen the end-user click on the response header that contains a link the target will be opened in ARC new window.HighRemoval of functional code in faker.jsFaker.js helps users create large amounts of data for testing and development. The maintainer deliberately removed the functional code from this package. This appears to...HighInefficient Regular Expression Complexity in Validator.js - validatorVersions of validator prior to 13.7.0 are affected by an inefficient Regular Expression complexity when using the rtrim and trim sanitizers.MediumCWE-1333Marked ReDoS due to email addresses being evaluated in quadratic timeVersions of marked from 0.3.14 until 0.6.2 are vulnerable to Regular Expression Denial of Service. Email addresses may be evaluated in quadratic time, allowing attackers...MediumCWE-400fuelux vulnerable to Cross-Site Scripting in Pillbox featureAffected versions of fuelux contain a cross-site scripting vulnerability in the Pillbox feature. By supplying a script as a value for a new pillbox, it...HighCWE-79Pannellum Cross-Site Scripting due to data not being sanitized for URIs or vbscriptVersions of pannellum prior to 2.5.6 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize URLs for data URIs, which may allow attackers...MediumCWE-79cookie-signature Timing AttackAffected versions of cookie-signature are vulnerable to timing attacks as a result of using a fail-early comparison instead of a constant-time comparison.MediumCWE-362Path traversal for local publishers in TechDocs backendA malicious actor with the ability to register entities in the Software Catalog is able to write files to arbitrary paths on the techdocs backend...MediumArbitrary Code Execution in require-nodeVersions of require-node prior to 1.3.4 for 1.x and 2.0.4 for 2.x are vulnerable to Arbitrary Code Execution. The package fails to sanitize requests to...HighCWE-78Regular Expression Denial of Service in slugAffected versions of slug are vulnerable to a regular expression denial of service when parsing untrusted user input.MediumCWE-400Cleartext Transmission of Sensitive Information in moment-timezoneNo description available.MediumCWE-319Command Injection in moment-timezoneAll versions of moment-timezone from 0.1.0 contain build tasks vulnerable to command injection.Lowgatsby-transformer-remark has possible unsanitized JavaScript code injectionThe gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the gray-matter npm package, which is vulnerable to JavaScript injection in its...HighCWE-79Cross-site Scripting in bootstrap-table - bootstrap-tableThis affects all versions of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the...LowCWE-843RSSHub SSRF vulnerabilityRSSHub is vulnerable to Server-Side Request Forgery (SSRF) attacks. This vulnerability allows an attacker to send arbitrary HTTP requests from the server to other servers...HighCWE-918Prototype Pollution in chartkickAffected versions of @polymer/polymer are vulnerable to prototype pollution. The package fails to prevent modification of object prototypes through chart options containing a payload such...HighImproper Input Validation in url-jsThe package url-js before 2.1.0 is vulnerable to Improper Input Validation due to improper parsing, which makes it is possible for the hostname to be...MediumCWE-20Spoofing attack in swagger-ui-distThe swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to...MediumCWE-1021Sudden swap of user auth tokens in VoltoDue to the usage of an outdated version of the react-cookie library, under the circumstances of given a server high load, it is possible that...MediumCWE-287Cross-site Scripting in sanitize-urlThe package @braintree/sanitize-url before 6.0.0 is vulnerable to Cross-site Scripting (XSS) due to improper sanitization in the sanitizeUrl function.MediumCWE-79Server-Side Request Forgery in FUXAA Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive information from the server’s internal environment...HighCWE-918Command injection in launchpadAll versions of package launchpad are vulnerable to Command Injection via stop.HighCWE-77yargs-parser Vulnerable to Prototype PollutionAffected versions of yargs-parser are vulnerable to prototype pollution. Arguments are not properly sanitized, allowing an attacker to modify the prototype of Object, causing the...MediumCWE-915Prototype Pollution in algoliasearch-helperThe package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties....HighCWE-915Cross-site Scripting in CKEditor4The vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4.MediumCWE-79Prototype Pollution in mathjsThe package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.HighCWE-915Prototype Pollution in mout - moutThis affects all versions of package mout. The deepFillIn function can be used to ‘fill missing properties recursively’, while the deepMixIn ‘mixes objects into the...HighCWE-1321Prototype Pollution in set-inThe package set-in before 2.0.3 is vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to merge object prototypes into it....HighCWE-1321Prototype pollution vulnerability in js-extendPrototype pollution vulnerability in ‘js-extend’ versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.HighCWE-915Failure to validate signature during handshake@chainsafe/libp2p-noise before 4.1.2 and 5.0.3 was not correctly validating signatures during the handshake process.This may allow a man-in-the-middle to pose as other peers and get...HighCWE-347Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTMLThe vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4.HighCWE-79modern-async's `forEachSeries` and `forEachLimit` functions do not limit the number of requestsThis is a bug affecting two of the functions in this library: forEachSeries and forEachLimit. They should limit the concurrency of some actions but, in...HighCWE-770Prototype Pollution in ts-nodashts-nodash before version 1.2.7 is vulnerable to Prototype Pollution via the Merge() function due to lack of validation input.HighCWE-915Utils.readChallengeTx does not verify the server account signatureThe Utils.readChallengeTx function used in SEP-10 Stellar Web Authentication states in its function documentation that it reads and validates the challenge transaction including verifying that...MediumCWE-347Prototype Pollution in libnestedThe package libnested before 1.5.2 are vulnerable to Prototype Pollution via the set function in index.js. Note: This vulnerability derives from an incomplete fix for...HighCWE-1321Command Injection in ungitThe package ungit before 1.5.20 are vulnerable to Remote Code Execution (RCE) via argument injection. The issue occurs when calling the /api/fetch endpoint. User controlled...HighCWE-77Prototype pollution in supermixerPrototype pollution in Stampit supermixer allows an attacker to modify the prototype of a base object which can vary in severity depending on the implementation....HighCWE-1321Cross-site Scripting in @rocket.chat/livechatA blind self XSS vulnerability exists in RocketChat LiveChat versions lower than 1.9 that could allow an attacker to trick a victim pasting malicious code...MediumCWE-79URL Confusion When Scheme Not Supplied in medialize/uri.jsMedialize is a Javascript URL mutation library. When parsing a URL without a scheme and with excessive slashes, like ///www.example.com, URI.js will parse the hostname...MediumCWE-601Cross site scripting in valinevaline is a fast, simple & powerful comment system. Cross Site Scripting (XSS) vulnerability in xCss Valine v1.4.14 via the nick parameter to /classes/Comment. A...MediumCWE-79Cross-site Scripting in tableexport.jquery.pluginThere is a cross-site scripting vulnerability with default onCellHtmlData function in GitHub repository hhurz/tableexport.jquery.plugin prior to 1.25.0. This can result in transmitting cookies to third-party...MediumCWE-79Prototype Pollution in fullpage.jsfullPage utils are available to developers using window.fp_utils. They can use these utils for their own use-case (other than fullPage) as well. However, one of...HighCWE-1321Cross-site Scripting in fullpage.jsusing fullpage.js you can create a anchor tag . But when put href in anchor then it does not sanitize the url which allow for...MediumCWE-79Prototype Pollution in madlib-object-utilsThe package madlib-object-utils before version 0.1.8 is vulnerable to Prototype Pollution via the setValue method, as it allows an attacker to merge object prototypes into...HighCWE-1321Unrestricted Upload of File with Dangerous Type in ButterCMSAn arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.HighCWE-434Unrestricted Upload of File with Dangerous Type in PayloadAn arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file.HighCWE-434Improper handling of multiline messages in node-irc affects matrix-appservice-ircmatrix-appservice-irc provides an IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing IRC commands by having...HighCWE-74Cross-site Scripting in Auth0 LockIn versions before and including 11.32.2, when the “additional signup fields” feature is configured, a malicious actor can inject invalidated HTML code into these additional...MediumCWE-79Prototype Pollution in json-pointerThis affects versions of package json-pointer up to and including 0.6.1. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer...MediumCWE-843x-data-spreadsheet through 1.1.9 vulnerable to Cross-site ScriptingAll versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of values inserted into the cells.MediumCWE-79Prototype pollution in dojo - dojoIn affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution.HighCWE-94Improper Neutralization of Input During Web Page Generation in CKEditor4A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user...MediumCWE-79Improper Neutralization of Input During Web Page Generation in swagger-uiswagger-ui has XSS in key namesMediumCWE-79Improper Control of Generation of Code in doTThe dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if...HighCWE-94Improper Neutralization of Input During Web Page Generation in Select2In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when...MediumCWE-79Improper Removal of Sensitive Information Before Storage or Transfer in Strapi - @strapi/strapiAn authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for other...HighCWE-212Improper Removal of Sensitive Information Before Storage or Transfer in StrapiAn authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for API...HighCWE-212Improper Input Validation in DeapThe utilities function in all versions < 1.0.1 of the deap node module can be tricked into modifying the prototype of Object when the attacker...HighCWE-20AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributesVersions of angular prior to 1.5.0-beta.1 are vulnerable to Cross-Site Scripting. The package fails to sanitize xlink:href attributes, which may allow attackers to execute arbitrary...MediumCWE-79cruddl vulnerable to ArangoDB Query Language (AQL) injection through flexSearchIf a vunerable version of cruddl is used to generate a schema that uses @flexSearchFulltext, users of that schema may be able to inject arbitrary...HighCWE-74OpenPGP 1.2.0 and earlier decrypts arbitrary messagess2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is...HighUnsanitized JavaScript code injection possible in gatsby-plugin-mdxThe gatsby-plugin-mdx plugin prior to versions 3.15.2 and 2.14.1 passes input through to the gray-matter npm package, which is vulnerable to JavaScript injection in its...HighCWE-502Potential Sensitive Cookie Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxyThe nestjs-proxy library did not have a way to block sensitive cookies (e.g. session cookies) from being forwarded to backend services configured by the application...MediumCWE-200Improper handling of CSS at-rules in lettersanitizerAll versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule @keyframes.HighCWE-754Hostname confusion in parse-urlExposure of Sensitive Information to an Unauthorized Actor via hostname confusion in GitHub repository ionicabizau/parse-url prior to 6.0.1HighCWE-200Server-Side Request Forgery in parse-urlServer-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.HighCWE-918Potential Authorization Header Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxyThe nestjs-proxy library did not have a way to control when Authorization headers should should be forwarded for specific backend services configured by the application...MediumCWE-200jquery-validation Regular Expression Denial of Service due to arbitrary input to url2 methodSummaryHighCWE-1333Cross site scripting in parse-urlCross-site Scripting (XSS) - Generic in GitHub repository ionicabizau/parse-url prior to 6.0.1MediumCWE-79Prototype Pollution in deep-get-setAll versions of package deep-get-set are vulnerable to Prototype Pollution via the ‘deep’ function. Note: This vulnerability derives from an incomplete fix of CVE-2020-7715HighCWE-1321JWS and JWT signature validation vulnerability with special charactersJsrsasign supports JWS(JSON Web Signatures) and JWT(JSON Web Token) validation. However JWS or JWT signature with non Base64URL encoding special characters or number escaped characters...HighCWE-347Regular expression denial of service in react-nativeA regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This...HighCWE-697Server-Side Request Forgery in link-preview-jsThe package link-preview-js before 2.1.17 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read...MediumCWE-918Cross site scripting in parse-url - parse-urlCross-site Scripting (XSS) - Stored in GitHub repository ionicabizau/parse-url prior to 7.0.0.MediumCWE-79Authorization Bypass in parse-pathAuthorization Bypass Through User-Controlled Key in GitHub repository ionicabizau/parse-path prior to 5.0.0.HighCWE-639set-deep-prop Prototype PollutionAll versions of package set-deep-prop are vulnerable to Prototype Pollution via the main functionality.HighCWE-1321ion-parser Prototype Pollution when malicious INI file submitted to application that parses with `parse`This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with parse , they...HighCWE-1321node-import `params` argument can be controlled by users without any sanitizationThis affects all versions of package node-import. The params argument of module function can be controlled by users without any sanitization. This is then provided...Hights-deepmerge before 2.0.2 vulnerable to Prototype PollutionThe package ts-deepmerge before version 2.0.2 is vulnerable to Prototype Pollution due to missing sanitization of the merge function.HighCWE-1321markdown-it-toc Cross-site Scripting due to title of generated toc and contents of header not being escapedThis affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.MediumCWE-79grapesjs before 0.19.5 vulnerable to Cross-site ScriptingThe package grapesjs before 0.19.5 is vulnerable to Cross-site Scripting (XSS) due to an improper sanitization of the class name in Selector Manager.MediumCWE-79Improperly Controlled Modification of Dynamically-Determined Object Attributes in utilitifyutilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.HighCWE-915Improperly Controlled Modification of Dynamically-Determined Object Attributes in vega-utilvega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype....MediumCWE-915Prototype Pollution in cookiex/deepThe npm @cookiex/deep package before version 0.0.7 has a prototype pollution vulnerability. The global proto object can be polluted using the proto object.HighCWE-915Uncontrolled Resource Consumption in fun-mapfun-map through 3.3.1 is vulnerable to Prototype Pollution. The function assocInM could be tricked into adding or modifying properties of ‘Object.prototype’ using a ‘proto’ payload....HighCWE-915Prototype Pollution in arr-flatten-unflattenAll versions of package arr-flatten-unflatten up to and including version 1.1.4 are vulnerable to Prototype Pollution via the constructor.HighCWE-1321Prototype pollution in class-transformerclass-transformer through 0.2.3 is vulnerable to Prototype Pollution. The ‘classToPlainFromExist’ function could be tricked into adding or modifying properties of ‘Object.prototype’ using a ‘proto’ payload....MediumCWE-915Prototype Pollution in madlib-object-utils - madlib-object-utilsmadlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.HighCWE-915Prototype Pollution in x-assignThis vulnerability affects all versions of package x-assign. The global proto object can be polluted using the proto object.HighCWE-915Solana Pay Vulnerable to Weakness in Transfer Validation LogicWhen a Solana Pay transaction is located using a reference key, it may be checked to represent a transfer of the desired amount to the...MediumCWE-670Cross-Site Scripting in min-http-serverAll versions of min-http-server are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize filenames, allowing attackers to execute arbitrary JavaScript in the victim’s...MediumCWE-79Prototype pollution in chart.jsThis affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing...HighCWE-915Prototype Pollution in property-exprThe package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.HighCWE-915RSA-PSS signature validation vulnerability by prepending zeros in jsrsasignJsrsasign can verify RSA-PSS signature which value can expressed as BigInteger. When there is a valid RSA-PSS signature value, this vulnerability is also accept value...HighCWE-119Cross site scripting in mobiledoc-kitCross-site Scripting (XSS) - Reflected in GitHub repository bustle/mobiledoc-kit prior to 0.14.2.MediumCWE-79Uncontrolled Resource Consumption in node-opcuaThe package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per...HighCWE-400parse-url parses http URLs incorrectly, making it vulnerable to host name spoofingparse-url prior to 8.1.0 is vulnerable to Misinterpretation of Input. parse-url parses certain http or https URLs incorrectly, identifying the URL’s protocol as ssh. It...MediumCWE-115Matrix-appservice-irc vulnerable to sql injection via roomIds argumentA vulnerability was found in matrix-appservice-irc up to 0.35.1. This vulnerability affects the file src/datastore/postgres/PgDataStore.ts. The manipulation of the argument roomIds leads to sql injection....MediumCWE-89deep-object-diff vulnerable to Prototype Pollutiondeep-object-diff before version 1.1.6 allows an external attacker to edit or add new properties to an object. This is possible because the application does not...MediumCWE-1321Cross-site scripting vulnerability in TinyMCE alertsA cross-site scripting (XSS) vulnerability was discovered in the alert and confirm dialogs when these dialogs were provided with malicious HTML content. This can occur...MediumCWE-79@cubejs-backend/api-gateway row level security bypassAll authenticated Cube clients could bypass row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint.HighCWE-89dustjs-linkedin vulnerable to Prototype PollutionA vulnerability was found in LinkedIn dustjs prior to version 3.0.0 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation...HighCWE-94Jodit Editor vulnerable to Cross-site Scripting - joditJodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vulnerable to XSS attacks when pasting...MediumCWE-79secp256k1-js implements ECDSA without required r and s validation, leading to signature forgeryThe secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.HighCWE-347matrix-appservice-irc vulnerable to IRC mode parameter confusionIRC allows you to specify multiple modes in a single mode command. Due to a bug in the underlying matrix-org/node-irc library, affected versions of matrix-appservice-irc...MediumCWE-269Parsing issue in matrix-org/node-irc leading to room takeoversAttackers can specify a specific string of characters, which would confuse the bridge into combining an attacker-owned channel and an existing channel, allowing them to...HighCWE-269@mattkrick/sanitize-svg vulnerable to Cross-Site Scripting (XSS)The sanitize-svg package uses a deny-list-pattern to sanitize SVGs to prevent cross-site scripting (XSS). In doing so, literal <script>-tags and on-event handlers were detected:HighCWE-79Cross-site Scripting in JoplinAn XSS issue in Joplin desktop allows arbitrary code execution via a malicious HTML embed tag.MediumCWE-79inflect vulnerable to Inefficient Regular Expression Complexityinflect is customizable inflections for nodejs. inflect is vulnerable to Inefficient Regular Expression ComplexityHighCWE-1333merge vulnerable to Prototype Pollutionmerge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’)HighCWE-915cumulative-distribution-function Infinite Loop vulnerabilityA flaw enabling an infinite-loop was discovered in the code for evaluating the cumulative-distribution-functionof input data. Although the documentation explains that numeric data is required,...HighCWE-835prismjs Regular Expression Denial of Service vulnerabilityPrism is a syntax highlighting library. The prismjs package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide...MediumCWE-400Improper Input Validation in Google Closure LibraryA URL parsing issue in goog.uri of the Google Closure Library versions up to and including v20200224 allows an attacker to send malicious URLs to...MediumCWE-20deep-parse-json vulnerable to Prototype Pollutiondeep-parse-json version 1.0.2 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly...MediumCWE-1321Improper Control of Generation of Code ('Code Injection') in mdx-mermaidArbitary javascript injectionLowCWE-94DOM-based cross-site scripting in Froala EditorFroala WYSIWYG HTML Editor is a lightweight WYSIWYG HTML Editor written in JavaScript that enables rich text editing capabilities for web applications. A DOM-based cross-site...MediumCWE-79Options structure open to Cross-site Scripting if passed unfilteredIn Highcharts versions 8 and earlier, the chart options structure was not systematically filtered for XSS vectors. The potential impact was that content from untrusted...HighCWE-79Prototype poisoningThe issue is as follows: when msgpack5 decodes a map containing a key "__proto__", it assigns the decoded value to __proto__. As you are no...MediumCWE-915Remote code execution in Eclipse TheiaIn Eclipse Theia 0.3.9 to 1.8.1, the “mini-browser” extension allows a user to preview HTML files in an iframe inside the IDE. But with the...HighCWE-942Joplin is vulnerable to arbitrary code executionJoplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.HighCWE-79Smoothie vulnerable to Cross-site Scripting when tooltipLabel or strokeStyle are controlled by usersThe package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties....MediumCWE-79node-opcua DoS vulnerability via message with memory allocation that exceeds v8's memory limitThe package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA message with a special OPC UA...HighCWE-770node-opcua DoS when bypassing limitations for excessive memory consumptionThe package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests...HighCWE-400matrix-js-sdk subject to user impersonation due to key/device identifier confusion in SAS verificationAn attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user identity in place of...HighCWE-322steal vulnerable to Prototype Pollution via optionName variablePrototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js.HighCWE-1321Inefficient Regular Expression Complexity in vuelidatevuelidate is a simple, lightweight model-based validation for Vue.js 2.x & 3.0. A ReDoS (regular expression denial of service) flaw was found in the @vuelidate/validators...HighCWE-697TypeORM vulnerable to MAID and Prototype PollutionPrototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or...HighCWE-471Improper beacon events in matrix-js-sdk can result in availability issuesImproperly formed beacon events (from MSC3488) can disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer’s ability to process data safely. Note...MediumCWE-20steal vulnerable to Prototype Pollution via key variable in babel.jsPrototype pollution vulnerability in function extend in babel.js in stealjs steal via the key variable in babel.js.HighCWE-1321steal vulnerable to Prototype Pollution via requestedVersion variablePrototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal via the requestedVersion variable in the npm-convert.js file.HighCWE-1321matrix-js-sdk subject to impersonated messages due to permissive key forwardingAn attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey...HighCWE-287CKEditor 5 Markdown plugin Regular expression Denial of ServiceA regular expression denial of service (ReDoS) vulnerability has been discovered in the CKEditor 5 Markdown plugin code. The vulnerability allowed to abuse a link...MediumCWE-400matrix-js-sdk subject to user spoofing via Olm/Megolm protocol confusionAn attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a...HighCWE-322ejs template injection vulnerabilityThe ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and...HighCWE-74@dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability DetailsDue to the common practice of providing vulnerability details in markdown format, the Dependency-Track frontend renders them using the JavaScript library Showdown. Showdown does not...MediumCWE-79jsx-slack insufficient patch for CVE-2021-43838 ReDoSWe found the patch for CVE-2021-43838 in jsx-slack v4.5.1 is insufficient to save from Regular Expression Denial of Service (ReDoS) attack.MediumCWE-400jquery.terminal self XSS on user inputThis is low impact and limited XSS, because code for XSS payload is always visible, but attacker can use other techniques to hide the code...LowCWE-80Vuetify Cross-site Scripting vulnerabilityThe package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the ‘eventName’ function within the...MediumCWE-79Prototype Pollution in moutThis affects all versions of package mout. The deepFillIn function can be used to ‘fill missing properties recursively’, while the deepMixIn mixes objects into the...HighCWE-1321Fastly Compute@Edge JS Runtime has fixed random number seed during compilationMath.random and crypto.getRandomValues methods failed to use sufficiently random values. The initial value to seed the CSPRNG (cryptographically secure pseudorandom number generator) was baked-in to...HighCWE-335React Editable Json Tree vulnerable to arbitrary code execution via function parsingOur library allows strings to be parsed as functions and stored as a specialized component, JsonFunctionValue. To do this, Javascript’s eval function was used to...HighCWE-95Cross-site Scripting (XSS) in serve-liteAll versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file...MediumCWE-79Directory Traversal vulnerability in serve-liteAll versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employed to the req.url...HighCWE-22TaffyDB can allow access to any data items in the DB - taffyTaffyDB allows attackers to forge adding additional properties into user-input processed by taffy which can allow access to any data items in the DB. Taffy...HighCWE-668TaffyDB can allow access to any data items in the DBTaffyDB allows attackers to forge adding additional properties into user-input processed by taffy which can allow access to any data items in the DB. Taffy...HighCWE-668RSA PKCS#1 decryption vulnerability with prepending zeros in jsrsasignJsrsasign supports RSA PKCS#1 v1.5 (i.e. RSAES-PKCS1-v1_5) and RSA-OAEP encryption and decryption. Its encrypted message is represented as BigInteger. When there is a valid encrypted...HighCWE-119ECDSA signature validation vulnerability by accepting wrong ASN.1 encoding in jsrsasignJsrsasign supports ECDSA signature validation which signature value is represented by ASN.1 DER encoding. This vulnerablity may accept a wrong ASN.1 DER encoded ECDSA signature...HighCWE-347Prototype Pollution in dojoAll versions of package dojo are vulnerable to Prototype Pollution via the setObject function.HighCWE-1321Path Traversal in mcstaticAll versions of mcstatic are vulnerable to path traversal.HighCWE-22metascraper before v5.2.0 vulnerable to stored cross-site scriptingVersions of metascraper prior to 5.2.0 are vulnerable to stored cross-site scripting (XSS).MediumCWE-79CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - @ckeditor/ckeditor5-html-support@ckeditor/ckeditor5-markdown-gfm@ckeditor/ckeditor5-html-support@ckeditor/ckeditor5-html-embedMediumCWE-79CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - @ckeditor/ckeditor5-markdown-gfm@ckeditor/ckeditor5-markdown-gfm@ckeditor/ckeditor5-html-support@ckeditor/ckeditor5-html-embedMediumCWE-79CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process@ckeditor/ckeditor5-markdown-gfm@ckeditor/ckeditor5-html-support@ckeditor/ckeditor5-html-embedMediumCWE-79@ianwalter/merge Prototype Pollution via `merge` functionAll versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. @ianwalter/merge is deprecated and the maintainer suggests using @generates/merger instead....MediumCWE-1321Nadesiko3 OS Command Injection vulnerabilityOS command injection vulnerability in Nadesiko3 (PC Version) v3.3.68 and earlier allows a remote attacker to execute an arbitrary OS command when processing compression and...HighCWE-78nadesiko3 allows remote attacker to inject invalid value to decodeURIComponent of nako3editNako3edit is the editor component of Nadeshiko 3, a programming language developed based on Japanese. Improper check or handling of exceptional conditions in Nako3edit v3.3.74...MediumCWE-755nadesiko3 vulnerable to OS Command InjectionOS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain appkey of the product...HighCWE-78steal vulnerable to Prototype PollutionPrototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js.HighCWE-1321Valine code injection vulnerabilityValine was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.HighCWE-79Toast UI Grid vulnerable to Cross-site ScriptingToast UI Grid is a component to display and edit data. Versions prior to 4.21.3 are vulnerable to cross-site scripting attacks when pasting specially crafted...MediumCWE-79steal vulnerable to Prototype Pollution via alias variablePrototype pollution vulnerability in stealjs steal via the alias variable in babel.js.HighCWE-1321Regular Expression Denial of Service in ua-parser-jsThe package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA....HighCWE-400Prototype Pollution in dsetAll versions of dset prior to 3.1.2 are vulnerable to Prototype Pollution via dset/merge mode, as the dset function checks for prototype pollution by validating...MediumCWE-1321materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user inputAll versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being...MediumCWE-79Privilege Issues in jailedAll versions of package jailed are vulnerable to Sandbox Bypass via an exported alert() method which can access the main application. Exported methods are stored...HighPrototype Pollution in DexieDexie is a minimalistic wrapper for IndexedDB. The package dexie before 3.2.2, from 4.0.0-alpha.1 and before 4.0.0-alpha.3 are vulnerable to Prototype Pollution in the Dexie.setByKeyPath(obj,...HighCWE-1321Insecure password handling vulnerability in StrapiStoring passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a...HighCWE-922Cross-site Scripting in video.jsThis affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execute arbitrary code.MediumCWE-79Cross-site Scripting in jquery.json-viewerThe jquery.json-viewer library before version 1.5.0 for Node.js does not properly escape characters such as < in a JSON object, as demonstrated by a SCRIPT...MediumCWE-79Cross-site Scripting in pandao editor.mdpandao Editor.md 1.5.0 allows XSS via the Javascript: string.MediumCWE-79Invalid Curve Attack in openpgpVersions of openpgp prior to 4.3.0 are vulnerable to an Invalid Curve Attack. The package’s implementation of ECDH fails to verify the validity of the...MediumCWE-327Cross-site Scripting in node-red-dashboardIt is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.MediumCWE-79Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-hgch-jjmr-gp7wVersions of safer-eval before 1.3.2 are vulnerable to Sandbox Escape leading to Remote Code Execution. A payload using constructor properties can escape the sandbox and...HighCWE-94Cross-site Scripting in pandaopandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.MediumCWE-79Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-r3x4-wr4h-pw33Versions of safer-eval prior to 1.3.4 are vulnerable to Sandbox Escape leading to Remote Code Execution. A payload using constructor properties can escape the sandbox...HighCWE-94XSS in knockoutThere is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its...MediumCWE-79Uncaught exception in engine.ioA specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process.MediumCWE-248Denial of Service and Content Injection in i18n-node-angularVersions of i18n-node-angular prior to 1.4.0 are affected by denial of service and cross-site scripting vulnerabilities. The vulnerabilities exist in a REST endpoint that was...HighCWE-74Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-evalAll versions of safer-eval are vulnerable to Sandbox Escape leading to Remote Code Execution. The package fails to restrict access to the main context and...HighCWE-94node-red-dashboard vulnerable to Cross-site Scriptingnode-red-dashboard contains a cross-site scripting vulnerability. This issue affects some unknown processing of the file components/ui-component/ui-component-ctrl.js of the component ui_text Format Handler. The attack may...MediumCWE-79Cross-Site Scripting in @novnc/novncVersions of @novnc/novnc prior to 0.6.2 are vulnerable to Cross-Site Scripting (XSS). The package fails to validate input from the remote VNC server such as...MediumCWE-79Cross-site Scripting in Joplin - joplin - GHSA-6r7x-hc8m-985rJoplin through 1.0.184 allows Arbitrary File Read via Cross-site Scripting (XSS).MediumCWE-79Unprotected dynamically loaded chunksAll dynamically loaded chunks receive an invalid integrity hash that is ignored by the browser, and therefore the browser cannot validate their integrity. This removes...LowCWE-345Prototype Pollution in highlight.jsAffected versions of this package are vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will result in prototype pollution of...MediumCWE-471Axios vulnerable to Server-Side Request ForgeryAxios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that...MediumCWE-918regular expression denial of service (ReDoS) - date-and-timedate-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be...HighCWE-400Regular Expression Denial of Service (REDoS) in MarkedRegular expression Denial of ServiceMediumCWE-400SSRF in RendertronRendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force...MediumCWE-918Prototype pollution in JointJS - jointjsThe package jointjs before 3.3.0 are vulnerable to Prototype Pollution via util.setByPath (https://resources.jointjs.com/docs/jointjs/v3.2/joint.htmlutil.setByPath). The path used the access the object’s key and set the value...HighCWE-400Angular Expressions - Remote Code ExecutionThe vulnerability, reported by GoSecure Inc, allows Remote Code Execution, if you call expressions.compile(userControlledInput) where userControlledInput is text that comes from user input.HighCWE-94Prototype pollution in set-in - set-inPrototype pollution vulnerability in ‘set-in’ versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service and may lead to remote code execution.HighCWE-1321Cross-site Scripting in vis-timelineThis affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code...MediumCWE-79Regular expression Denial of Service in @progfay/scrapbox-parserA Regular expression Denial of Service flaw was found in the @progfay/scrapbox-parser package before 6.0.3, 7.0.2 for Node.js.The attacker that is able to be parsed...MediumCWE-400Cross-site Scripting (XSS) in Eclipse TheiaIn Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code.HighCWE-79[thi.ng/egf] Potential arbitrary code execution of `#gpg`-tagged property valuesPotential for arbitrary code execution in #gpg-tagged property values (only if decrypt: true option is enabled)MediumCWE-78Prototype Pollution Vulnerability in object-colliderPrototype pollution vulnerability in ‘object-collider’ versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution.HighCWE-1321Denial of Service (DoS) via the unsetByPath function in jsjointsThe package jointjs before 3.3.0 are vulnerable to Denial of Service (DoS) via the unsetByPath function.HighCWE-400Hostname spoofing via backslashes in URLIf using affected versions to determine a URL’s hostname, the hostname can be spoofed by using a backslash (\) character followed by an at (@)...MediumCWE-20Improper Neutralization of Input in Theia consoleIn Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected....MediumCWE-79XSS in VegaVega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package.In Vega before version 5.17.3...LowCWE-79Cross-site scripting in SocksJS-nodehtmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulnerable to Reflected XSS via the /htmlfile c (aka callback) parameter.MediumCWE-79Path traversal in Node-RED-DashboardIn Node-RED-Dashboard before 2.26.2 there is a path traversal vulnerability. It allows ui_base/js/..%2f directory traversal to read files.HighCWE-22Prototype Pollution in dot-objectdot-object before 2.1.3 is vulnerable to Prototype Pollution. The set function could be tricked into adding or modifying properties of Object.prototype using a proto payload....MediumCWE-74Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-engineA regular expression denial of service (ReDoS) vulnerability has been discovered in multiple CKEditor 5 packages. The vulnerability allowed to abuse particular regular expressions, which...MediumCWE-400Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-fontA regular expression denial of service (ReDoS) vulnerability has been discovered in multiple CKEditor 5 packages. The vulnerability allowed to abuse particular regular expressions, which...MediumCWE-400Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-imageA regular expression denial of service (ReDoS) vulnerability has been discovered in multiple CKEditor 5 packages. The vulnerability allowed to abuse particular regular expressions, which...MediumCWE-400Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-listA regular expression denial of service (ReDoS) vulnerability has been discovered in multiple CKEditor 5 packages. The vulnerability allowed to abuse particular regular expressions, which...MediumCWE-400Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-media-embedA regular expression denial of service (ReDoS) vulnerability has been discovered in multiple CKEditor 5 packages. The vulnerability allowed to abuse particular regular expressions, which...MediumCWE-400Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-paste-from-officeA regular expression denial of service (ReDoS) vulnerability has been discovered in multiple CKEditor 5 packages. The vulnerability allowed to abuse particular regular expressions, which...MediumCWE-400Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-widgetA regular expression denial of service (ReDoS) vulnerability has been discovered in multiple CKEditor 5 packages. The vulnerability allowed to abuse particular regular expressions, which...MediumCWE-400Regular expression Denial of Service in multiple packagesA regular expression denial of service (ReDoS) vulnerability has been discovered in multiple CKEditor 5 packages. The vulnerability allowed to abuse particular regular expressions, which...MediumCWE-400Server-Side Request Forgery in private-ipInsufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF.HighCWE-918Prototype Pollution in decal - decalThis affects all versions of package decal. The vulnerability is in the set function.HighCWE-400Regular Expression Denial of Service (ReDoS) in ua-parser-jsua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of service. If an attacker sends a malicious User-Agent header,...HighCWE-400Arbitrary code execution in djvThis affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine.HighCWE-94Prototype pollution in set-object-valuePrototype pollution vulnerability in ‘set-object-value’ versions 0.0.0 through 0.0.5 allows an attacker to cause a denial of service and may lead to remote code execution....HighCWE-1321Prototype Pollution in copy-propsThe package copy-props before 2.0.5 are vulnerable to Prototype Pollution via the main functionality.HighCWE-1321Regular Expression Denial of Service in hosted-git-infoThe npm package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js....MediumCWE-400Improper Input Validation in klonaFlaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution or...HighCWE-20Improper Input Validation in sanitize-html - sanitize-htmlApostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the “allowedIframeHostnames” option when the “allowIframeRelativeUrls” is set to true, which allows...MediumCWE-20Insufficient Verification of Data Authenticity in Eclipse TheiaIn Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is “Mini-Browser”, published as “@theia/mini-browser” on npmjs.com.HighCWE-345Improper Input Validation in SocksJS-NodeIncorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.MediumCWE-20Prototype Pollution in undefsafeundefsafe before 2.0.3 is vulnerable to Prototype Pollution. The ‘a’ function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload....MediumCWE-74Resource exhaustion in socket.io-parserThe socket.io-parser npm package before versions 3.3.2 and 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a...HighCWE-400Padding Oracle Attack due to Observable Timing Discrepancy in josejose is an npm library providing a number of cryptographic operations.MediumCWE-696Prototype pollution in json8-merge-patchPrototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.HighCWE-471Cross-site Scripting in reveal.js - reveal.jsInsufficient validation in cross-origin communication (postMessage) in reveal.js version 3.9.1 and earlier allow attackers to perform cross-site scripting attacks.MediumCWE-79Improper Authentication in react-adalThis affects versions of react-adal < 0.5.1. It is possible for a specially crafted JWT token and request URL can cause the nonce, session and...HighCWE-287Prototype pollution in pathvalA prototype pollution vulnerability affects all versions of package pathval under 1.1.1.HighCWE-20Prototype Pollution in set-or-getPrototype pollution vulnerability in ‘set-or-get’ version 1.0.0 through 1.2.10 allows an attacker to cause a denial of service and may lead to remote code execution....HighCWE-1321Regular expression denial of service in codemirrorThis affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129.MediumCWE-400Regular Expression Denial of Service in dat.guiAll versions of package dat.gui are vulnerable to Regular Expression Denial of Service (ReDoS) via specifically crafted rgb and rgba values.HighCWE-400Regular Expression Denial of Service in trimAll versions of package trim lower than 0.0.3 are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().HighCWE-400Cross-site scripting in @atlaskit/editor-coreThe hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in...MediumCWE-79Buffer overflow in canvasA buffer overflow is present in canvas versions before 1.6.11, which could lead to a Denial of Service or execution of arbitrary code when it...HighCWE-120Prototype pollution in json8This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly...HighCWE-1321Prototype Pollution in node-oojsAll versions of package node-oojs up to and including version 1.4.0 are vulnerable to Prototype Pollution via the setPath function.HighCWE-1321Prototype Pollution in phpjsAll versions of phpjs up to and including 1.3.2 are vulnerable to Prototype Pollution via parse_str. phpjs is no longer maintained and users are advised...HighCWE-1321Prototype Pollution in promisehelpersAll versions of package promisehelpers up to and including version 0.0.5 are vulnerable to Prototype Pollution via the insert function.HighCWE-1321Regular expression denial of service in @absolunet/kafeThis affects the package @absolunet/kafe before 3.2.10. It allows cause a denial of service when validating crafted invalid emails.MediumCWE-400Path traversal in rollup-plugin-servePath traversal in npm package rollup-plugin-serve before version 1.0.2. There is no path sanitization in readFile operation.HighCWE-22Prototype Pollution in tiny-confAll versions of package tiny-conf up to and including version 1.1.0 are vulnerable to Prototype Pollution via the set function.HighCWE-1321Improper Input Validation in access-policyaccess-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the template function is executed by the eval function resulting in code...HighCWE-94Improper parsing of octal bytes in netmaskImproper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks...HighCWE-20Prototype Pollution in gediAll versions of package gedi up to and including version 1.6.3 are vulnerable to Prototype Pollution via the set function.HighCWE-1321Insecure template handling in haml-coffeehaml-coffee is a JavaScript templating solution. haml-coffee mixes pure template data with engine configuration options through the Express render API. More specifically, haml-coffee supports overriding...HighCWE-79Regular Expression Denial of Service in postcss - postcssThe npm package postcss from 7.0.0 and before versions 7.0.36 and 8.2.10 is vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing....MediumCWE-400Cross-site scripting in Joplin - joplinJoplin allows XSS via a LINK element in a note.MediumCWE-79Cross-site Scripting in aurelia-frameworkThe HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnerable to XSS. The sanitizer only attempts to filter...MediumCWE-79Validation bypass in jpvjpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.HighCWE-20Command Injection in @theia/messagesIn Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.MediumCWE-829Exposure of Resource to Wrong Sphere in valibvalib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function...MediumCWE-668Prototype Pollution in swiperVersions of the package swiper before 6.5.1 are susceptible to prototype pollution.HighCWE-1321ua-parser-js Regular Expression Denial of Service vulnerabilityThe package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).HighCWE-400Injection and Command Injection in devcertA command injection vulnerability in the devcert module may lead to remote code execution when users of the module pass untrusted input to the certificateFor...HighCWE-78Uncontrolled Resource Consumption in firebaseThis affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided,...MediumCWE-400Code Injection in cd-messengercd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the color argument executed by the eval function resulting in code execution....HighCWE-94Prototype pollution in controlled-mergePrototype pollution vulnerability in ‘controlled-merge’ versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution.HighCWE-1321Prototype Pollution in deep-get-set - deep-get-setAll versions of package deep-get-set prior to version 1.1.1 are vulnerable to Prototype Pollution via the main function.HighCWE-1321Prototype Pollution in safe-object2All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.HighCWE-1321Cross-site Scripting in docsifydocsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources from server-side .md files....MediumCWE-79Code Injection in moscmosc through 1.0.0 is vulnerable to Arbitrary Code Execution. User input provided to properties argument is executed by the eval function, resulting in code execution....HighCWE-94Prototype Pollution in deep-overridePrototype pollution vulnerability in ‘deep-override’ versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution....HighCWE-1321Cross-site scripting in react-bootstrap-tableAll versions of package react-bootstrap-table are vulnerable to Cross-site Scripting (XSS) via the dataFormat parameter. The problem is triggered when an invalid React element is...MediumCWE-79Regular Expression Denial of Service (ReDoS) in PrismSome languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS).HighCWE-400Widget feature vulnerability allowing to execute JavaScript code using undo functionalityThe vulnerability has been discovered in Widget plugin if used alongside Undo feature.HighCWE-79Prototype pollution in safe-objPrototype pollution vulnerability in ‘safe-obj’ versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote code execution....HighCWE-1321Clipboard feature vulnerability allowing to inject arbitrary HTML into the editor using paste functionalityThe vulnerability has been discovered in clipboard plugin. All plugins with clipboard plugin dependency are affected:MediumCWE-94Denial of service in ValineValine is a fast, simple & powerful comment system. Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a...MediumCWE-94Reflected XSS when using flashMessages or languageDictionaryVersions before and including 11.30.0 are vulnerable to reflected XSS. An attacker can execute arbitrary code when the library’s flashMessage feature is utilized and user...HighCWE-79Passing in a non-string 'html' argument can lead to unsanitized outputA type-confusion vulnerability can cause striptags to concatenate unsanitized strings when an array-like object is passed in as the html parameter. This can be abused...MediumCWE-843ReDOS in IS-SVGA vulnerability was discovered in IS-SVG version 4.3.1 and below where a Regular Expression Denial of Service (ReDOS) occurs if the application is provided and...HighCWE-770Regular Expression Denial of Service (ReDOS) - color-stringIn the npm package color-string, there is a ReDos (Regular Expression Denial of Service) vulnerability regarding an exponential time complexity forlinearly increasing input lengths for...MediumCWE-770Cross-site Scripting in curly-bracket-parserThis affects all versions of package curly-bracket-parser. When used as a template library, it does not properly sanitize the user input.MediumCWE-79Fake objects feature vulnerability allowing to execute JavaScript code using malformed HTML.The vulnerability has been discovered in Fake Objects plugin. All plugins with Fake Objects plugin dependency are affected:HighCWE-79Prototype Pollution in deepmergefnAll versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function.MediumCWE-915Clipboard-based DOM-XSSA self Cross-Site Scripting vulnerability exists in the @github/paste-markdown library.MediumCWE-79Prototype Pollution in mootoolsThis affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()MediumCWE-1321Incorrect Calculation in the MSR JavaScript Cryptography LibraryA Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic Curve Cryptography (ECC)...HighCWE-682Cross-site Scripting in file-upload-with-previewThis affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name can be uploaded (a user needs to be tricked...MediumCWE-79Prototype Pollution in jointjsThis affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the...MediumCWE-843Uncontrolled Resource Consumption in transpileAll versions of package transpile are vulnerable to Denial of Service (DoS) due to a lack of input sanitization or whitelisting, coupled with improper exception...MediumCWE-755Path traversalA malicious actor could read sensitive files from the environment where TechDocs documentation is built and published by setting a particular path for docs_dir in...MediumCWE-22Prototype pollution vulnerability in 'patchmergePrototype pollution vulnerability in ‘patchmerge’ versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution....HighCWE-1321Script injection - @backstage/plugin-techdocsA malicious internal actor can potentially upload documentation content with malicious scripts by embedding the script within an object element. This may give access to...MediumCWE-77Script injectionA malicious internal actor is able to upload documentation content with malicious scripts. These scripts would normally be sanitized by the TechDocs frontend, but by...MediumCWE-77Cross-site Scripting in jsoneditorStored XSS was discovered in the tree mode of jsoneditor before 9.0.2 through injecting and executing JavaScript.MediumCWE-79Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor,...MediumCWE-829Basic-auth app bundle credential exposure in gatsby-source-wordpressThe gatsby-source-wordpress plugin prior to versions 4.0.8 and 5.9.2 leaks .htaccess HTTP Basic Authentication variables into the app.js bundle during build-time. Users who are not...HighCWE-522Cross-site Scripting in MermaidMermaid before 8.11.0 allows XSS when the antiscript feature is used.MediumCWE-79Cross-site Scripting in tempuraThis affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is returned without...MediumCWE-79Improper Input Validation in is-emailis-email helps validate an email address. A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js....HighCWE-400Prototype pollution in aurelia-pathThe vulnerability exposes Aurelia application that uses aurelia-path package to parse a string. The majority of this will be Aurelia applications that employ the aurelia-router...HighCWE-915XSS vulnerability allowing arbitrary JavaScript executionToday we are releasing Grafana 8.2.3. This patch release includes an important security fix for an issue that affects all Grafana versions from 8.0.0-beta1.MediumCWE-79Cross-site scripting in anchormeAll versions of package anchorme are vulnerable to Cross-site Scripting (XSS) via the main functionality.MediumCWE-79Cross-site Scripting in Froala Editor - froala-editorFroala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads to persistent Cross-site scripting (XSS) vulnerability within...MediumCWE-79Cross Site Request Forgery in kindeditorCross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x. First, you upload an html file containing csrf on the website that uses a google...HighCWE-352GraphiQL introspection schema template injection attackThis is a security advisory for an XSS vulnerability in graphiql.HighCWE-79Unauthorized access to data in @sap-cloud-sdk/coreThis affects applications on SAP Business Technology Platform that use the SAP Cloud SDK and enabled caching of destinations.In some cases, when user information was...MediumCWE-200Uncontrolled Resource Consumption in trim-off-newlinesAll versions of package trim-off-newlines are vulnerable to Regular Expression Denial of Service (ReDoS) via string processing.MediumCWE-400Prototype Pollution in merge-changeAll current versions of package merge-change are vulnerable to Prototype Pollution via the utils.set function.HighCWE-915Unsafe defaults in `remark-html`The documentation of remark-html has mentioned that it was safe by default. In practise the default was never safe and had to be opted into....HighCWE-79Prototype pollution vulnerability in 'deeprefPrototype pollution vulnerability in ‘deepref’ versions 1.1.1 through 1.2.1 allows attacker to cause a denial of service and may lead to remote code execution.HighCross-site Request Forgery (CSRF) in joplinThe package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.MediumCWE-352Cross site scripting in kindeditorCross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this...MediumCWE-79Prototype Pollution in ProtoThis affects all versions of package Proto. It is possible to inject pollute the object property of an application using Proto by leveraging the merge...HighCWE-1321Clipboard-based XSSXSS against the user.HighCWE-79Improper Verification of Communication Channel in @theia/plugin-extIn versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().MediumCWE-940Code injection in pluploadThis affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a...MediumCWE-75Prototype pollution vulnerability in 'libnestedPrototype pollution vulnerability in ‘libnested’ versions 0.0.0 through 1.5.0 allows an attacker to cause a denial of service and may lead to remote code execution....HighRisk of code injectionSome routes use eval or Function constructor, which may be injected by the target site with unsafe code, causing server-side security issuesHighCWE-74Insecure random number generation in keypairA bug in the pseudo-random number generator used by keypair versions up to and including 1.0.3 could allow for weak RSA key generation. This could...HighCWE-335Cross-Site Scripting Vulnerability in @joeattardi/emoji-buttonThere are two vectors for XSS attacks with versions of @joeattardi/emoji-button before 4.6.2:HighCWE-79Prototype Pollution in dotty - dottyThis affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the...MediumCWE-843Cross-site Scripting in pekeuploadThis affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains javascript code, the javascript code...MediumCWE-79Prototype Pollution in @fabiocaccamo/utils.jsutils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’).HighCWE-1321Strapi mishandles hidden attributes within admin API responsesStrapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.HighCWE-89Twitter-Post-Fetcher vulnerable to Use of Web Link to Untrusted Target with window.opener AccessA vulnerability classified as problematic has been found in Twitter-Post-Fetcher up to 17.x. This affects an unknown part of the file js/twitterFetcher.js of the component...MediumCWE-1022Misinterpretation of malicious XML input - xmldom - GHSA-h6q6-9hqw-rwfvxmldom versions 0.4.0 and older do not correctly preserve system identifiers, FPIs or namespaces when repeatedly parsing and serializing maliciously crafted documents.MediumCWE-436liquidjs may leak properties of a prototypeThe package liquidjs before 10.0.0 is vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking properties of a prototype....MediumCWE-200Expo on iOS is insecure due incorrect security attribute applicationsecure-store in Expo through 9.1.0 on iOS provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN_UNLOCKED_THIS_DEVICE_ONLY is used.MediumMarkdown-Nice v1.8.22 vulnerable to Cross-site ScriptingA cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community...MediumCWE-79Cross-site Scripting in Bootstrap-3-TypeaheadBootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute...MediumCWE-79Cross-site Scripting in bootstrap-tableBootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure...MediumCWE-79markdown-it vulnerable to Inefficient Regular Expression ComplexityA vulnerability was found in markdown-it up to 2.x. It has been classified as problematic. Affected is an unknown function of the file lib/common/html_re.js. The...HighCWE-1333string-kit Inefficient Regular Expression Complexity vulnerabilityA vulnerability classified as problematic was found in cronvel string-kit up to 0.12.7. This vulnerability affects the function naturalSort of the file lib/naturalSort.js. The manipulation...HighCWE-1333Json2html vulnerable to cross-site scriptingJson2html is a client side javascript HTML templating library with wrappers for both jQuery and Node.js. A vulnerability was found in moappi Json2html up to...MediumCWE-79Cross site scripting in Metro UIMetro UI v4.4.0 to v4.5.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function. User input is not properly sanitized...MediumCWE-79Regular Expression Denial of Service in moment - momentVersions of moment prior to 2.11.2 are affected by a regular expression denial of service vulnerability. The vulnerability is triggered when arbitrary user input is...MediumCWE-400Prototype Pollution in js-data - js-dataAll versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of CVE-2020-28442.HighCWE-1321uppy's companion module is vulnerable to Server-Side Request Forgery (SSRF) - uppyuppy’s companion module is vulnerable to Server-Side Request Forgery (SSRF) via IPv4-mapped IPv6 addresses.HighCWE-918Reflected cross-site scripting (XSS) vulnerabilityThis security advisory relates to a capability for an attacker to exploit a reflected cross-site scripting vulnerability when using the @keystone-6/auth package.HighCWE-79Incorrect sanitisation function leads to `XSS` in mermaidMalicious diagrams can contain javascript code that can be run at diagram readers machines.HighCWE-79Prototype Pollution in realms-shim - realms-shimAll versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.HighCWE-1321Prototype Pollution in realms-shimAll versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.HighCWE-1321Cross site scripting in three.jsVersions of three.js prior to 0.137.0 load untrusted iframes and allow for attackers to inject arbitrary javascript into a users browser.HighCWE-79Exposure of Sensitive Information in simple-getIn versions of simple-get prior to 4.0.1, 3.1.1, and 2.8.2, when fetching a remote url with a cookie location response, headers will be followed, potentially...HighCWE-200Prototype Pollution in keygetThe package keyget from 0.0.0 are vulnerable to Prototype Pollution via the methods set, push, and at which could allow an attacker to cause a...MediumCWE-1321Cross-site Scripting in karmakarma prior to version 6.3.14 contains a cross-site scripting vulnerability.MediumCWE-79Server-Side Request Forgery in @peertube/embed-api@peertube/embed-api version 4.0.0 and prior is vulnerable to server-side request forgery.MediumCWE-918Cross site scripting in @awsui/components-reactComponents could potentially allow cross-site scripting (XSS) in certain circumstances. These components could render content without adequate neutralization.HighCWE-79Open redirect in karmaKarma before 6.3.16 is vulnerable to Open Redirect due to missing validation of the return_url query parameter.MediumCWE-601Authorization Bypass Through User-Controlled Key in urijsAttacker can use case-insensitive protocol schemes like HTTP, htTP, HTtp etc. in order to bypass the patch for CVE-2021-3647.MediumCWE-639Prototype Pollution in litespeed.js and appwrite/server-ceThis affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl...HighCWE-1321Leading white space bypasses protocol validationWhitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly and protocol validation mechanisms may fail.MediumCWE-20Prototype Pollution in object-extendThe package object-extend from 0.0.0 through 0.5.0 is vulnerable to Prototype Pollution via object-extend.HighCWE-1321Cross-site Scripting in PrismPrism’s Command line plugin can be used by attackers to achieve an XSS attack. The Command line plugin did not properly escape its output, leading...HighCWE-79Cross site scripting in reveal.jsThe onmessage event listener in /plugin/notes/speaker-view.html does not check the origin of postMessage before adding the content to the webpage.MediumCWE-79Open Redirect in urijsurijs prior to version 1.19.10 is vulnerable to open redirect. This is the result of a bypass for the fix to CVE-2022-0613.MediumCWE-601Eta vulnerable to Code Injection via templates rendered with user-defined dataVersions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from...HighCWE-94Joplin Desktop App vulnerable to Cross-site ScriptingCross Site Scripting vulnerability in Joplin Desktop App before v2.9.17 allows attacker to execute arbitrary code via improper santization.MediumCWE-79XSS Attack with Express APIXSS attack - anyone using the Express API is impactedHighCWE-79Cross site scripting in froala-editorA cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor allows attackers to execute arbitrary web scripts or HTML.MediumCWE-79Cross site scripting Vulnerability in backstage Software Catalog - @backstage/core-componentsThis vulnerability allows a malicious actor with access to add or modify content in an instance of the Backstage software catalog to inject script URLs...MediumCWE-79Cross site scripting Vulnerability in backstage Software CatalogThis vulnerability allows a malicious actor with access to add or modify content in an instance of the Backstage software catalog to inject script URLs...MediumCWE-79jSuites subect to Cross-site ScriptingVersions of the package jsuites before 5.0.1 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization in the Editor() function.MediumCWE-79Improper calculations in ECC implementation can trigger a Denial-of-Service (DoS)When using the non-default “fallback” crypto back-end, ECC operations in node-jose can trigger a Denial-of-Service (DoS) condition, due to a possible infinite loop in an...HighCWE-835iziModal Cross-site Scripting vulnerabilityiziModal is a modal plugin with jQuery. Versions prior to 1.6.1 are vulnerable to cross-site scripting (XSS) when handling untrusted modal titles.MediumCWE-79Baremetrics date range picker vulnerable to Cross-site ScriptingThe Baremetrics date range picker is a solution for selecting both date ranges and single dates from a single calender view. Versions 1.0.14 and prior...MediumCWE-79textAngular Cross-site Scripting vulnerabilitytextAngular is a text editor for Angular.js. Version 1.5.16 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the...MediumCWE-79Mind-elixir Cross-site Scripting vulnerabilityMind-elixir is a free, open source mind map core. Prior to version 0.18.1, mind-elixir is prone to cross-site scripting when handling untrusted menus. This issue...MediumCWE-79Cross-Site-Scripting attack on `<RichTextField>` - react-adminAll React applications built with react-admin and using the <RichTextField> are affected.MediumCWE-79Cross-Site-Scripting attack on `<RichTextField>`All React applications built with react-admin and using the <RichTextField> are affected.MediumCWE-79Cross-site scripting in CKEditor5CKSource CKEditor5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget.MediumCWE-79Cross-site Scripting in dijit editor's LinkDialog pluginXSS possible for users of the Dijit Editor’s LinkDialog pluginLowCWE-79Path Traversal in localhost-now - localhost-now - GHSA-2gjg-5x33-mmp2Versions of localhost-now before 1.0.2 are vulnerable to path traversal. This allows a remote attacker to read the content of an arbitrary file.HighCWE-22Cross-site Scripting in jspreadsheetThe dropdown menu in jspreadsheet before v4.6.0 was discovered to be vulnerable to cross-site scripting (XSS).MediumCWE-79Vega vulnerable to arbitrary code execution when clicking href linksVega is vulnerable to arbitrary code execution when clicking href links. Versions 5.4.1 and 4.5.1 contain a patch.Medium@braintree/sanitize-url Cross-site Scripting vulnerabilitysanitize-url (aka @braintree/sanitize-url) before 6.0.1 allows XSS via HTML entities.MediumCWE-79rangy vulnerable to Prototype PollutionAll versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can...HighCWE-1321xterm vulnerable to remote code executionA remote code execution vulnerability exists in Xterm.js when the component mishandles special characters.HighCWE-94mde utilities contains Prototype PollutionAll versions of the package utilities are vulnerable to Prototype Pollution via the _mix function.HighCWE-1321Vega Expression Language `scale` expression function Cross Site Scripting - vegaThe Vega scale expression function has the ability to call arbitrary functions with a single controlled argument. This can be exploited to escape the Vega...MediumCWE-79Vega Expression Language `scale` expression function Cross Site ScriptingThe Vega scale expression function has the ability to call arbitrary functions with a single controlled argument. This can be exploited to escape the Vega...MediumCWE-79dot-lens vulnerable to Prototype PollutionAll versions of the package dot-lens are vulnerable to Prototype Pollution via the set() function in index.js file.HighCWE-1321Vega has Cross-site Scripting vulnerability in `lassoAppend` function - vegaVega’s lassoAppend function: lassoAppend accepts 3 arguments and internally invokes push function on the 1st argument specifying array consisting of 2nd and 3rd arguments as...MediumCWE-79Vega has Cross-site Scripting vulnerability in `lassoAppend` functionVega’s lassoAppend function: lassoAppend accepts 3 arguments and internally invokes push function on the 1st argument specifying array consisting of 2nd and 3rd arguments as...MediumCWE-79rsshub vulnerable to Cross-site Scripting via unvalidated URL parametersWhen the URL parameters contain certain special characters, it returns an error page that does not properly handle XSS vulnerabilities, allowing for the execution of...MediumCWE-79Padding Oracle Attack due to Observable Timing Discrepancy in jose-node-esm-runtimeAES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed JWEDecryptionFailed would be thrown.MediumCWE-696Padding Oracle Attack due to Observable Timing Discrepancy in jose-node-cjs-runtimeAES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed JWEDecryptionFailed would be thrown.MediumCWE-696Arbitrary local file read vulnerability during template rendering - swig-templatesDirectory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files via the include or extends tags.HighCWE-22Arbitrary local file read vulnerability during template renderingDirectory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files via the include or extends tags.HighCWE-22angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backendangular-server-side-configuration detects used environment variables in TypeScript (.ts) files during build time of an Angular CLI project. The detected environment variables are written to a...HighCWE-538Padding Oracle Attack due to Observable Timing Discrepancy in jose-browser-runtimeAES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed JWEDecryptionFailed would be thrown.MediumCWE-203Content Injection via TileJSON Name in mapbox.jsVersions 1.x prior to 1.6.6 and 2.x prior to 2.2.4 of mapbox.js are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios.MediumCWE-79Content Injection via TileJSON attribute in mapbox.jsVersions 1.x prior to 1.6.5 and 2.x prior to 2.1.7 of mapbox.js are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios.MediumCWE-79matrix-js-sdk Prototype Pollution vulnerabilityEvents sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer’s ability to process...HighCWE-1321fastify/websocket vulnerable to uncaught exception via crash on malformed packetAny application using @fastify/websocket could crash if a specific, malformed packet is sent.HighCWE-248xmldom allows multiple root nodes in a DOM - xmldomxmldom parses XML that is not well-formed because it contains multiple top level elements, and adds all root nodes to the childNodes collection of the...HighCWE-20xmldom allows multiple root nodes in a DOMxmldom parses XML that is not well-formed because it contains multiple top level elements, and adds all root nodes to the childNodes collection of the...HighCWE-20CKEditor 4.0 vulnerability in the HTML Data ProcessorA cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14.0 allows remote attackers to inject arbitrary web script through a...MediumCWE-79Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-g336-c7wv-8hp3Affected versions of swagger-ui are vulnerable to cross-site scripting via the url query string parameter.HighCWE-79Cross-Site Scripting in @toast-ui/editorVersions of @toast-ui/editor prior to 2.2.0 are vulnerable to Cross-Site Scripting (XSS). There are multiple bypasses to the package’s built-in XSS sanitization. This may allow...HighCWE-79Cross-Site Scripting in bootstrap-vueVersions of bootstrap-vue prior to 2.0.0-rc.12 are vulnerable to Cross-Site Scripting. Due to insufficient input sanitization, components may be vulnerable to Cross-Site Scripting through the...HighCWE-79Content Injection in remarkableVersions 1.4.0 and earlier of remarkable are affected by a cross-site scripting vulnerability. This occurs because vulnerable versions of remarkable did not properly whitelist link...HighCWE-94Cross-Site Scripting in webtorrentVersions of webtorrent prior to 0.107.6 are vulnerable to Cross-Site Scripting. webtorrent servers started with torrent.createServer() lists a torrent’s title and files in the index...MediumCWE-79Cross-Site Scripting in c3Affected versions of c3 are vulnerable to cross-site scripting via improper sanitization of HTML in rendered tooltips.MediumCWE-79Reverse Tabnabbing in showdownVersions of showdown prior to 1.9.1 are vulnerable to Reverse Tabnabbing. The package uses target='_blank' in anchor tags, allowing attackers to access window.opener for the...LowCWE-1022SvelteKit vulnerable to Cross-Site Request ForgeryThe SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a +server.js file, containing endpoint handlers for different...HighCWE-352phoenix_html allows Cross-site Scripting in HEEx class attributestag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributesMediumCWE-79Pandao Editor.md vulnerable to cross-site scripting (XSS) in editor parameterCross-site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the editor parameter.MediumCWE-79Pandao Editor.md vulnerable to cross-site scripting (XSS) in iframe src parameterCross-site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script in the <iframe> src parameter....MediumCWE-79Regular Expression Denial of Service in hawkVersions of hawk prior to 3.1.3, or 4.x prior to 4.1.1 are affected by a regular expression denial of service vulnerability related to excessively long...HighCWE-1333Regular Expression Denial of Service in highcharts - highchartsVersions of highcharts prior to 6.1.0 are vulnerable to Regular Expression Denial of Service (ReDoS). Untrusted input may cause catastrophic backtracking while matching regular expressions....HighCWE-1333Denial of Service in protobufjs - protobufjsVersions of protobufjs before 5.0.3 and 6.8.6 are vulnerable to a regular expression denial of service when parsing crafted invalid *.proto files.MediumCWE-1333Regular Expression Denial of Service in clean-cssVersion of clean-css prior to 4.1.11 are vulnerable to Regular Expression Denial of Service (ReDoS). Untrusted input may cause catastrophic backtracking while matching regular expressions....LowCWE-1333Regular Expression Denial of Service in marked - marked - GHSA-ch52-vgq2-943fAffected versions of marked are vulnerable to Regular Expression Denial of Service (ReDoS). The _label subrule may significantly degrade parsing performance of malformed input.LowCWE-1333Regular Expression Denial of Service in momentAffected versions of moment are vulnerable to a low severity regular expression denial of service when parsing dates as strings.HighCWE-400Denial of Service in axiosVersions of axios prior to 0.18.1 are vulnerable to Denial of Service. If a request exceeds the maxContentLength property, the package prints an error but...HighCWE-755SvelteKit framework has Insufficient CSRF protection for CORS requestsThe SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a +server.js file, containing endpoint handlers for different...HighCWE-918Insecure Cryptography Algorithm in simple-crypto-jsVersions of simple-crypto-js prior to 2.3.0 use AES-CBC with PKCS#7 padding, which is vulnerable to padding oracle attacks. This may allow attackers to break the...MediumCWE-327Authentication Bypass in @strapi/plugin-users-permissionsStrapi through 4.5.6 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for...HighImproper Input Validation in sanitize-htmlApostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by...MediumCWE-20Out-of-bounds Read in base64urlVersions of base64url before 3.0.0 are vulnerable to to out-of-bounds reads as it allocates uninitialized Buffers when number is passed in input on Node.js 4.x...MediumCWE-125Switcher Client contains Regular Expression Denial of Service (ReDoS)Unsanitized input flows into Strategy match operation (EXIST), where it is used to build a regular expression. This may result in a Regular expression Denial...HighCWE-400matrix-js-sdk vulnerable to invisible eavesdropping in group callsAn attacker present in a room where an MSC3401 group call is taking place can eavesdrop on the video and audio of participants using matrix-js-sdk,...MediumCWE-862Cross-Site Scripting in @ckeditor/ckeditor5-linkVersions of status-board prior to 10.0.1 are vulnerable to Cross-Site Scripting. The _createPreviewButton() function fails to sanitize the href attribute of a created <a> tag....MediumCWE-79Cross-site scripting vulnerability in TinyMCE - tinymce - GHSA-vrv8-v4w8-f95hA cross-site scripting (XSS) vulnerability was discovered in the core parser. The vulnerability allowed arbitrary JavaScript execution when inserting a specially crafted piece of content...MediumCWE-79Cross-Site Scripting in react - reactAffected versions of react are vulnerable to Cross-Site Scripting (XSS). The package fails to properly sanitize input used to create keys. This may allow attackers...MediumCWE-79Prototype pollution in matrix-js-sdk (part 2)In certain configurations, data sent by remote servers containing special strings in key locations could cause modifications of the Object.prototype, disrupting matrix-js-sdk functionality, causing denial...HighCWE-1321Server side request forgery in SwaggerUI - swagger-ui-distSwaggerUI supports displaying remote OpenAPI definitions through the ?url parameter. This enables robust demonstration capabilities on sites like petstore.swagger.io, editor.swagger.io, and similar sites, where users...MediumCWE-918Server side request forgery in SwaggerUI - swagger-ui-reactSwaggerUI supports displaying remote OpenAPI definitions through the ?url parameter. This enables robust demonstration capabilities on sites like petstore.swagger.io, editor.swagger.io, and similar sites, where users...MediumCWE-918Server side request forgery in SwaggerUISwaggerUI supports displaying remote OpenAPI definitions through the ?url parameter. This enables robust demonstration capabilities on sites like petstore.swagger.io, editor.swagger.io, and similar sites, where users...MediumCWE-918@claviska/jquery-minicolors vulnerable to Cross-site ScriptingjQuery MiniColors is a color picker built on jQuery. Prior to version 2.3.6, jQuery MiniColors is prone to cross-site scripting when handling untrusted color names....MediumCWE-79Deserialization of Untrusted Data in bson - bsonIncorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure.MediumCWE-502Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-urlServer-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 8.1.0.HighCWE-918Out-of-bounds Read in atobVersions of atob before 2.1.0 uninitialized Buffers when number is passed in input on Node.js 4.x and below.HighCWE-125Incorrect Authorization in @uppy/companion@uppy/companion prior to version 3.3.1 is vulnerable to incorrect authorization. A user with URL upload access could enumerate internal companion server networks, send local webservers...HighCWE-918Uncaught Exception in engine.io - engine.ioA specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process.HighCWE-755Cross-site scripting vulnerability in TinyMCE - tinymce - GHSA-27gm-ghr9-4v95A cross-site scripting (XSS) vulnerability was discovered in: the core parser, paste and visualchars plugins. The vulnerability allowed arbitrary JavaScript execution when inserting a specially...HighCWE-79Leaking of user information on Cross-Domain communication in sysendUsers that use Cross-Origin communication and send sensitive information make it possible for this data to be intercepted.This is not a big impact because it...MediumCWE-346@vendure/admin-ui-plugin authenticated Cross-site Scripting vulnerabilityVendure provides an authorization system with different levels of privileges. For example, an administrator cannot create another administrator.MediumCWE-79is_js vulnerable to Regular Expression Denial of Serviceis.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service...HighCWE-400Cross-Site Scripting in jquery - jqueryAffected versions of jquery are vulnerable to cross-site scripting. This occurs because the main jquery function uses a regular expression to differentiate between HTML and...MediumCWE-79RCE in SiteServer CMSSiteServer CMS v7.x, which SiteServer UI relies on, allows attackers to execute arbitrary code via a crafted plug-in.Highsemver-regex Regular Expression Denial of Service (ReDOS)npm semver-regex is vulnerable to Inefficient Regular Expression ComplexityHighCWE-400jquery-plugin-query-object contains prototype pollution vulnerabilityImproperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’) in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.HighCWE-1321Kibana Sensitive Data DisclosureIt was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be...MediumCWE-319eivindfjeldstad-dot contains prototype pollution vulnerabilityeivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function ‘set’ could be tricked into adding or modifying properties of ‘Object.prototype’ using a ‘proto’ payload.MediumCWE-915Validation bypass in frourioNo description available.HighCWE-20Validation bypass in frourio-expressNo description available.HighCWE-20Malicious Package in radicjsVersion 0.2.1 of radicjs contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send...HighMalicious Package in pm-controlsVersion 1.1.8 of pm-controls contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send...Highxdlocalstorage does not verify request originAn issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function...HighCWE-668Regular expression denial of service in semver-regexAn exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input...LowCWE-1333Regular Expression Denial of Service (ReDoS) in jsx-slackjsx-slack v4.5.1 and earlier versions are vulnerable to a regular expression denial-of-service (ReDoS) attack.LowCWE-400Possible inject arbitrary `CSS` into the generated graph affecting the container HTMLAn attacker is able to inject arbitrary CSS into the generated graph allowing them to change the styling of elements outside of the generated graph,...MediumCWE-79JOSE vulnerable to resource exhaustion via specifically crafted JWE - jose-browser-runtimeThe PBKDF2-based JWE key management algorithms expect a JOSE Header Parameter named p2c (PBES2 Count), which determines how many PBKDF2 iterations must be executed in...MediumCWE-834JOSE vulnerable to resource exhaustion via specifically crafted JWE - jose-node-cjs-runtimeThe PBKDF2-based JWE key management algorithms expect a JOSE Header Parameter named p2c (PBES2 Count), which determines how many PBKDF2 iterations must be executed in...MediumCWE-834JOSE vulnerable to resource exhaustion via specifically crafted JWE - jose-node-esm-runtimeThe PBKDF2-based JWE key management algorithms expect a JOSE Header Parameter named p2c (PBES2 Count), which determines how many PBKDF2 iterations must be executed in...MediumCWE-834JOSE vulnerable to resource exhaustion via specifically crafted JWEThe PBKDF2-based JWE key management algorithms expect a JOSE Header Parameter named p2c (PBES2 Count), which determines how many PBKDF2 iterations must be executed in...MediumCWE-834Potential exposure of tokens to an Unauthorized ActorWhen using this library as a way to programmatically communicate with Replit in a standalone fashion, if there are multiple failed attempts to contact Replit...MediumCWE-200Uncontrolled Resource Consumption in markdown-itSpecial patterns with length > 50K chars can slow down parser significantly.MediumCWE-400Denial of Service (DoS) vulnerability in RSSHubPassing some special values to the filter and filterout parameters can cause an abnormally high CPU. Impact on the performance of the servers and RSSHub...MediumCWE-400Malicious Package in leaflet-gpxVersion 1.0.1 of leaflet-gpx contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send...HighMalicious Package in coffee-projectVersion 1.7.5 of coffee-project contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the...HighMalicious Package in ember-power-timepickerVersion 1.0.8 of ember-power-timepicker contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send...HighMalicious Package in geoheatVersion 1.3.2 of geoheat contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send...HighMalicious Package in angular-location-updateVersion 0.0.3 of angular-location-update contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send...HighMalicious Package in libubxVersion 1.0.3 of libubx contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send...HighMalicious Package in jasminVersion 0.0.3 of jasmin contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the...HighMalicious Package in oauth-validatorVersion 1.0.2 of oauth-validator contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the...HighMalicious Package in react-dates-scVersion 0.3.0 of react-dates-sc contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the...HighMalicious Package in ngx-picaVersion 1.1.5 of ngx-pica contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send...HighMalicious Package in github-jquery-widgetsVersion 0.1.2 of github-jquery-widgets contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send...HighMalicious Package in scrooolVersion 0.1.7 of scroool contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send...HighMalicious Package in precode.jsVersion 1.1.1 of precode.js contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send...HighMalicious Package in react-server-nativeVersion 0.0.7 of react-server-native contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the...HighMalicious Package in mx-nested-menuVersion 0.1.30 of mx-nested-menu contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send...HighMalicious Package in device-mqttVersion 1.0.11 of device-mqtt contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the...Highv8n vulnerable to Inefficient Regular Expression ComplexityInefficient regular expression complexity of lowercase() and uppercase() regex could lead to a denial of service attack. With a formed payload 'a' + 'a'.repeat(i) +...HighCWE-400Malicious Package in radic-utilVersion 1.0.2 of radic-util contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send...HighPrototype Pollution in backbone-query-parametersImproperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’) in backbone-query-parameters 0.4.0 allows a malicious user to inject properties into Object.prototype.HighCWE-1321matrix-js-sdk can be tricked into disclosing E2EE room keys to a participating homeserverA logic error in the room key sharing functionality of matrix-js-sdk before 12.4.1 allows a malicious Matrix homeserver† participating in an encrypted room to steal...MediumCWE-327@excalidraw/excalidraw Cross-site Scripting vulnerabilityXSS vulnerability due to improperly sanitizing URLs of links that can be attached on canvas elements. This affects users of the npm package @excalidraw/excalidraw provided...MediumCWE-79Prototype pollution in dottyPrototype pollution vulnerability in ‘dotty’ before version 0.1.1 allows attackers to cause a denial of service and may lead to remote code execution.HighCWE-400Prototype Pollution in lutilsAll versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function.MediumCWE-1321Prototype pollution in nestiePrototype pollution vulnerability in ‘nestie’ versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of service and may lead to remote code execution....HighCWE-913Regular Expression Denial of Service in browserslistThe package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.MediumCWE-400steal vulnerable to Regular Expression Denial of Service via source and sourceWithCommentsA Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal via the source and sourceWithComments variable in main.js.HighCWE-1333steal Inefficient Regular Expression Complexity vulnerability via string variableA Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the string variable in babel.js.HighCWE-1333Angular critical CSS inlining Cross-site Scripting Vulnerability AdvisoryAngular Universal applications on 16.1.0 and 16.1.1 using critical CSS inlining are vulnerable to a cross-site scripting (XSS) attack where an attacker can trick another...HighCWE-79Materialize-css vulnerable to Improper Neutralization of Input During Web Page Generation - materialize-cssIn Materialize through 1.0.0, XSS is possible via the Toast feature.MediumCWE-79Materialize-css vulnerable to Improper Neutralization of Input During Web Page GenerationIn Materialize through 1.0.0, XSS is possible via the Toast feature.MediumCWE-79Materialize-css vulnerable to Cross-site Scripting in tooltip component - materialize-cssAll versions of materialize-css are vulnerable to Cross-Site Scripting. The tooltip component does not sufficiently sanitize user input, allowing an attacker to execute arbitrary JavaScript...MediumCWE-79Materialize-css vulnerable to Cross-site Scripting in tooltip componentAll versions of materialize-css are vulnerable to Cross-Site Scripting. The tooltip component does not sufficiently sanitize user input, allowing an attacker to execute arbitrary JavaScript...MediumCWE-79Materialize-css vulnerable to Cross-site Scripting in autocomplete component - materialize-cssAll versions of materialize-css are vulnerable to Cross-Site Scripting. The autocomplete component does not sufficiently sanitize user input, allowing an attacker to execute arbitrary JavaScript...MediumCWE-79Materialize-css vulnerable to Cross-site Scripting in autocomplete componentAll versions of materialize-css are vulnerable to Cross-Site Scripting. The autocomplete component does not sufficiently sanitize user input, allowing an attacker to execute arbitrary JavaScript...MediumCWE-79dijit editor cross-site scripting vulnerabilitydijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.MediumCWE-79Regular Expression Denial of Service in jquery-validationThe GitHub Security Lab team has identified potential security vulnerabilities in jquery.validation.HighCWE-400Prototype Pollution in js-dataAll versions of package js-data prior to 3.0.10 are vulnerable to Prototype Pollution via the deepFillIn function.HighCWE-1321Prototype pollution in @tsed/coreThis affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used as part of the utils directory. Depending on...MediumCWE-915Cross-site Scripting in markdown-it-highlightjsThis affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of lang in the markdown-it-highlightjs Inline code highlighting feature....MediumCWE-79Prototype Pollution in decalThis affects all versions of package decal. The vulnerability is in the extend function.HighCWE-94Denial of service in prismjsThe package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the prism-asciidoc, prism-rest, prism-tap and prism-eiffel components.HighCWE-400js-bson vulnerable to REDoSThe MongoDB bson JavaScript module (also known as js-bson) versions 0.5.0 to 1.0.x before 1.0.5 is vulnerable to a Regular Expression Denial of Service (ReDoS)...HighCWE-400Inefficient Regular Expression Complexity in handsontableThe package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) in Handsontable.helper.isNumeric function.HighCWE-1333rendertron can remotely shut down Chrome instanceRendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET...HighCWE-284dalek-browser-chrome Downloads Resources over HTTPAffected versions of dalek-browser-chrome insecurely download an executable over an unencrypted HTTP connection.HighCWE-311rendertron LFI vulnerabilityRendertron 1.0.0 allows for alternative protocols such as ‘file://’ introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by a remote...HighCWE-22rendertron XSS vulnerabilityError reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.MediumCWE-79ReDoS via long UserAgent header in useragentAffected versions of useragent are vulnerable to regular expression denial of service when an arbitrarily long User-Agent header is parsed.HighCWE-400Invalid Curve Attack in node-joseAffected versions of node-jose are vulnerable to an invalid curve attack. This allows an attacker to recover the private secret key when JWE with Key...MediumCWE-200Elliptic Uses a Broken or Risky Cryptographic AlgorithmThe npm package elliptic before version 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that...MediumCWE-327Rendertron discloses absolute paths of filesInstalled packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the “_where” attribute of...HighCWE-200SimpleMDE XSS VulnerabilitySimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters, which is mishandled...MediumCWE-79Svelte vulnerable to XSS when using objects during server-side renderingThe package svelte before 3.49.0 is vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects...MediumCWE-79Valine HTML InjectionAn issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with...MediumCWE-79Directory Traversal in commentapp.stetsonwoodAffected versions of commentapp.stetsonwood resolve relative file paths, resulting in a directory traversal vulnerability. A malicious actor can use this vulnerability to access files outside...HighCWE-22opencv.js is malwareopencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.HighCWE-506Command injection in github-todosnaholyr github-todos 3.1.0 is vulnerable to command injection. The range argument for the _hook subcommand is concatenated without any validation, and is directly used by...HighCWE-78steal vulnerable to Regular Expression Denial of Service via input variableA Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal via the input variable in main.js.HighCWE-1333dalek-browser-ie downloads Resources over HTTPAffected versions of dalek-browser-ie insecurely download an executable over an unencrypted HTTP connection.HighCWE-311URIjs Vulnerable to Hostname spoofing via backslashes in URLIf using affected versions to determine a URL’s hostname, the hostname can be spoofed by using a combination of backslash (\) and slash (/) characters...MediumCWE-601Template Injection in jsrenderAffected versions of jsrender are susceptible to a remote code execution vulnerability when used with server delivered client-side tempates which dynamically embed user input.MediumCWE-94Regular Expression Denial of Service in marked - markedAffected versions of marked are vulnerable to a regular expression denial of service.HighCWE-400Sanitization bypass using HTML Entities in markedAffected versions of marked are susceptible to a cross-site scripting vulnerability in link components when sanitize:true is configured.MediumCWE-79Prototype Pollution in deephasPrototype pollution vulnerability in ‘deephas’ versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.HighCWE-915openssl.js is malwareThe openssl.js package is a piece of malware that steals environment variables and sends them to attacker controlled locations.HighCWE-506Insecure Defaults Allow MITM Over TLS in engine.io-clientAffected versions of engine.io-client do not verify certificates by default, and as such may be vulnerable to Man-in-the-Middle attacks.MediumCWE-300Marked vulnerable to XSS from data URIsmarked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.MediumCWE-79Cross-site scripting in jspdf - jspdfAffected versions of this package are vulnerable to Cross-site Scripting (XSS). It’s possible to inject JavaScript code via the html method.MediumCWE-79Cross-site scripting in jspdfIt’s possible to use nested script tags in order to bypass the filtering regex.MediumCWE-79Regular Expression Denial of Service in contentAffected versions of content are vulnerable to a regular expression denial of service when parsing malicious Content-Type and Content-Disposition headers.HighCWE-400Cross-site Scripting in remarkableIn remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintable characters, as demonstrated by a \x0ejavascript: URL.MediumCWE-79Code injection in mock2easyThis affects all versions up to and including version 0.0.24 of package mock2easy. a malicious user could inject commands through the _data variable:HighCWE-77Regular Expression Denial of Service in postcssThe package postcss versions before 7.0.36 or between 8.0.0 and 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in...MediumCWE-400Pandao editor.md vulnerable to DOM XSSpandao Editor.md 1.5.0 has DOM XSS via input starting with a << substring, which is mishandled during construction of an A element.MediumCWE-79XSS in Data URI in remarkableAffected versions of remarkable are vulnerable to cross-site scripting. Vulnerable versions of the package allow the use of data: URIs in links, and can therefore...HighCWE-79Regular Expression Denial of Service in decamelizeAffected versions of decamelize are susceptible to a denial of service vulnerability when user input is passed directly into decamelize.HighCWE-400Pandao editor.md vulnerable to XSS in IMG attributesPandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.MediumCWE-79jspdf vulnerable to Regular Expression Denial of Service (ReDoS)This affects the package jspdf before 2.3.1. ReDoS is possible via the addImage function.HighCWE-400netmask npm package mishandles octal input dataThe netmask package before 2.0.1 for Node.js mishandles certain unexpected characters in an IP address string, such as an octal digit of 9. This (in...MediumCWE-20ejs is vulnerable to remote code execution due to weak input validationnodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() functionHighCWE-20Cryptographically Weak PRNG in randomaticAffected versions of randomatic generate random values using a cryptographically weak psuedo-random number generator. This may result in predictable values instead of random values as...MediumCWE-338ejs vulnerable to DoS due to weak input validationnodejs ejs version older than 2.5.5 is vulnerable to a denial-of-service due to weak input validation in ejs.renderFile()HighCWE-20Prototype Pollution in seyAll versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.MediumCWE-1321node-browser downloads Resources over HTTPAffected versions of node-browser insecurely downloads resources over HTTP.HighCWE-311mde ejs vulnerable to XSSnodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code injectionMediumCWE-79Prototype Pollution in fieldPrototype pollution vulnerability in ‘field’ versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.HighCWE-915Cross-Site Scripting in sanitize-html - sanitize-htmlAffected versions of sanitize-html are vulnerable to cross-site scripting when allowedTags includes at least one nonTextTag.MediumCWE-79Cross-Site Scripting in sanitize-htmlAffected versions of sanitize-html are vulnerable to cross-site scripting.MediumCWE-79superagent vulnerable to zip bomb attacksAffected versions of superagent do not check the post-decompression size of ZIP compressed HTTP responses prior to decompressing. This results in the package being vulnerable...MediumCWE-409Cross-Site Scripting in i18next - i18nextAffected versions of i18next may fail to sanitize user input when certain configuration options are used. When using the .init method, passing interpolation options without...MediumCWE-79Cross-Site Scripting in i18nextAffected versions of i18next allow untrusted user input to be injected into dictionary key names, resulting in a cross-site scripting vulnerability.MediumCWE-79Macro in MathJax running untrusted Javascript within a web browserMathJax version prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability in the \unicode{} macro that can result in Potentially untrusted Javascript running...MediumCWE-79Insecure template handling in SquirrellySquirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options...HighCWE-200Denial of service in threeThis affects the package three before 0.125.0. This can happen when handling rgb or hsl colors.HighCWE-400selenium-chromedriver Downloads Resources over HTTPAffected versions of selenium-chromedriver insecurely download an executable over an unencrypted HTTP connection.HighCWE-311auth0-lock vulnerable to XSS via unsanitized placeholder propertyAuth0 Lock version 11.20.4 and earlier did not properly sanitize the generated HTML code. Customers using the additionalSignUpFields customization option to add a checkbox to...MediumCWE-79pym.js CSRF VulnerabilityNPR Visuals Team Pym.js version versions 0.4.2 up to 1.3.1 contains a Cross Site Request Forgery (CSRF) vulnerability in Pym.js _onNavigateToMessage function.HighCWE-352d3.js is malwareThe d3.js package is a piece of malware that steals environment variables and sends them to attacker controlled locations.HighCWE-506dalek-browser-ie-canary downloads Resources over HTTPAffected versions of dalek-browser-ie-canary insecurely download an executable over an unencrypted HTTP connection.HighCWE-311Path Traversal in localhost-nowAll versions of localhost-now are vulnerable to Path Traversal. The package fails to sanitize URLs, allowing attackers to access server files outside of the served...HighCWE-22Prototype Pollution in record-like-deep-assignAll versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality.HighCWE-915RSA signature validation vulnerability on maleable encoded message in jsrsasignVulnerable jsrsasign will accept RSA signature with improper PKCS#1.5 padding.Decoded RSA signature value consists following form:01(ff...(8 or more ffs)...ff)00[ASN.1 OF DigestInfo]Its byte length must be...HighCWE-347Sensitive data exposure in NATS - natsPreview versions of two NPM packages and one Deno package from the NATS project contain an information disclosure flaw, leaking options to the NATS server;...HighCWE-522Sensitive data exposure in NATSPreview versions of two NPM packages and one Deno package from the NATS project contain an information disclosure flaw, leaking options to the NATS server;...HighCWE-522Regular Expression Denial of Service in no-caseAffected versions of no-case are vulnerable to a regular expression denial of service when parsing untrusted user input.HighCWE-400bracket-template vulnerable to reflected XSSbracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in templateMediumCWE-79Regular Expression Denial of Service in jadedownThe jadedown package is affected by a regular expression denial of service vulnerability when certain types of user input are passed in.LowCWE-400Cross-site Scripting in React Draft Wysiwygreact-draft-wysiwyg (aka React Draft Wysiwyg) before 1.14.6 allows a javascript: URi in a Link Target of the link decorator in decorators/Link/index.js when a draft is...MediumCWE-79cloudpub-redis downloads Resources over HTTPAffected versions of cloudpub-redis insecurely download an executable over an unencrypted HTTP connection.HighCWE-311CORS misconfiguration in socket.ioThe package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.MediumCWE-453Code Injection in jsenThis affects all versions of package jsen. If an attacker can control the schema file, it could run arbitrary JavaScript code on the victim machine....HighCWE-94Regular Expression Denial of Service in djvalidatorAll versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted invalid emails - for example, --@------------------------------------------------------------------------------------------------------------------------!.HighCWE-400Directory Traversal in rtcmulticonnection-clientAffected versions of rtcmulticonnection-client resolve relative file paths, resulting in a directory traversal vulnerability. A malicious actor can use this vulnerability to access files outside...HighCWE-22Directory Traversal in cyber-jsAffected versions of cyber-js resolve relative file paths, resulting in a directory traversal vulnerability. A malicious actor can use this vulnerability to access files outside...HighCWE-22Directory Traversal in xtalkAffected versions of xtalk are vulnerable to directory traversal, allowing access to the filesystem by placing “../” in the URL.HighCWE-22XSS in hello.jsThis affects the package hello.js before 1.18.6. The code get the param oauth_redirect from url and pass it to location.assign without any check and sanitisation....HighCWE-79Credential leak in react-native-fast-imageThis affects all versions before version 8.3.0 of package react-native-fast-image. When an image with source= is loaded, all other subsequent images will use the same...MediumCWE-200Remote Code Execution in scratch-vmMIT Lifelong Kindergarten Scratch scratch-vm before 0.2.0-prerelease.20200714185213 loads extension URLs from untrusted project.json files with certain _ characters, resulting in remote code execution because the...HighCWE-502mime Regular Expression Denial of Service when MIME lookup performed on untrusted user inputAffected versions of mime are vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.HighCWE-400selenium-wrapper downloads Resources over HTTPAffected versions of selenium-wrapper insecurely download an executable over an unencrypted HTTP connection.HighCWE-311Code Injection in cryoAll versions of cryo are vulnerable to code injection due to an Insecure implementation of deserialization.HighCWE-94Arbitrary Code Execution in mathjsmath.js before 3.17.0 had an issue where private properties such as a constructor could be replaced by using unicode characters when creating an object.HighCWE-88Regular Expression Denial of Service in riot-compilerAffected versions of riot-compiler are susceptible to a regular expression denial of service vulnerability.HighCWE-400mcstatic directory traversal vulnerabilityA server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to access sensitive information in the file system...HighCWE-22Bypassing Sanitization using DOM clobbering in html-janitorAll versions of html-janitor are vulnerable to cross-site scripting (XSS).MediumCWE-642html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS) - html-parse-stringifyThis affects the package html-parse-stringify before 2.0.1; all versions of package html-parse-stringify2. Sending certain input could cause one of the regular expressions that is used...MediumCWE-400html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS)This affects the package html-parse-stringify before 2.0.1; all versions of package html-parse-stringify2. Sending certain input could cause one of the regular expressions that is used...MediumCWE-400XSS in apexchartsThe package apexcharts before 3.24.0 are vulnerable to Cross-site Scripting (XSS) via lack of sanitization of graph legend fields.MediumCWE-79Prototype pollution in gsapThere is a prototype pollution vulnerability in gsap which affects all versions before 3.6.0.HighCWE-400Cross-Site Scripting in html-janitorVersions of html-janitor prior to 2.0.2 (all current versions) are vulnerable to cross-site scripting (XSS).MediumCWE-79Directory Traversal in fbr-clientAffected versions of fbr-client resolve relative file paths, resulting in a directory traversal vulnerability. A malicious actor can use this vulnerability to access files outside...HighCWE-22Server-Side Request Forgery in @uppy/companionThe @uppy/companion npm package before versions 1.13.2 and 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local...HighCWE-918Regular Expression Denial of Service in timespanAffected versions of timespan are vulnerable to a regular expression denial of service when parsing dates.HighCWE-400Electron vulnerable to URL spoofing via PDFiumElectron version 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can...MediumCWE-345Docsify XSS VulnerabilityThis affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execute malicious JavaScript through the following methods...MediumCWE-79auth0-js Privilege Escalation VulnerabilityA cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire authenticated users’ tokens...HighCWE-200tiny-json-http missing SSL certificate validationbrianleroux tiny-json-http version all versions since commit 9b8e74a232bba4701844e07bcba794173b0238a8 (Oct 29 2016) contains a Missing SSL certificate validation vulnerability in The libraries core functionality is affected....HighCWE-295DataTable Vulnerable to Cross-Site ScriptingCross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers to inject arbitrary web script or HTML via the...HighCWE-79Directory Traversal in datachannel-clientAffected versions of datachannel-client resolve relative file paths, resulting in a directory traversal vulnerability. A malicious actor can use this vulnerability to access files outside...HighCWE-22Prototype Pollution in asciitable.jsThe package asciitable.js before 1.0.3 is vulnerable to Prototype Pollution via the main function.HighCWE-400Cross-site Scripting in epubjsmanagers/views/iframe.js in FuturePress EPub.js before 0.3.89 allows XSS.MediumCWE-79jszip Vulnerable to Prototype PollutionThis affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in...MediumCWE-1321Regular Expression Denial of Service (ReDoS) - ssrinpm ssri 5.2.2-6.0.1 and 7.0.0-8.0.0, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely...HighCWE-400Regular Expression Denial of Service (ReDoS)The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker...HighCWE-400Inefficient Regular Expression Complexity in chalk/ansi-regexansi-regex is vulnerable to Inefficient Regular Expression Complexity which could lead to a denial of service when parsing invalid ANSI escape codes.HighCWE-697decode-uri-component vulnerable to Denial of Service (DoS)decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.HighCWE-20Cross-Site Scripting (XSS) in jqueryAffected versions of jquery interpret text/javascript responses from cross-origin ajax requests, and automatically execute the contents in jQuery.globalEval, even when the ajax request doesn’t contain...MediumCWE-79hexo-admin plugin for Node.js XSS VulnerabilityThe Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post....MediumCWE-79Cezerin Unauthorized AccesCezerin v0.33.0 allows unauthorized order-information modification because certain internal attributes can be overwritten via a conflicting name when processing order requests. Hence, a malicious customer...HighCWE-20jQuery-UI vulnerable to Cross-site Scripting in dialog closeTextAffected versions of jquery-ui are vulnerable to a cross-site scripting vulnerability when arbitrary user input is supplied as the value of the closeText parameter in...MediumCWE-79XSS in `*Text` options of the Datepicker widget in jquery-uiAccepting the value of various *Text options of the Datepicker widget from untrusted sources may execute untrusted code. For example, initializing the datepicker in the...MediumCWE-79bson-objectid contains Improper input validationAn issue was discovered in the BSON ObjectID (aka bson-objectid) package 1.3.0 for Node.js. ObjectID() allows an attacker to generate a malformed objectid by inserting...HighCWE-670XSS in the `altField` option of the Datepicker widget in jquery-uiAccepting the value of the altField option of the Datepicker widget from untrusted sources may execute untrusted code. For example, initializing the datepicker in the...MediumCWE-79dojox vulnerable to unescaped string injectionIn Dojo Toolkit before 1.14.0, there is unescaped string injection in dojox/Grid/DataGrid.HighCWE-116Cross-Site Scripting in dojoAffected versions of dojo are susceptible to a cross-site scripting vulnerability in the dijit.Editor and textarea components, which execute their contents as Javascript, even when...MediumCWE-79Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-4f9m-pxwh-68hgVersions of swagger-ui prior to 3.20.9 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize URLs used in the OAuth auth flow, which...MediumCWE-79Cross-Site Scripting in diagram-jsVersions of diagram-js prior to 3.3.1 (for 3.x) and 2.6.2 (for 2.x) are vulnerable to Cross-Site Scripting. The package fails to escape output of user-controlled...MediumCWE-79Etherpad Lite Access Restriction Bypassnode/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.HighCWE-20Angular Redactor XSS VulnerabilityImperavi Redactor 3 in Angular Redactor 1.1.6, when HTML content mode is used, allows stored XSS, as demonstrated by an onerror attribute of an IMG...MediumCWE-79Converse.js Exposure of Sensitive InformationConverse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe publication of private data...MediumCWE-200Simditor XSS VulnerabilitySimditor v2.3.11 allows XSS via crafted use of svg/onload=alert in a TEXTAREA element, as demonstrated by Firefox 54.0.1.MediumCWE-79Cross-Site Scripting in swagger-ui - swagger-uiAffected versions of swagger-ui are vulnerable to cross-site scripting. This vulnerability exists because swagger-ui automatically executes external Javascript that is loaded in via the url...HighCWE-79Cisco node-jose improper validation of JWT signatureA vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is...HighCWE-347Auth0 angular-jwt misinterprets allowlist as regexAuth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain allowlist...MediumCWE-20keyget vulnerable to prototype pollutionPrototype pollution vulnerability in ‘keyget’ versions 1.0.0 through 2.2.0 allows attacker to cause a denial of service and may lead to remote code execution.HighCWE-1321Grunt-karma vulnerable to prototype pollutionPrototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.HighCWE-1321Xen Orchestra Mishandles AuthorizationXen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by modified WebSocket resourceSet.getAll data is which the attacker changes the...MediumCWE-863Docsify vulnerable to cross-site scripting due to mishandled encodingdocsify versions 4.12.1 and earlier are vulnerable to cross-site scripting (XSS) because the search component does not appropriately encode Code Blocks and mishandles the "...MediumCWE-79mxGraph vulnerable to cross-site scripting in color fieldmxGraph through 4.0.0, related to the draw.io Diagrams plugin before 8.3.14 for Confluence and other products, is vulnerable to cross-site scripting. draw.io Diagrams allows the...MediumCWE-79MJML vulnerable to path traversalMJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.HighCWE-22mxGraph vulnerable to cross-site scripting in setTooltips functionmxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.MediumCWE-79mxGraph vulnerable to XXE attacksIn mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView....HighCWE-611rgb2hex vulnerable to inefficient regular expression complexityA vulnerability was found in rgb2hex up to 0.1.5. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to...HighCWE-1333skeemas Inefficient Regular Expression Complexity vulnerabilityA vulnerability was found in Prestaul skeemas and classified as problematic. This issue affects some unknown processing of the file validators/base.js. The manipulation of the...HighCWE-1333is-url Inefficient Regular Expression Complexity vulnerabilityA vulnerability was found in Segmentio is-url up to 1.2.2. It has been rated as problematic. Affected by this issue is an unknown functionality of...HighCWE-1333debug Inefficient Regular Expression Complexity vulnerabilityA vulnerability classified as problematic has been found in debug-js debug up to 3.0.x. This affects the function useColors of the file src/node.js. The manipulation...HighCWE-1333Cross-realm object access in Webpack 5Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted...HighEpicEditor XSS VulnerabilityEpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML...MediumCWE-79Prototype Pollution leading to Remote Code Execution in superjsonThis is critical vulnerability, as it allows to run arbitrary code on any server using superjson input, including a Blitz.js server, without prior authentication or...HighCWE-94Improper Input Validation in vriteio/vriteImproper Input Validation in GitHub repository vriteio/vrite prior to 0.3.0.MediumCWE-20Server-Side Request Forgery (SSRF) in vriteio/vriteServer-Side Request Forgery (SSRF) in GitHub repository vriteio/vrite prior to 0.3.0.HighCWE-918webmention.js Cross-site Scripting vulnerabilitywebmention.js prior to 0.5.5 is vulnerable to cross-site scripting.HighCWE-79Leaking sensitive user information still possible by filtering on private with prefix fieldsStill able to leak private fields if using the t(number) prefixHighCWE-200progressbar.js vulnerable to Prototype PollutionAll versions of the package progressbar.js prior to 1.1.1 are vulnerable to Prototype Pollution via the function extend() in the file utils.js.HighCWE-1321Jodit Editor vulnerable to cross-site scriptingCross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensitive information via the rich text editor component.MediumCWE-79Path traversal vulnerability in gatsby-plugin-sharpThe gatsby-plugin-sharp plugin prior to versions 5.8.1 and 4.25.1 contains a path traversal vulnerability exposed when running the Gatsby develop server (gatsby develop).MediumCWE-22Making all attributes on a content-type public without noticing it - @strapi/utilsAnyone (Strapi developers, users, plugins) can make every attribute of a Content-Type public without knowing it.MediumCWE-200Making all attributes on a content-type public without noticing itAnyone (Strapi developers, users, plugins) can make every attribute of a Content-Type public without knowing it.MediumCWE-200layui vulnerable to cross-site scriptingA vulnerability, which was classified as problematic, was found in layui up to v2.8.0-rc.16. This affects an unknown part of the component HTML Attribute Handler....MediumCWE-79Improper Neutralization of Script in Attributes in @dcl/single-sign-on-clientImproper input validation in the init function allows arbitrary javascript to be executed using the javascript: prefixHighCWE-79@builder.io/qwik-city Cross-Site Request Forgery vulnerabilityCross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.MediumCWE-352Cleartext Signed Message Signature Spoofing in openpgpOpenPGP Cleartext Signed Messages are cryptographically signed messages where the signed text is readable without special tools:MediumCWE-347Chaijs/get-func-name vulnerable to ReDoSThe current regex implementation for parsing values in the module is susceptible to excessive backtracking, leading to potential DoS attacks.HighCWE-400tarteaucitron.js vulnerable to Cross-site ScriptingCross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1.MediumCWE-79Cross-Site Scripting in serialize-to-jsVersions of serialize-to-js prior to 3.0.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize serialized regular expressions. This vulnerability does not affect...LowCWE-79Unauthorized Access to Private Fields in User Registration API - @strapi/plugin-users-permissions| Name | Value ||———-|————————|| OS | Windows 11 || Version | 4.11.1 (node v16.14.2) || Database | mysql |HighCWE-287Unauthorized Access to Private Fields in User Registration API| Name | Value ||———-|————————|| OS | Windows 11 || Version | 4.11.1 (node v16.14.2) || Database | mysql |HighCWE-287TinyMCE XSS vulnerability in notificationManager.open APIA cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s Notification Manager API. The vulnerability exploits TinyMCE’s unfiltered notification system, which is used in error handling....MediumCWE-79antfu/utils vulnerable to prototype pollutionPrototype Pollution in GitHub repository antfu/utils prior to 0.7.3.MediumCWE-1321Feathers socket handler allows abusing implicit toString - @feathersjs/socketioFeathers socket handler did not catch invalid string conversion errors like:HighCWE-754Feathers socket handler allows abusing implicit toStringFeathers socket handler did not catch invalid string conversion errors like:HighCWE-754editor.md vulnerable to Cross-site ScriptingCross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script or HTML via crafted markdown text.MediumCWE-79Strapi leaking sensitive user information by filtering on private fieldsStrapi through 4.7.1 allows unauthenticated attackers to discover sensitive user details for Strapi administrators and API users.HighCWE-312Strapi plugins vulnerable to Server-Side Template Injection and Remote Code Execution in the Users-Permissions PluginStrapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server.HighCWE-74Cloudera HUE Account EnumerationCloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete.MediumCWE-200external-svg-loader Cross-site Scripting vulnerabilityAccording to the docs, svg-loader will strip all JS code before injecting the SVG file for security reasons but the input sanitization logic is not...HighCWE-79Allocation of Resources Without Limits or Throttling in vriteio/vriteAllocation of Resources Without Limits or Throttling in GitHub repository vriteio/vrite prior to 0.3.0.MediumCWE-770html inputs of type password recorded in plaintext when converted to text inputsHighlight may record passwords on customer deployments when a password html input is switched to type="text" via a javascript “Show Password” button. This differs from...MediumCWE-319Svelecte item names vulnerable to execution of arbitrary JavaScriptSvelecte item names are rendered as raw HTML with no escaping. This allows the injection of arbitrary HTML into the Svelecte dropdown. This can be...MediumCWE-79Strapi does not verify the access or ID tokens issued during the OAuth flowStrapi 3.2.1 until 4.6.0 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used...Mediumckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of EditorIt has been discovered that the ckeditor-wordcount-plugin plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode.MediumCWE-79When setting EntityOptions.apiPrefilter to a function, the filter is not applied to API requests for a resource by IdIf you used the apiPrefilter option of the @Entity decorator, by setting it to a function that returns a filter that prevents unauthorized access to...MediumCWE-284jquery-ui Tooltip widget vulnerable to XSSCross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject...MediumCWE-79MrSwitch hello.js vulnerable to prototype pollutionA prototype pollution vulnerability in MrSwitch hello.js prior to version 1.18.8 allows remote attackers to execute arbitrary code via hello.utils.extend function.HighCWE-1321Uncaught Exception in yamlUncaught Exception in GitHub repository eemeli/yaml starting at version 2.0.0-5 and prior to 2.2.2.HighCWE-248Joplin Cross-site Scripting vulnerability - joplinJoplin before 2.11.5 allows XSS via a USE element in an SVG document.MediumCWE-79Joplin Cross-site Scripting vulnerabilityJoplin before 2.11.5 allows XSS via an AREA element of an image map.MediumCWE-79@udecode/plate-link does not sanitize URLs to prevent use of the `javascript:` schemeAffected versions of the link plugin and link UI component do not sanitize URLs to prevent use of the javascript: scheme. As a result, links...HighCWE-79Cross-Site Scripting in highchartsVersions of highcharts prior to 7.2.2 or 8.1.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize href values and does not restrict...HighCWE-79A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXAA remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.HighCWE-94Strapi Improper Rate Limiting vulnerability - @strapi/plugin-users-permissionsThere is a rate limit on the login function of Strapi’s admin screen, but it is possible to circumvent it.HighCWE-770Strapi Improper Rate Limiting vulnerabilityThere is a rate limit on the login function of Strapi’s admin screen, but it is possible to circumvent it.HighCWE-770Strapi may leak sensitive user information, user reset password, tokens via content-manager views - @strapi/utilsI can get access to user reset password tokens if I have the configure view permissionsMediumCWE-200Strapi may leak sensitive user information, user reset password, tokens via content-manager viewsI can get access to user reset password tokens if I have the configure view permissionsMediumCWE-200`chainId` may be outdated if user changes chains as part of connection in @web3-react - @web3-react/coinbase-walletchainId may be outdated if the user changes chains as part of the connection flow. This means that the value of chainId returned by useWeb3React()...MediumCWE-362`chainId` may be outdated if user changes chains as part of connection in @web3-react - @web3-react/eip1193chainId may be outdated if the user changes chains as part of the connection flow. This means that the value of chainId returned by useWeb3React()...MediumCWE-362`chainId` may be outdated if user changes chains as part of connection in @web3-react - @web3-react/metamaskchainId may be outdated if the user changes chains as part of the connection flow. This means that the value of chainId returned by useWeb3React()...MediumCWE-362`chainId` may be outdated if user changes chains as part of connection in @web3-reactchainId may be outdated if the user changes chains as part of the connection flow. This means that the value of chainId returned by useWeb3React()...MediumCWE-362angular-ui-notification Cross-site Scripting vulnerabilityangular-ui-notification v0.1.0, v0.2.0, and v0.3.6 was discovered to contain a cross-site scripting (XSS) vulnerability.MediumCWE-79Hidden fields can be leaked on readable collections in PayloadIf a user has access to documents that contain hidden fields or fields they do not have access to, the user could reverse-engineer those values...HighCWE-200Use-After-Free in puppeteerVersions of puppeteer prior to 1.13.0 are vulnerable to the Use-After-Free vulnerability in Chromium (CVE-2019-5786). The Chromium FileReader API is vulnerable to Use-After-Free which may...MediumCWE-416Prototype Pollution in NASA Open MCTIn NASA Open MCT (aka openmct) before commit 545a177 is subject to a prototype pollution which can occur via an import action.HighCWE-1321Gatsby develop server has Local File Inclusion vulnerabilityThe Gatsby framework prior to versions 4.25.7 and 5.9.1 contain a Local File Inclusion vulnerability in the __file-code-frame and __original-stack-frame paths, exposed when running the...MediumCWE-22Margox Braft-Editor Cross-site Scripting VulnerabilityCross Site Scripting (XSS) vulnerability in margox braft-editor version 2.3.8, allows remote attackers to execute arbitrary code via the embed media feature.MediumCWE-79Potential for cross-site scripting in PostHog-jsPotential for cross-site scripting in posthog-js.MediumCWE-79matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged roomsIt was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing...LowCWE-200graphql Uncontrolled Resource Consumption vulnerabilityVersions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file...MediumCWE-400@nuxtlabs/github-module made Use of Hard-coded Credentialshttps://nuxt.com had a hardcoded GitHub token in the source code of the page. This token had access to multiple repositories under nuxt, nuxtlabs and nuxt-themes...HighCWE-798Bootbox.js Cross Site Scripting vulnerabilityCross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(),...MediumCWE-79TinyMCE mXSS vulnerability in undo/redo, getContent API, resetContent API, and Autosave pluginA mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo and redo functionality. When a carefully-crafted HTML snippet passes the XSS sanitisation layer,...MediumCWE-79TinyMCE vulnerable to mutation Cross-site Scripting via special characters in unescaped text nodesA mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo/redo functionality and other APIs and plugins. Text nodes within specific parents are not...MediumCWE-79Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpointAn unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary URLs and reflecting the response back to the user.MediumCWE-918chromedriver Command Injection vulnerabilityVersions of the package chromedriver before 119.0.1 are vulnerable to Command Injection when setting the chromedriver.path to an arbitrary system binary. This could lead to...MediumCWE-78NASA Open MCT Cross Site Scripting vulnerabilityCross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary code via the new component feature in...MediumCWE-79NASA Open MCT Cross Site Request Forgery (CSRF) vulnerabilityCross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.MediumCWE-352Uncontrolled Resource Consumption in strapiA denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin rights can lead to arbitrary...MediumCWE-400google-translate-api-browser Server-Side Request Forgery (SSRF) VulnerabilityA Server-Side Request Forgery (SSRF) Vulnerability is present in applications utilizing the google-translate-api-browser package and exposing the translateOptions to the end user. An attacker can...LowCWE-918Exposure of Sensitive Information in eventsourceWhen fetching an url with a link to an external site (Redirect), the users Cookies & Autorisation headers are leaked to the third party application....HighCWE-212uri-template-lite Regular Expression Denial of ServiceAn exponential ReDoS (Regular Expression Denial of Service) can be triggered in the uri-template-lite npm package, when an attacker is able to supply arbitrary input...MediumCWE-697Collection.js vulnerable to Prototype PollutionVersions of the package collection.js before 6.8.1 are vulnerable to Prototype Pollution via the extend function in Collection.js/dist/node/iterators/extend.js.HighCWE-1321Regular expression denial of service in devcertAn exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input...HighCWE-1333dottie vulnerable to Prototype PollutionVersions of the package dottie before 2.0.4 are vulnerable to Prototype Pollution due to insufficient checks, via the set() function and the current variable in...HighCWE-1321fast-xml-parser regex vulnerability patch could be improved from a safety perspectiveThis is a comment on https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-6w63-h3fj-q4vw and the patches fixing it.LowRegular Expression Denial of Service in HandlebarsHandlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing...HighCWE-400Prototype Pollution in handlebars - handlebars - GHSA-q42p-pg8m-cqh6Versions of handlebars prior to 4.0.14 are vulnerable to Prototype Pollution. Templates may alter an Objects’ prototype, thus allowing an attacker to execute arbitrary code...HighCWE-471Arbitrary Code Execution in Handlebars - handlebarsHandlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit...HighCWE-94Remote code execution in handlebars when compiling templatesThe package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source....HighCWE-94Uncontrolled Resource Consumption in HawkHawk is an HTTP authentication scheme providing mechanisms for making authenticated HTTP requests with partial cryptographic verification of the request and response, covering the HTTP...HighCWE-400Validation Bypass in kind-ofVersions of kind-of 6.x prior to 6.0.3 are vulnerable to a Validation Bypass. A maliciously crafted object can alter the result of the type check,...HighCWE-668Inefficient Regular Expression Complexity in marked - markedDenial of service.HighCWE-1333Inefficient Regular Expression Complexity in markedDenial of service.HighCWE-400ReDoS in normalize-urlThe normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it...HighCWE-400Inefficient Regular Expression Complexity in nth-checkThere is a Regular Expression Denial of Service (ReDoS) vulnerability in nth-check that causes a denial of service when parsing crafted invalid CSS nth-checks.HighCWE-1333Prototype pollution in Plist before 3.0.5 can cause denial of servicePrototype pollution vulnerability via .parse() in Plist allows attackers to cause a Denial of Service (DoS) and may lead to remote code execution.HighCWE-1321Prototype Pollution in protobufjsThe package protobufjs is vulnerable to Prototype Pollution, which can allow an attacker to add/modify properties of the Object.prototype. Versions after and including 6.10.0 until...HighCWE-1321Prototype Pollution in querystringifyA vulnerability was found in querystringify before 2.0.0. It’s possible to override built-in properties of the resulting query string object if a malicious string is...HighCWE-1321Code Execution Through IIFE in serialize-to-jsAffected versions of serialize-to-js may be vulnerable to arbitrary code execution through an Immediately Invoked Function Expression (IIFE).HighCWE-502Insecure serialization leading to RCE in serialize-javascriptserialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function “deleteFunctions” within “index.js”.HighCWE-502Uncontrolled Resource Consumption in trim-newlines@rkesters/gnuplot is an easy to use node module to draw charts using gnuplot and ps2pdf. The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for...HighCWE-400underscore-keypath vulnerable to Prototype PollutionVersions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible...HighCWE-1321Incorrect protocol extraction via \r, \n and \t characters\r, \n and \t characters in user-input URLs can potentially lead to incorrect protocol extraction when using npm package urijs prior to version 1.19.11.HighCWE-20Authorization Bypass Through User-Controlled Key in url-parseurl-parse prior to version 1.5.8 is vulnerable to Authorization Bypass Through User-Controlled Key.HighCWE-639Prototype Pollution in vConsolevConsole was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.HighCWE-1321Inefficient Regular Expression Complexity in validator.jsvalidator.js prior to 13.7.0 is vulnerable to Inefficient Regular Expression ComplexityMediumCWE-1333Improper Certificate Validation in xmlhttprequest-sslThe xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to...HighCWE-295xmlhttprequest and xmlhttprequest-ssl vulnerable to Arbitrary Code Injection - xmlhttprequestThis affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into...HighCWE-94xmlhttprequest and xmlhttprequest-ssl vulnerable to Arbitrary Code InjectionThis affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into...HighCWE-94Malicious Package in another-date-pickerVersion 2.0.43 of another-date-picker contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the...HighCWE-506Denial of Service in markdown-it-toc-and-anchorAll versions of markdown-it-toc-and-anchor are vulnerable to Denial of Service. Parsing markdown containing **text**+\n@[toc] causes the application to enter and infinite loop.HighCWE-400Improper Key Verification in ipnsVersions 0.1.1 or 0.1.2 of ipns are vulnerable to improper key validation. This is due to the public key verification was not being performed properly,...HighCWE-287Malicious Package in another-date-range-pickerVersion 4.1.48 of another-date-range-picker contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the...HighCWE-506Denial of Service in ipfs-bitswapVersions of ipfs-bitswap prior to 0.24.1 are vulnerable to Denial of Service (DoS). The package put unwanted blocks in the blockstore, which could be used...MediumCWE-400URIjs Hostname spoofing via backslashes in URLIf using affected versions to determine a URL’s hostname, the hostname can be spoofed by using a backslash (\) character as part of the scheme...HighCWE-20SSRF & Credentials Leaknuxt-api-party allows developers to proxy requests to an API without exposing credentials to the client. A previous vulnerability allowed an attacker to change the baseURL...HighCWE-918Directory Traversal in evershop - @evershop/evershop - GHSA-4wrm-qmq2-5fjxDirectory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the readDirSync function...MediumCWE-22Cross-site Scripting in evershop - @evershop/evershop - GHSA-2xcj-557c-hf8rCross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the sortBy...MediumCWE-79Cross Site Scripting in evershop - @evershop/evershopCross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted request to the ProductGrid...MediumCWE-79Directory Traversal in evershop - @evershop/evershopDirectory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the DELETE function...HighCWE-22Directory Traversal in evershopDirectory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the mkdirSync function...MediumCWE-22Cross-site Scripting in evershopCross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted scripts to the Admin...MediumCWE-79Code execution in evershopAn issue in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information and execute arbitrary code via the /deleteCustomer/route.json file.HighDOS by abusing `fetchOptions.retry`.nuxt-api-party allows developers to proxy requests to an API without exposing credentials to the client. ofetch is used to send the requests.HighCWE-787Buttercup allows attackers to obtain the hash of the master passwordButtercup allows attackers to obtain the hash of the master password for the password manager via accessing the file /vaults.json/.MediumCWE-916fast-xml-parser vulnerable to Prototype Pollution through tag or attribute nameAs a part of this vulnerability, user was able to se code using __proto__ as a tag or attribute name.MediumCWE-1321Cross-site Scripting in @spscommerce/ds-reactXSS, anyone using the SPS Select with options prop populated from user input is impacted. If these options are stored, then it could have been...HighCWE-79mockjs vulnerable to Prototype Pollution via the Util.extend functionAll versions of the package mockjs are vulnerable to Prototype Pollution via the Util.extend function due to missing check if the attribute resolves to the...HighCWE-1321Cube API denial of service attackIt is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint.MediumCWE-20Cross-site Scripting in cesiumA cross-site scripting (XSS) vulnerability in CesiumJS v1.111 allows attackers to execute arbitrary code in the context of the victim’s browser via sending a crafted...MediumCWE-79HTML comments vulnerability allowing to execute JavaScript codeThe vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4.HighCWE-79Sentry's Astro SDK vulnerable to ReDoSA ReDoS (Regular expression Denial of Service) vulnerability has been identified in Sentry’s Astro SDK 7.78.0-7.86.0. Under certain conditions, this vulnerability allows an attacker to...HighCWE-400bsock uses weak hashing algorithmsAn issue was discovered in the bsock component of bcoin-org bcoin that allows remote attackers to obtain sensitive information via weak hashing algorithms in the...HighCWE-327Cross-site scripting vulnerability in TinyMCE - tinymceA cross-site scripting (XSS) vulnerability was discovered in the URL sanitization logic of the core parser. The vulnerability allowed arbitrary JavaScript execution when inserting a...MediumCWE-79Cross-site scripting vulnerability in TinyMCE pluginsA cross-site scripting (XSS) vulnerability was discovered in the URL processing logic of the image and link plugins. The vulnerability allowed arbitrary JavaScript execution when...MediumCWE-79Cross-site scripting vulnerability in TinyMCEA cross-site scripting (XSS) vulnerability was discovered in the schema validation logic of the core parser. The vulnerability allowed arbitrary JavaScript execution when inserting a...MediumCWE-79Layui cross-site scripting (XSS) vulnerabilitylayui up to v2.74 was discovered to contain a cross-site scripting (XSS) vulnerability via the data-content parameter.MediumCWE-79msgpackr's conversion of property names to strings can trigger infinite recursionWhen decoding user supplied MessagePack messages, users can trigger stuck threads by crafting messages that keep the decoder stuck in a loop.HighCWE-674botframework-connector vulnerable to Improper AuthenticationA maliciously crafted claim may be incorrectly authenticated by the bot. Impacts bots that are not configured to be used as a Skill. This vulnerability...MediumCWE-287@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router.HighCWE-639react-native-mmkv Insertion of Sensitive Information into Log File vulnerabilityBefore version v2.11.0, the react-native-mmkv logged the optional encryption key for the MMKV database into the Android system log. The key can be obtained by...MediumCWE-532QooxDoo XSS in Callback ParameterCross-site scripting (XSS) vulnerability in framework/source/resource/qx/test/jsonp_primitive.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2 and 2.3, and possibly other products allows...MediumCWE-79Incorrect Default Permissions in log4jsDefault file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files...MediumCWE-276Sending a GET or HEAD request with a body crashes SvelteKitIn SvelteKit 2 sending a GET request with a body eg {} to a SvelteKit app in preview or with adapter-node throws Request with GET/HEAD...HighCWE-20npm package rfc6902 vulnerable to Prototype PollutionA vulnerability classified as problematic has been found in chbrown rfc6902. This affects an unknown part of the file pointer.ts. The manipulation leads to improperly...HighCWE-74@urql/next Cross-site Scripting vulnerabilityThe @urql/next package is vulnerable to XSS. To exploit this an attacker would need to ensure that the response returns html tags and that the...HighCWE-79@apollo/experimental-nextjs-app-support Cross-site Scripting vulnerabilityThe @apollo/experimental-apollo-client-nextjs NPM package is vulnerable to a cross-site scripting vulnerability. This vulnerability arises from improper handling of untrusted input when @apollo/experimental-apollo-client-nextjs performs server-side rendering...HighCWE-80react-query-streamed-hydration Cross-site Scripting vulnerabilityThe @tanstack/react-query-next-experimental NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this, an attacker would need to either inject malicious input or arrange...HighCWE-79MathJax Regular expression Denial of Service (ReDoS)Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. NOTE:...HighCWE-1333@lobehub/chat vulnerable to unauthorized access to pluginsWhen the application is password-protected (deployed with the ACCESS_CODE option), it is possible to access plugins without proper authorization (without password).MediumCWE-284crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standardNo description available.HighCWE-916shvl vulnerable to prototype pollutionPrototype pollution vulnerability in ‘shvl’ versions 1.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution....HighCWE-1321dset vulnerable to prototype pollutionPrototype pollution vulnerability in ‘dset’ versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution.HighCWE-1321Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS)The Enhanced Image (aka image2) plugin for CKEditor in versions 4.5.10 through 4.9.1; fixed in 4.9.2, and as used in Drupal 8 before 8.4.7 and...MediumCWE-79Ckeditor XSS VulnerabilityCKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.MediumCWE-79Arbitrary Code Execution in handlebarsVersions of handlebars prior to 3.0.8 or 4.5.2 are vulnerable to Arbitrary Code Execution. The package’s lookup helper fails to properly validate templates, allowing attackers...HighCWE-94CKEditor cross-site scripting vulnerability in AJAX sampleThe vulnerability has been discovered in the AJAX sample available at the samples/old/ajax.html file location. All integrators that use that sample in the production code...MediumCWE-79ckeditor4 vulnerable to cross-site scriptingA cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript...MediumCWE-79Regular Expression Denial of Service in markedVersions 0.3.3 and earlier of marked are affected by a regular expression denial of service ( ReDoS ) vulnerability when passed inputs that reach the...HighCWE-1333Luxon Inefficient Regular Expression Complexity vulnerabilityLuxon’s DateTime.fromRFC2822() has quadratic (N^2) complexity on some specific inputs. This causes a noticeable slowdown for inputs with lengths above 10k characters. Users providing untrusted...HighCWE-1333Stimulsoft Dashboard.JS directory traversal vulnerabilityDirectory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.3 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName...HighCWE-22Stimulsoft Dashboard.JS Cross Site Scripting vulnerabilityCross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the...MediumCWE-79Default swagger-ui configuration exposes all files in the moduleThe default configuration of @fastify/swagger-ui without baseDir set will lead to all files in the module’s directory being exposed via http routes served by the...MediumCWE-1188GitHub Security Lab (GHSL) Vulnerability Report, scrypted: `GHSL-2023-218`, `GHSL-2023-219`The GitHub Security Lab team has identified potential security vulnerabilities in scrypted.HighPrototype Pollution in JSON5 via Parse MethodThe parse method of the JSON5 library before and including version 2.2.1 does not restrict parsing of keys named __proto__, allowing specially crafted strings to...HighCWE-1321Misinterpretation of malicious XML input - xmldomxmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes...MediumCWE-116Misinterpretation of malicious XML inputxmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes...MediumCWE-116Marvin Attack of RSA and RSAOAEP decryption in jsrsasignRSA PKCS#1.5 or RSAOAEP ciphertexts may be decrypted by this Marvin attack vulnerability.HighCWE-203Starcounter-Jack JSON-Patch Prototype Pollution vulnerabilityA vulnerability has been found in Starcounter-Jack JSON-Patch up to 3.1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improperly...HighCWE-1321CKEditor4 Cross-site Scripting vulnerability in samples with enabled the preview featureThe vulnerability has been discovered in the samples that use the preview feature:MediumCWE-79Stimulsoft Dashboard.JS Cross Site Scripting vulnerability - stimulsoft-dashboards-jsCross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the...MediumCWE-79CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detectionThe vulnerability has been discovered in the core HTML parsing module and may affect all editor instances that: Enabled full-page editing mode, or enabled CDATA...MediumCWE-79JSONata expression can pollute the "Object" prototypeIn JSONata versions >= 1.4.0, < 1.8.7 and >= 2.0.0, < 2.0.4, a malicious expression can use the transform operator to override properties on the...HighCWE-1321TurboBoost Commands vulnerable to arbitrary method invocationTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren’t as...HighCWE-74Strapi 4.1.12 Cross-site Scripting via crafted fileAn unrestricted file upload vulnerability in the Add New Assets function of Strapi v4.1.12 allows attackers to execute arbitrary code via a crafted file. After...MediumCWE-79RSSHub Cross-site Scripting vulnerability caused by internal media proxyWhen the specially crafted image is supplied to the internal media proxy, it proxies the image without handling XSS vulnerabilities, allowing for the execution of...MediumCWE-79RSSHub vulnerable to Server-Side Request ForgeryServeral Server-Side Request Forgery (SSRF) vulnerabilities in RSSHub allow remote attackers to use the server as a proxy to send HTTP GET requests to arbitrary...MediumCWE-918SQL injection in typeORMThe findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a...HighCWE-89Path traversal in webpack-dev-middlewareNo description available.HighCWE-22Cache Poisoning VulnerabilityAn attacker controlling the second variable of the translate function is able to perform a cache poisoning attack. They can change the outcome of translation...MediumCWE-20Regular Expression Denial of Service in debugAffected versions of debug are vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter.LowCWE-400KaTeX's maxExpand bypassed by Unicode sub/superscriptsKaTeX users who render untrusted mathematical expressions could encounter malicious input using \def or \newcommand that causes a near-infinite loop, despite setting maxExpand to avoid...MediumCWE-674KaTeX's `\includegraphics` does not escape filenameKaTeX users who render untrusted mathematical expressions could encounter malicious input using \includegraphics that runs arbitrary JavaScript, or generate invalid HTML.MediumCWE-116KaTeX missing normalization of the protocol in URLs allows bypassing forbidden protocolsCode that uses KaTeX’s trust option, specifically that provides a function to block-list certain URL protocols, can be fooled by URLs in malicious inputs that...MediumCWE-184OneUptime Vulnerable to a Privilege Escalation via Local Storage Key ManipulationA security vulnerability exists in oneuptime’s local storage handling, where a regular user can escalate privileges by modifying the is_master_admin key to true. This allows...HighCWE-639TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elementsA cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code. A SVG image could be loaded though an object or...MediumCWE-79TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframesA cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content insertion code. This allowed iframe elements containing malicious code to execute when inserted into the editor.MediumCWE-79@workos-inc/authkit-nextjs session replay vulnerabilityA user can reuse an expired session by controlling the x-workos-session header.MediumCWE-294jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext - jose-node-cjs-runtimeA vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. This...MediumCWE-400jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext - jose-node-esm-runtimeA vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. This...MediumCWE-400jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintextA vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. This...MediumCWE-400Formstone Vulnerable to Reflected XSSFormstone <=1.4.16 is vulnerable to a Reflected Cross-Site Scripting (XSS) vulnerability caused by improper validation of user supplied input in the upload-target.php and upload-chunked.php files....MediumCWE-79MooTools Regular Expression Denial of ServiceMooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial...HighCWE-400jplayer Cross Site Scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.3.MediumCWE-79jQuery-Upload-File XSS in fileNameStrA cross-site scripting (XSS) vulnerability in the fileNameStr parameter of jQuery-Upload-File v4.0.11 allows attackers to execute arbitrary web scripts or HTML via a crafted file...MediumCWE-79json-pointer vulnerable to Prototype PollutionA vulnerability, which was classified as critical, has been found in json-pointer up to 0.6.1. Affected by this issue is the function set of the...HighCWE-1321Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeUsing Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely...HighCWE-697dectalk-tts Uses Unencrypted HTTP RequestIn [email protected], network requests to the third-party API are sent over HTTP, which is unencrypted. Unencrypted traffic can be easily intercepted and modified by attackers....HighCWE-598React Native Sms User Consent Intent Redirection VulnerabilityA vulnerability, which was classified as critical, has been found in kyivstarteam react-native-sms-user-consent up to 1.1.4 on Android. Affected by this issue is the function...MediumCWE-926Summernote vulnerable to cross-site scriptingCross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code via a crafted payload to the codeview parameter....MediumCWE-79Matrix IRC Bridge truncated content of messages can be leakedThe matrix-appservice-irc before version 2.0.0 can be exploited to leak the truncated body of a message if a malicious user sends a Matrix reply to...MediumCWE-280Handling untrusted input can result in a crash, leading to loss of availability / denial of serviceUsing particular inputs with @solana/web3.js will result in memory exhaustion (OOM).HighCWE-119Prototype pollution in emit functionA prototype pollution in derby can crash the application, if the application author has atypical HTML templates that feed user input into an object key....LowCWE-1321Stored Cross-site Scripting (XSS) in excalidraw's web embed componentA stored XSS vulnerability in Excalidraw’s web embeddable component. This allows arbitrary JavaScript to be run in the context of the domain where the editor...MediumCWE-79zcap has incomplete expiration checks in capability chains.When invoking a capability with a chain depth of 2, i.e., it is delegated directly from the root capability, the expires property is not properly...MediumCWE-613Insufficient validation when decoding a Socket.IO packet - socket.io-parserDue to improper type validation in the socket.io-parser library (which is used by the socket.io and socket.io-client packages to encode and decode Socket.IO packets), it...HighCWE-89Regular Expression Denial Of Service in uri-jsAffected versions of uri-js is susceptible to a regular expression denial of service vulnerability when user input is sent to the .parse() method.MediumCWE-400Regular Expression Denial of Service in remarkablelib/common/html_re.js in remarkable 1.7.1 allows Regular Expression Denial of Service (ReDoS) via a CDATA section.HighCWE-400jqueryFileTree vulnerable to Directory TraversaljqueryFileTree 2.1.5 and older is vulnerable to Directory TraversalHighCWE-22Prototype pollution vulnerability in 'deep-setThe NPM module ‘deep-set’ can be abused by Prototype Pollution vulnerability since the function deepSet() does not check for the type of object before assigning...HighCWE-1321CKEditor 4 ReDoS VulnerabilityIt was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input...MediumCWE-1333mootools-more vulnerable to prototype pollutionImproperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’) in mootools-more 1.6.0 allows a malicious user to inject properties into Object.prototype.HighCWE-1321Sanitize-html Vulnerable To REDoS AttacksThe package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment...HighCWE-1333deep-defaults vulnerable to prototype pollutionPrototype pollution vulnerability in ‘deep-defaults’ versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.HighCWE-1321Joplin vulnerable to Cross-site Scripting in notesJoplin before 2.0.9 allows Cross-site Scripting via button and form in the note body.MediumCWE-79Joplin Vulnerable to Code InjectionJoplin prior to version 2.7.1 allows remote attackers to execute system commands through malicious code in user search results.HighCWE-94Joplin Vulnerable to Cross-site Scripting in Note ContentJoplin version prior to 1.0.90 contains a Cross-site Scripting (XSS) evolving into code execution due to enabled nodeIntegration for that particular BrowserWindow instance where XSS...MediumCWE-79Joplin Cross Site Scripting Vulnerability via NOSCRIPT tagsCross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html.MediumCWE-79Joplin Remote Code ExecutionJoplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via...HighCWE-20MediaElement Vulnerable to Reflected XSSCross-site scripting (XSS) vulnerability in flash/FlashMediaElement.swf in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or...MediumCWE-79Prototype Pollution in immer - immer - GHSA-c36v-fmgq-m8hximmer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’).HighCWE-915Prototype Pollution in immer - immerAffected versions of immer are vulnerable to Prototype Pollution.HighCWE-471Prototype Pollution in immerThis affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used in the...HighCWE-843Server-Side Template Injection in formioA Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL. NOTE:...HighCWE-74Apache 2.4.49 Path Traversal and RCEA vulnerability was discovered in Apache HTTP Server 2.4.49 related to changes made to path normalization. This flaw enables attackers to perform path traversal attacks,...HighCWE-78Apache Expect Header Cross Site ScriptingCross-Site Scripting (XSS) attacks occur when malicious scripts are injected into trusted websites, often through user inputs, and executed in the browsers of other users....HighCWE-79Apache mod_jk Access Control BypassThe Apache Web Server (httpd) with Apache Tomcat JK (mod_jk) Connector versions 1.2.0 to 1.2.44 contains a flaw in path normalization, allowing specially crafted requests...HighApache mod_proxy 2.4.48 SSRFA vulnerability exists in Apache HTTP Server 2.4.48 and earlier versions, specifically within the mod_proxy module. An attacker can exploit this flaw by crafting a...MediumCWE-918Apache server-info enabledExposing the Apache server-info page allows attackers to gather detailed information about the server configuration, installed modules, and other system-related details, aiding potential attacks.MediumCWE-200Apache server-status enabledExposing the Apache server-status page allows attackers to gather detailed information about the server’s current state, facilitating potential attacks by revealing active connections, server uptime,...MediumCWE-200Apache Struts 2 Forced double OGNL evaluation S2-059The Apache Struts framework, when forced, performs double evaluation of attributes’ values assigned to certain tags attributes such as id. This allows attackers to pass...HighCWE-78Apache Struts 2 RCE S2-045Apache Struts 2 suffers from a Remote Code Execution (RCE) vulnerability, designated as S2-045. This vulnerability allows attackers to execute arbitrary commands on the server...HighCWE-78Apache Struts 2 REST plugin XStream RCE S2-052Apache Struts 2, specifically the REST Plugin, is susceptible to a Remote Code Execution (RCE) vulnerability identified as S2-052. This vulnerability arises due to the...HighCWE-78Apache Struts OGNL expression RCE S2-057A Remote Code Execution (RCE) attack is possible in Apache Struts when alwaysSelectFullNamespace is set to true (either by the user or by a plugin...HighCWE-78Apache Tomcat JSP Upload RCEApache Tomcat is susceptible to a Remote Code Execution (RCE) vulnerability when running on Windows with HTTP PUTs enabled. By sending a specially crafted request,...HighCWE-78Apache Tomcat Manager Login FoundBy default, the Tomcat Manager application should only be accessible from a browser running on the same machine as Tomcat. However, if the Manager login...MediumApache Version DisclosureA misconfigured web server may expose the Apache version number either in the Server HTTP header or in the body of error pages. Attackers leverage...InformationalCWE-200Application and Database ErrorAn application and database error occurs when the application encounters issues related to both its functionality and interaction with the database backend. Unhandled exceptions in...MediumCWE-209Application ErrorUnhandled exceptions pose two primary risks. Firstly, they can lead to denial of service by causing memory leaks or excessive resource consumption. Secondly, they may...MediumCWE-209Arbitrary Source Code DisclosureArbitrary Source Code Disclosure is a vulnerability that occurs when it’s possible to access the source code of any file on a web application, potentially...HighCWE-540ASP.NET Version DisclosureThe presence of the X-AspNet-Version and X-AspNetMvc-Version headers exposes the version of ASP.NET used by the web server, providing valuable information to attackers. This disclosure...InformationalCWE-200Auto Complete Enabled Password InputEnabling autocomplete for password input fields allows browsers to save and autofill sensitive information, such as passwords. This poses a security risk, particularly on shared...LowCWE-16Basic Authentication Over HTTPUsing Basic Authentication over HTTP exposes user credentials to potential interception by attackers who can sniff and capture HTTP traffic. This authentication method sends credentials...MediumCWE-319Blind OS Command ExecutionBlind OS Command Execution, also known as Command Injection, is a severe vulnerability that allows attackers to execute arbitrary commands on the host operating system...HighCWE-78Blind SQL InjectionBlind SQL Injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database without directly...HighCWE-89BREACH attackBREACH is a variant of the CRIME attack that targets HTTP compression, specifically gzip or DEFLATE algorithms used via the content-encoding option within HTTP. Attackers...LowCWE-310Broken LinkBroken hyperlinks in web pages can create a bad experience for the users. It can also affect the web page ranking in web search results....InformationalBrute Force Prevention BypassedBrute Force Prevention Bypassed occurs when software lacks adequate measures to counter multiple failed authentication attempts within a short time frame, rendering it vulnerable to...MediumCWE-307Buffer OverflowBuffer overflow occurs when an application accepts more data than it can handle, leading to data overflowing the designated memory space. This vulnerability can be...MediumCWE-119Content Character Encoding is not DefinedWhen the character encoding is not explicitly defined in web content, browsers may resort to guessing or using a default encoding. This can lead to...InformationalCWE-16Content-Security-Policy Header is MissingThe absence of the Content-Security-Policy (CSP) response header leaves a website vulnerable to various types of attacks, including Cross-Site Scripting (XSS) and data injection attacks....LowCWE-16Cookie Accessible for SubdomainsThe presence of the Domain attribute in the Set-Cookie header instructs browsers to send the cookie to any subdomains of the specified domain. This can...InformationalCWE-16Cookie without HttpOnly FlagThe absence of the HttpOnly flag in cookies allows JavaScript running on the client-side to access them through the Document.cookie API. This presents a security...LowCWE-16Cookie without SameSite FlagThe absence of the SameSite flag in cookies leaves them vulnerable to cross-site request forgery (CSRF) attacks, where unauthorized actions are performed on behalf of...LowCWE-16Cookie without Secure FlagThe absence of the Secure flag in cookies allows them to be transmitted over unencrypted connections, making them vulnerable to interception by attackers conducting man-in-the-middle...LowCWE-614CRIME (SPDY) attackThe CRIME (Compression Ratio Info-leak Made Easy) attack targets the SPDY protocol versions 3 and earlier, used in browsers like Mozilla Firefox and Google Chrome....LowCWE-310CRIME (SSL/TLS) attackCRIME (Compression Ratio Info-leak Made Easy) is a security exploit targeting secret web cookies transmitted over HTTPS and SPDY connections utilizing data compression. By analyzing...LowCWE-310CRLF Injection in URLCRLF injection involves injecting Carriage Return (ASCII 13, \r) and Line Feed (ASCII 10, \n) characters into web requests or responses. These characters are used...HighCWE-93Cross-Origin Resource Sharing AllowedCross-Origin Resource Sharing (CORS) is a mechanism that uses additional HTTP headers to allow a web application running at one origin to access selected resources...InformationalCWE-942Cross Site ScriptingCross-Site Scripting (XSS) attacks occur when malicious scripts are injected into trusted websites, often through user inputs, and executed in the browsers of other users....HighCWE-79Database ErrorA database error occurs when the application encounters an issue while interacting with the database backend. Such errors can arise due to various factors, including...MediumCWE-209Detailed Application and Database ErrorDetailed application and database errors occur when the application encounters issues related to both its functionality and interaction with the database backend. These errors expose...MediumCWE-209Detailed Application ErrorDetailed application errors, caused by unhandled exceptions, pose two primary risks. Firstly, they can lead to denial of service by causing memory leaks or excessive...MediumCWE-209Directory Listing of Sensitive FilesDirectory listing of sensitive files occurs when directory listing, if enabled, exposes the complete index of resources within a directory to potential attackers. This can...LowCWE-548Directory ListingDirectory listing, when enabled, exposes the complete index of resources within a directory to potential attackers. This can lead to unauthorized access to sensitive files...LowCWE-548Drupal 4.1/4.2 XSSCross-Site Scripting (XSS) attacks occur when malicious scripts are injected into trusted websites, often through user inputs, and executed in the browsers of other users....HighCWE-79Drupal 'Drupalgeddon2' Remote Code ExecutionA vulnerability in multiple subsystems of Drupal allows remote attackers to execute arbitrary operating system commands on the server, leading to potential compromise of the...HighCWE-78Drupal Module Cumulus Cross Site ScriptingCross-Site Scripting (XSS) attacks occur when malicious scripts are injected into trusted websites, often through user inputs, and executed in the browsers of other users....HighCWE-79Drupal7 Pre Auth SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Email Address DisclosureThe disclosure of email addresses on webpages can make them vulnerable to harvesting by spambots, leading to an influx of unsolicited spam emails.InformationalCWE-200Expression Language InjectionExpression Language Injection (EL Injection) is a critical vulnerability that occurs when user inputs are used to construct dynamic expressions in web applications without proper...HighCWE-917File Upload FunctionalityThe <input> element with type="file" enables users to select and upload files from their device storage to a remote server. However, unrestricted file upload functionality...InformationalHidden Resource in Robots.txtHidden resources in robots.txt refer to sensitive paths or directories that are inadvertently exposed in the robots.txt file. The robots.txt file is used to instruct...MediumCWE-200Host Header InjectionDuring the processing of an incoming HTTP request, the web server relies on the Host HTTP header to determine which component or virtual host should...MediumHTTP Protocol Stack Remote Code Execution Vulnerability (DOS)A vulnerability in the Microsoft Windows HTTP Protocol Stack (HTTP.sys) allows remote attackers to execute arbitrary code or cause a system crash on the host...HighHTTP Response SplittingHTTP response splitting is the result of the failure of a web application to properly sanitize CR (ASCII 0x0D) and LF (ASCII 0x0A) character in...HighCWE-20Insecure Deserialization Remote Code ExecutionInsecure deserialization remote code execution is a critical security vulnerability that occurs when an application deserializes a user-supplied object string without properly verifying its integrity....HighCWE-502Insecure DeserializationInsecure deserialization occurs when an application deserializes a user-supplied object string without properly verifying its integrity. This vulnerability enables attackers to manipulate the system state...HighCWE-502Insecure Inline FrameWhen an inline frame tag (<iframe>) on a webpage references an external resource without the sandbox attribute set, it allows the external URL to manipulate...MediumCWE-829Internal Server ErrorAn internal server error occurs when the server encounters an unexpected condition that prevents it from fulfilling the request. This error can result from various...MediumCWE-755Joomla! 1.5 < 3.4.5 RCEOS Command Execution, also known as Command Injection, is a severe vulnerability that allows attackers to execute arbitrary commands on the host operating system. Attackers...HighCWE-78Joomla! < 1.7.0 XSSCross-Site Scripting (XSS) attacks occur when malicious scripts are injected into trusted websites, often through user inputs, and executed in the browsers of other users....HighCWE-79Joomla! 3.2.1 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Advertisement Board 3.1.0 'catname' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Aist 2.0 'id' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component AllVideos Reloaded 1.2.x 'divid' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component CcNewsletter 2.x.x 'id' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Com_cbcontact 'contact_id' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Com_contenthistory SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Com_fields 3.7 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component com_hdwplayer 4.2 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Com_newsfeeds 1.0 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Com_rsgallery2 2.0 'catid' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Com_shop 'editid' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Com_shop 'id' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component DT Register 3.2.7 'id' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Fastball 2.5 'season' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component File Download Tracker 3.0 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Form Maker 3.6.12 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Google Map Landkarten 4.2.3 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component InviteX 3.0.5 'invite_type' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component JB Bus 2.3 'order_number' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component JCK Editor 6.4.4 'parent' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component JCK Editor 6.4.4 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component JEXTN Video Gallery 3.0.5 'id' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component JGive 2.0.9 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Jobs Factory 2.0.4 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component JomEstate PRO 3.7 'id' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component JquickContact 1.3.2.2.1 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Music Collection 3.0.3 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component NextGen Editor 2.1.0 'plname' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Odudeprofile 2.8 'profession' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Reverse Auction Factory 4.3.8 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! Component Timetable Responsive Schedule For Joomla! 1.5 'alias' SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Joomla! 'J2Store < 3.3.7' SQL InjectionA vulnerability in the J2Store component for Joomla! allows attackers to inject and execute SQL commands on the website’s database, potentially leading to data theft,...HighJoomla! Pinterest Clone Social Pinboard 2.0 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89Local File InclusionLocal File Inclusion (LFI) is a vulnerability that allows attackers to include local files, exploiting dynamic file inclusion mechanisms in the target application. This occurs...HighCWE-98Microsoft IIS Tilde Directory EnumerationIn some versions of Microsoft IIS, it is possible to detect the existence of files using an 8.3 short filename (SFN). This vulnerability allows attackers...MediumCWE-200Missing or Insecure Cache-Control HeaderWeb cache or HTTP cache is a system used to optimize web performance. Browsers cache the contents of a resource to reuse it on subsequent...InformationalCWE-525Nginx Code Execution due to MisconfigurationMisconfigurations in Nginx, particularly with PHP FPM (FastCGI Process Manager), can lead to a critical security vulnerability. Attackers can exploit this misconfiguration by appending /.php...HighCWE-16Nginx Integer OverflowNginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to an integer overflow vulnerability in the nginx range filter module. This vulnerability can...HighCWE-200Nginx Null Byte Code ExecutionAllowing null byte character (ASCII 0x00) in the URL can lead to a severe security risk. If the user can manipulate file contents on the...HighCWE-158Nginx Restriction Bypass via Space Character in URIA vulnerability in Nginx allows attackers to bypass security restrictions in specific configurations by exploiting a flaw in request URI processing. When an unescaped space...HighCWE-20Nginx Version DisclosureThe Server header reveals detailed information about the server application handling the request, including the Nginx version. Exposing this information can aid attackers in identifying...InformationalCWE-200No HTTPSIn HTTP communications, traffic is not encrypted and can be captured by an attacker who has access to a network interface. This exposes sensitive information...MediumCWE-319No Redirection from HTTP to HTTPSIn scenarios where HTTPS is enabled but HTTP requests are not automatically redirected to HTTPS, users must explicitly use the HTTPS URL to ensure encrypted...MediumCWE-311Old/Backup Resource FoundOld or backup files left accessible on a web server can inadvertently expose sensitive information such as source code, administrative interfaces, or credentials. These files...LowCWE-530Open Redirection In URLUnvalidated redirects and forwards occur when a web application accepts untrusted input that could redirect the user to a URL provided within the input. Attackers...HighCWE-601OS Command ExecutionOS Command Execution, also known as Command Injection, is a severe vulnerability that allows attackers to execute arbitrary commands on the host operating system. Attackers...HighCWE-78Passive Mixed ContentWhen a user visits a page served over HTTPS, their connection with the web server is encrypted with TLS, protecting it from most sniffers and...LowCWE-319Password Input on HTTPWhen passwords are sent over unencrypted HTTP traffic, attackers can intercept and capture them easily, leading to unauthorized access to user accounts, sensitive data exposure,...MediumCWE-319Password Sent in HTTP QueryWhen passwords are included in URLs and sent as part of HTTP queries, they may be logged in various places, including server logs, and disclosed...MediumCWE-319Password Sent in QueryWhen passwords are included in URLs and sent as part of HTTP queries, they may be logged in various places, including server logs, and disclosed...LowCWE-598Password Sent Over HTTPWhen passwords are sent over unencrypted HTTP traffic, attackers can intercept and capture them easily, leading to unauthorized access to user accounts, sensitive data exposure,...MediumCWE-319Path Disclosure in Robots.txtPath disclosure in robots.txt occurs when sensitive paths or directories are inadvertently exposed in the robots.txt file. The robots.txt file is used to instruct web...InformationalCWE-200PHP Version DisclosureExposing the PHP version used by the server facilitates attackers in identifying vulnerabilities more easily. This information exposes the server to potential risks.InformationalCWE-200phpinfo() FoundThe phpinfo() method in PHP reveals extensive details about the PHP environment, including configuration settings, server information, and installed extensions. While useful for debugging and...MediumCWE-200Possible SQL InjectionPossible SQL Injection refers to a potential vulnerability where input data may be susceptible to SQL injection attacks. SQL injection is a type of attack...HighCWE-89Private IPv4 Address DisclosurePrivate IPv4 addresses are reserved for use within private networks such as local area networks (LANs). Revealing private IP addresses can provide insights into the...InformationalCWE-200Private IPv6 Address DisclosurePrivate IPv6 addresses are reserved for use within private networks and are not routable on the public Internet. Disclosing private IPv6 addresses can provide attackers...InformationalCWE-200ProfanityThe presence of profanity in web pages can create a negative user experience and may lead to decreased user engagement. Additionally, profanity can impact the...InformationalPublic-Key-Pins Header is SetThe HTTP Public-Key-Pins response header was used to associate a specific cryptographic public key with a web server to mitigate the risk of MITM attacks...InformationalCWE-16Redirection with BodyAn HTTP redirection (3XX status code) typically does not include a body. However, if a body is present in the redirection response, it indicates that...LowCWE-698Referrer-Policy Header is MissingThe Referrer-Policy HTTP header controls the amount of referrer information (sent via the Referer header) included with requests. The Referer header contains the address of...InformationalCWE-16Remote File DisclosureRemote File Disclosure (RFD) is a vulnerability that allows an attacker to disclose files located on remote servers, exploiting dynamic file inclusion mechanisms implemented in...HighCWE-98Remote File InclusionRemote File Inclusion (RFI) is a vulnerability that allows attackers to include remote files, exploiting dynamic file inclusion mechanisms in the target application. This occurs...HighCWE-98Remote URL InclusionRemote URL Inclusion (RUI) is a vulnerability that allows an attacker to include a remote URL, exploiting dynamic URL inclusion mechanisms implemented in the target...HighCWE-98Robots.txt FoundThe robots.txt file is used to instruct web robots on which parts of a website to avoid crawling or indexing. While intended for cooperation with...InformationalCWE-200Secure Renegotiation is not supportedWhen a server does not support secure renegotiation in SSL/TLS connections, it becomes vulnerable to content injection at the start of sessions. This vulnerability requires...LowCWE-310Sensitive Old/Backup Resource FoundSensitive Old/Backup Resource Found refers to old or backup files left accessible on a web server, which can inadvertently expose sensitive information such as source...MediumCWE-530Sensitive Unreferenced Resource FoundSensitive Unreferenced Resource Found refers to the discovery of sensitive resources within a web application that are not directly linked or referenced within the application...LowCWE-552Serialized Object FoundObject serialization allows transferring complex data structures over channels like HTTP. However, the presence of a serialized object within the application indicates potential vulnerabilities related...HighCWE-502Server Version DisclosureThe Server header describes the server application that handled the request. Detailed information in this header can expose the server to attackers. Using the information...LowCWE-200Session Cookie Accessible for SubdomainsWhen the Domain attribute is present in the Set-Cookie header, browsers send the cookie to any subdomains of the specified domain. This can result in...LowCWE-16Session Cookie without HttpOnly FlagThe absence of the HttpOnly flag in session cookies allows client-side JavaScript to access them, which poses a security risk. Without the HttpOnly flag, session...MediumCWE-16Session Cookie without SameSite FlagThe absence of the SameSite flag in session cookies leaves them vulnerable to cross-site request forgery (CSRF) attacks, where unauthorized actions are performed on behalf...MediumCWE-16Session Cookie without Secure FlagThe absence of the Secure flag in session cookies allows them to be transmitted over unencrypted connections, making them vulnerable to interception by attackers conducting...MediumCWE-614Source Code DisclosureSource code disclosure occurs when the source code of a web application is inadvertently exposed to users, potentially revealing sensitive information such as credentials, API...MediumCWE-540SQL Command DisclosureSQL commands reveal information about the structure of the underlying database. This information does not create any direct impact on the target, though it provides...InformationalCWE-89SQL InjectionSQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89SSL 2 enabledSSL version 2 is known to have numerous security vulnerabilities, rendering it highly insecure and susceptible to attacks.HighCWE-326SSL 3 enabledSSL version 3 is vulnerable to padding oracle attacks and other cryptographic weaknesses, making it insecure for use in secure communication.MediumCWE-326Strict-Transport-Security Header is MissingThe absence of the HTTP Strict-Transport-Security (HSTS) response header leaves a website vulnerable to protocol downgrade attacks and session hijacking. Without this header, attackers can...LowCWE-16Subresource Integrity is MissingSubresource Integrity (SRI) is a security feature that allows browsers to verify that resources fetched, such as from a content delivery network (CDN), are delivered...LowCWE-353The Heartbleed BugHeartbleed is a critical security vulnerability found in the OpenSSL cryptography library, used for implementing the Transport Layer Security (TLS) protocol. Attackers can exploit this...HighCWE-200The POODLE attackThe POODLE attack (Padding Oracle On Downgraded Legacy Encryption) is a vulnerability that exploits SSL 3.0 fallback mechanisms in internet and security software clients. Attackers...MediumCWE-327The ShellShock BugShellshock, also known as Bashdoor, is a critical vulnerability in the Unix Bash shell that allows attackers to execute arbitrary commands and gain unauthorized access....HighCWE-78Time Based SQL InjectionTime Based SQL Injection is a type of SQL injection attack where the attacker manipulates the timing of SQL query execution to infer information about...HighCWE-89TLS 1.0 enabledTLS version 1.0 is known to have several security vulnerabilities and weaknesses, making it susceptible to attacks.MediumCWE-326TLS 1.1 enabledTLS version 1.1 is known to have several security vulnerabilities and weaknesses, rendering it insecure for use.LowCWE-326Tomcat Version DisclosureExposing detailed information such as the Tomcat version number facilitates attackers in identifying vulnerabilities and planning their attacks more effectively.InformationalCWE-200TRACE Method AllowedThe HTTP TRACE method allows clients to view the entire request received by the web server, primarily for testing and diagnostic purposes. However, enabling this...LowCWE-16TRACK Method AllowedThe HTTP TRACK and TRACE methods allow the client to see the entire request that the web server has received. Although primarily intended for testing...LowCWE-16Unicode Transformation IssueThe Unicode Standard provides a unified encoding scheme for characters worldwide, enhancing program globalization and security. However, improper usage of Unicode can introduce security vulnerabilities,...HighCWE-176Unix Path DisclosureFile and directory paths reveal information about the structure of the file system of the underlying OS. While this information does not directly impact the...InformationalCWE-200Unreferenced Repository FoundUnreferenced repositories, such as those from version control systems like Git, SVN, CVS, and Mercurial, contain valuable information such as source code, historical changes, and...HighCWE-552Unreferenced Resource FoundUnreferenced resources in web applications may reveal sensitive information and provide attackers with insights into potential attack vectors. These resources, although not directly linked or...InformationalCWE-552Unreferenced Source Code DisclosureUnreferenced Source Code Disclosure is a vulnerability that occurs when a backup file or source code file of an application is accessible to users, potentially...HighCWE-540Unvalidated RedirectionUnvalidated redirects and forwards occur when a web application accepts untrusted input that could redirect the user to a URL provided within the input. Attackers...HighCWE-601User Controllable URLUser-controllable URLs refer to HTML attributes with a value type of URI, such as href in the a tag or src in the img tag....MediumCWE-20User EnumerationUser Enumeration occurs when web applications inadvertently reveal whether a username exists on the system, either due to misconfiguration or design decisions. Attackers exploit this...MediumCWE-209ViewState is not EncryptedThe ViewState, a hidden form input in ASP.NET pages, automatically persists information and application data specific to a page. If the ViewState is not encrypted,...InformationalCWE-200Weak PasswordWeak Password vulnerabilities arise when applications fail to enforce strong password policies, making it easier for attackers to guess or crack users’ passwords, leading to...HighCWE-521Web Server Path TraversalWhen a web server fails to properly normalize and validate the ../ sequence in URL paths, it enables attackers to access files outside the intended...HighCWE-22Werkzeug Interactive Debugging is ActiveWerkzeug is a comprehensive WSGI web application library for the Python language. Werkzeug provides a WSGI middleware that renders nice tracebacks, optionally with an interactive...MediumCWE-209Windows Path DisclosureFile and directory paths reveal information about the structure of the file system of the underlying OS. This information does not create any direct impact...InformationalCWE-200WordPress 4.6 Blind OS Command ExecutionPHPMailer before 5.2.18 allows remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code. It is possible to execute remote...HighCWE-78WordPress Plugin AdRotate 3.6.5 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin AdRotate 3.6.6 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin AdRotate 3.9.4 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin All Video Gallery 1.1 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Bannerize 2.8.6 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Bannerize 2.8.7 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Business Intelligence SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Chained Quiz 1.0.8 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Community Events 1.2.1 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin CP Multi View Event Calendar 1.01 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin CP Multi View Event Calendar 1.1.4 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin CP Multi View Event Calendar 1.1.7 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin DS FAQ 1.3.2 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Easy Contact Form Lite 1.0.7 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Event Registration 5.4.3 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Eventify Simple Events 1.7.f SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Facebook Promotions 1.3.3 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin File Groups 1.1.2 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin FireStorm Professional Real Estate 2.06.01 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Forum Server 1.7 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Glossary SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Google Document Embedder 2.5.14 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Google Document Embedder 2.5.16 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Hitasoft_player Ripe HD FLV Player 1.1 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Jetpack SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin JTRT Responsive Tables 4.1 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin KNR Author List Widget 2.0.0 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin LeagueManager 3.8 SQLIAn SQL Injection vulnerability exists in the league_id parameter of a function call made by the leaguemanager_export page.HighWordPress Plugin Link Library 5.2.1 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin NEX Forms 3.0 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Olimometer 2.56 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin OQey Headers 0.3 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Paid Downloads 2.01 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Post Highlights 2.2 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin SCORM Cloud 1.0.6.6 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin SH Slideshow 3.1.4 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Smart Google Code Inserter 3.5 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Tune Library 2.17 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Users Ultra 1.5.50 Blind SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin VideoWhisper Video Presentation 1.1 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin WP Fastest Cache 0.8.4.8 Blind SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin WP Statistics 13.0.7 Time Based SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin WP Support Plus Responsive Ticket System 7.1.3 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Wpfilemanager 6.8 RCEOS Command Execution, also known as Command Injection, is a severe vulnerability that allows attackers to execute arbitrary commands on the host operating system. Attackers...HighCWE-78WordPress Plugin Yolink Search 1.1.4 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Plugin Zotpress 4.4 SQLISQL injection is a type of attack where malicious SQL queries are inserted into input data, allowing attackers to manipulate the database. Successful exploitation can...HighCWE-89WordPress Theme Akal XSSCross-Site Scripting (XSS) attacks occur when malicious scripts are injected into trusted websites, often through user inputs, and executed in the browsers of other users....HighCWE-79WordPress User EnumerationUser Enumeration occurs when web applications inadvertently reveal whether a username exists on the system, either due to misconfiguration or design decisions. Attackers exploit this...MediumCWE-209X-Content-Type-Options Header is MissingThe absence of the X-Content-Type-Options response HTTP header may expose a website to MIME sniffing attacks. MIME sniffing, performed by browsers when the MIME type...InformationalCWE-16X-Frame-Options Header is MissingThe absence of the X-Frame-Options HTTP response header leaves a website vulnerable to click-jacking attacks. Without this header, attackers can embed the site’s content into...LowCWE-16X-Powered-By Header FoundThe presence of the X-Powered-By header reveals the technologies used by the web server, providing valuable information to attackers. This disclosure can aid attackers in...InformationalCWE-200X-XSS-Protection Header is SetThe HTTP X-XSS-Protection response header, originally designed for Internet Explorer, Chrome, and Safari, aimed to mitigate reflected cross-site scripting (XSS) attacks. However, its effectiveness has...InformationalCWE-16@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerabilityXML External entity injections could be possible, when running the provided XML Validator on arbitrary input.HighCWE-611lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerabilityThe latest version of lobe-chat(by now v0.141.2) has an unauthorized ssrf vulnerability. An attacker can construct malicious requests to cause SSRF without logging in, attack...HighCWE-918json-schema-ref-parser Prototype Pollution issueA Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to execute arbitrary code via the bundle(), parse(), resolve(),...HighCWE-1321vxe-table Cross-site Scripting vulnerabilityA vulnerability, which was classified as problematic, has been found in xuliangzhan vxe-table up to 3.7.9. This issue affects the function export of the file...LowCWE-79Malicious PDF can inject JavaScript into PDF ViewerThe PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then...HighCWE-94Trix Editor Arbitrary Code Execution VulnerabilityThe Trix editor, versions prior to 2.1.1, is vulnerable to arbitrary code execution when copying and pasting content from the web or other documents with...MediumCWE-79javascript-deobfuscator crafted payload can lead to code executionjavascript-deobfuscator removes common JavaScript obfuscation techniques. Crafted payloads targeting expression simplification can lead to code execution. This issue has been patched in version 1.1.0.HighCWE-94Conform contains a Prototype Pollution Vulnerability in `parseWith...` function - @conform-to/yupConform allows the parsing of nested objects in the form of object.property. Due to an improper implementation of this feature, an attacker can exploit it...HighCWE-1321Conform contains a Prototype Pollution Vulnerability in `parseWith...` function - @conform-to/zodConform allows the parsing of nested objects in the form of object.property. Due to an improper implementation of this feature, an attacker can exploit it...HighCWE-1321Conform contains a Prototype Pollution Vulnerability in `parseWith...` functionConform allows the parsing of nested objects in the form of object.property. Due to an improper implementation of this feature, an attacker can exploit it...HighCWE-1321ghtml Cross-Site Scripting (XSS) vulnerabilityIt is possible to introduce user-controlled JavaScript code and trigger a Cross-Site Scripting (XSS) vulnerability in some cases.HighCWE-80@strapi/plugin-upload has a Denial-of-Service via Improper Exception HandlingA Denial-of-Service was found in the media upload process causing the server to crash without restarting, affecting either development and production environments.MediumCWE-248SummerNote Cross Site Scripting VulnerabilitySummerNote 0.8.18 is vulnerable to Cross Site Scripting (XSS) via the Code View Function.MediumCWE-79Lobe Chat API Key LeakIf an attacker can successfully authenticate through SSO/Access Code, they can obtain the real backend API Key by modifying the base URL to their own...MediumCWE-918matrix-appservice-irc IRC command injection via admin commands containing newlinesIt is possible to craft a command with newlines which would not be properly parsed. This would mean you could pass a string of commands...MediumCWE-20datatables.net vulnerable to Prototype Pollution due to incomplete fixAll versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.HighCWE-1321Prototype Pollution in AjvAn issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution...MediumCWE-915Axios Cross-Site Request Forgery VulnerabilityAn issue discovered in Axios 0.8.1 through 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for...MediumCWE-352Cross site scripting in datatables.netThis affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped....MediumCWE-79Prototype Pollution in asyncA vulnerability exists in Async through 3.2.1 for 3.x and through 2.6.3 for 2.x (fixed in 3.2.2 and 2.6.4), which could let a malicious user...HighCWE-1321Cross-site Scripting in ZenUMLMarkdown-based comments in the ZenUML diagram syntax are susceptible to Cross-site Scripting (XSS).MediumCWE-80@fastly/js-compute has a use-after-free in some host call implementationsThe implementation of the following functions were determined to include a use-after-free bug:MediumCWE-416glob-parent vulnerable to Regular Expression Denial of Service in enclosure regexThis affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.HighCWE-400protobufjs Prototype Pollution vulnerabilityprotobuf.js (aka protobufjs) 6.10.0 until 6.11.4 and 7.0.0 until 7.2.4 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used...HighCWE-1321adolph_dudu ratio-swiper was discovered to contain a prototype pollution via the function extendDefaultsadolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function extendDefaults. This vulnerability allows attackers to execute arbitrary code or cause a...MediumCWE-1321@akbr/update Prototype Pollutionakbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js.MediumCWE-1321akbr patch-into was discovered to contain a prototype pollution via the function patchIntoakbr patch-into version 1.0.1 was discovered to contain a prototype pollution via the function patchInto. This vulnerability allows attackers to execute arbitrary code or cause...HighCWE-1321s3-url-parser vulnerable to Denial of Service via regexes components3-url-parser 1.0.3 is vulnerable to denial of service via the regexes component.HighCWE-400Blackprint @blackprint/engine Prototype Pollution issueA Prototype Pollution issue in Blackprint @blackprint/engine 0.8.12 through 0.9.1 allows an attacker to execute arbitrary code via the _utils.setDeepProperty function of engine.min.js.HighCWE-94Uncontrolled resource consumption in bracesThe NPM package braces fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In lib/parse.js, if a malicious...HighCWE-400Malicious Matrix homeserver can leak truncated message content of messages it shouldn't have access toThe fix for GHSA-wm4w-7h2q-3pf7 / CVE-2024-32000 included in matrix-appservice-irc 2.0.0 relied on the Matrix homeserver-provided timestamp to determine whether a user has access to the...MediumCWE-755jsonic was discovered to contain a prototype pollution via the function empty.rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a...HighCWE-94Jan path traversal vulnerability - @janhq/coreAn arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file. @janhq/core has...HighCWE-434EverShop vulnerable to improper authorization in GraphQL endpointsLack of authentication in NPM’s package @evershop/evershop before version 1.0.0-rc.9, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.HighCWE-287@cat5th/key-serializer Prototype Pollution vulnerabilityharvey-woo cat5th/key-serializer v0.2.5 was discovered to contain a prototype pollution via the function “query”. This vulnerability allows attackers to execute arbitrary code or cause a...MediumCWE-1321Regular Expression Denial of Service in msVersions of ms prior to 0.7.1 are affected by a regular expression denial of service vulnerability when extremely long version strings are parsed.HighCWE-400(ReDoS) Regular Expression Denial of Service in tf2-item-formatVersions of tf2-item-format since at least 4.2.6 are vulnerable to a Regular Expression Denial of Service (ReDoS) attack when parsing crafted user input.HighCWE-624VvvebJs Arbitrary File Upload vulnerabilityArbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter...MediumCWE-434ejs lacks certain pollution protectionThe ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.MediumCWE-693Badger Database Prototype PollutionA Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-database.esm.HighCWE-94obx Prototype Pollutionalmela obx before v.0.0.4 has a Prototype Pollution issue which allows arbitrary code execution via the obx/build/index.js:656), reduce (@almela/obx/build/index.js:470), Object.set (obx/build/index.js:269) component.HighCWE-1321@thi.ng/paths Prototype Pollution vulnerabilityAn issue in @thi.ng/paths v.5.1.62 and before allows a remote attacker to execute arbitrary code via the mutIn and mutInManyUnsafe components.HighCWE-1321TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp optionA cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content extraction code. When using the noneditable_regexp option, specially crafted HTML attributes containing malicious code were...MediumCWE-79TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elementsA cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed when...MediumCWE-79Plate media plugins has a XSS in media embed element when using custom URL parsersEditors that use MediaEmbedElement and pass custom urlParsers to the useMediaState hook may be vulnerable to XSS if a custom parser allows javascript:, data: or...HighCWE-79jrburke requirejs vulnerable to prototype pollutionjrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a...HighCWE-1321XSS vulnerability that affects bootstrap - bootstrapIn Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.MediumCWE-79XSS vulnerability that affects bootstrapIn Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.MediumCWE-79Bootstrap Cross-site Scripting vulnerability - bootstrap - GHSA-4p24-vmcr-4gqjIn Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different...MediumCWE-79Bootstrap Cross-site Scripting vulnerabilityIn Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different...MediumCWE-79bootstrap Cross-site Scripting vulnerability - bootstrap-sass - GHSA-ph58-4vrj-w6hrIn Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.MediumCWE-79bootstrap Cross-site Scripting vulnerability - bootstrapIn Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.MediumCWE-79Bootstrap vulnerable to Cross-Site Scripting (XSS)In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute.MediumCWE-79Editor.js vulnerable to Code InjectionEditor.js is a block-style editor with clean JSON output. Versions prior to 2.26.0 are vulnerable to Code Injection via pasted input. The processHTML method passes...MediumCWE-94Scrypted Cross-site Scripting vulnerabilityScrypted is a home video integration and automation platform. In versions 0.55.0 and prior (corresponding to @scrypted/core 0.1.142 and prior), a reflected cross-site scripting vulnerability...MediumCWE-79Nuxt Devtools has a Path Traversal: '../filedirNuxt Devtools is missing authentication on the getTextAssetContent RPC function which is vulnerable to path traversal. Combined with a lack of Origin checks on the...HighCWE-24Nuxt Icon affected by a Server-Side Request Forgery (SSRF)nuxt/icon provides an API to allow client side icon lookup. This endpoint is at /api/_nuxt_icon/[name].HighCWE-918@75lb/deep-merge Prototype Pollution vulnerabilityPrototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via merge...HighCWE-1321robinweser fast-loops vulnerable to prototype pollutionrobinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a...HighCWE-1321Cross-site Scripting in quillA vulnerability in the HTML editor of Slab Quill allows an attacker to execute arbitrary JavaScript by storing an XSS payload (a crafted onloadstart attribute...MediumCWE-79Server-Side Request Forgery in axiosaxios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.HighCWE-918Jan path traversal vulnerability - @janhq/core - GHSA-5jqc-qj57-4hrcJan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.HighCWE-31Trix has a cross-site Scripting vulnerability on copy & pasteThe Trix editor, versions prior to 2.1.4, is vulnerable to XSS when pasting malicious code. This vulnerability is a bypass of the fix put in...MediumCWE-79Jan path traversal vulnerabilityAn arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.HighCWE-94gettext.js has a Cross-site Scripting injectionPossible vulnerability to XSS injection if .po dictionary definition files is corruptedHighCWE-79Vulnerable IIS VersionThe Internet Information Services (IIS) version used is outdated and has security flaws. Vulnerabilities in older versions could be exploited by attackers to compromise the...MediumReact Native Document Picker Directory Traversal vulnerabilityDirectory Traversal vulnerability in React Native Document Picker before 8.2.2 and 9.x before 9.1.1 allows a local attacker to execute arbitrary code via a crafted...HighCWE-26MiguelCastillo @bit/loader Prototype Pollution issueA Prototype Pollution issue in MiguelCastillo @bit/loader v.10.0.3 allows an attacker to execute arbitrary code via the M function e argument in index.js.HighCWE-1321matrix-js-sdk will freeze when a user sets a room with itself as a its predecessorA malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk’s getRoomUpgradeHistory function will infinitely recurse in...MediumCWE-674squirrelly Code Injection vulnerabilitysquirrellyjs squirrelly v9.0.0 was discovered to contain a code injection vulnerability via the component options.varName. The issue was fixed in version 9.1.0.HighCWE-94ag-grid packages vulnerable to Prototype Pollution - @ag-grid-enterprise/chartsag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial...MediumCWE-1321ag-grid packages vulnerable to Prototype Pollution - ag-grid-enterpriseag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial...MediumCWE-1321ag-grid packages vulnerable to Prototype Pollutionag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial...MediumCWE-1321Cross-site scripting in Swagger-UIA Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based...HighCWE-79VvvebJs Reflected Cross-Site Scripting (XSS) vulnerabilityA reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.5 allows remote attackers to execute arbitrary code and obtain sensitive information via the action...MediumCWE-79Svelte has a potential mXSS vulnerability due to improper HTML escapingA potential XSS vulnerability exists in Svelte for versions prior to 4.2.19.MediumCWE-79Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSSWe discovered a DOM Clobbering vulnerability in Webpack’s AutoPublicPathRuntimeModule. The DOM Clobbering gadget in the module can lead to cross-site scripting (XSS) in web pages...MediumCWE-79ReDoS in urlregexA vulnerability was found in nescalante urlregex up to 0.5.0 and classified as problematic. This issue affects some unknown processing of the file index.js of...MediumCWE-1333Prototype pollution in ag-grid-community via the _.mergeDeep function - ag-grid-enterpriseag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execute arbitrary code or...HighCWE-1321Prototype pollution in ag-grid-community via the _.mergeDeep functionag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execute arbitrary code or...HighCWE-1321Zod denial of service vulnerabilityZod version 3.22.2 allows an attacker to perform a denial of service while validating emails.MediumCWE-1333Unreferenced Login Page FoundUnreferenced Login Page Found refers to the discovery of login pages within a web application that are not directly linked or referenced within the application...MediumCWE-656WordPress Login Page FoundWordPress wp-login.php serves as the primary login page for both users and administrators. Attackers commonly exploit this page through password guessing and brute force attacks...Mediumdset Prototype Pollution vulnerabilityVersions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the...HighCWE-1321DOM clobbering could escalate to Cross-site Scripting (XSS) - @pagefind/default-uiPagefind initializes its dynamic JavaScript and WebAssembly files relative to the location of the first script you load. This information is gathered by looking up...MediumCWE-79DOM clobbering could escalate to Cross-site Scripting (XSS) - pagefindPagefind initializes its dynamic JavaScript and WebAssembly files relative to the location of the first script you load. This information is gathered by looking up...MediumCWE-79DOM clobbering could escalate to Cross-site Scripting (XSS)Pagefind initializes its dynamic JavaScript and WebAssembly files relative to the location of the first script you load. This information is gathered by looking up...MediumCWE-79DOM Clobbering Gadget found in Rspack's AutoPublicPathRuntimeModule that leads to XSSHi, Rspack|Webpack developer team!MediumCWE-79Plate allows arbitrary DOM attributes in element.attributes and leaf.attributesOne longstanding feature of Plate is the ability to add custom DOM attributes to any element or leaf using the attributes property. These attributes are...HighCWE-79json-logic-js Command Injection vulnerabilityA vulnerability, which was classified as critical, has been found in json-logic-js 2.0.0. Affected by this issue is some unknown functionality of the file logic.js....HighCWE-77PHP CGI Argument Injection RCEIn PHP, when configured as a CGI script (php-cgi), improper handling of certain query strings can allow remote attackers to execute arbitrary code. Specifically, query...HighCWE-78FUXA vulnerable to Local File InclusionFUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.logHighCWE-98StimulusReflex arbitrary method callMore methods than expected can be called on reflex instances. Being able to call some of them has security implications.HighCWE-470Denial of service in rocket chat message parserRocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash...MediumCWE-400Layui has DOM Clobbering gadgets that leads to Cross-site ScriptingA DOM Clobbering vulnerability has been discovered in layui that can lead to Cross-site Scripting (XSS) on web pages where attacker-controlled HTML elements (e.g., img...MediumCWE-79DOM Clobbering Gadget found in rollup bundled scripts that leads to XSSWe discovered a DOM Clobbering vulnerability in rollup when bundling scripts that use import.meta.url or with plugins that emit and reference asset files from code...HighCWE-79lobe-chat implemented an insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)SSRF protection implemented in https://github.com/lobehub/lobe-chat/blob/main/src/app/api/proxy/route.ts does not consider redirect and could be bypassed when attacker provides external malicious url which redirects to internal resources like...MediumCWE-918Flowise and Flowise Chat Embed vulnerable to Stored Cross-site ScriptingFlowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.MediumCWE-79uPlot Prototype Pollution vulnerabilityVersions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to...HighCWE-1321Stored XSS in Jupyter nbdime - nbdimeImproper handling of user controlled input caused a stored cross-site scripting (XSS) vulnerability. All previous versions of nbdime are affected.MediumCWE-79Stored XSS in Jupyter nbdimeImproper handling of user controlled input caused a stored cross-site scripting (XSS) vulnerability. All previous versions of nbdime are affected.MediumCWE-79Heap-based Buffer Overflow in sqlite-vecsqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS)...HighCWE-787Sentry SDK Prototype Pollution gadget in JavaScript SDKsIn case a Prototype Pollution vulnerability is present in a user’s application or bundled libraries, the Sentry SDK could potentially serve as a gadget to...MediumCWE-913@saltcorn/plugins-loader unsanitized plugin name leads to a remote code execution (RCE) vulnerability when creating plugWhen creating a new plugin using the git source, the user-controlled value req.body.name is used to build the plugin directory where the location will be...HighCWE-78@saltcorn/server Remote Code Execution (RCE) / SQL injection via prototype pollution by manipulating `lang` and `defstThe endpoint /site-structure/localizer/save-string/:lang/:defstring accepts two parameter values: lang and defstring. These values are used in an unsafe way to set the keys and value of...HighCWE-1321@saltcorn/server arbitrary file and directory listing when accessing build mobile app resultsA user with admin permission can read arbitrary file and directory names on the filesystem by calling the admin/build-mobile-app/result?build_dir_name= endpoint. The build_dir_name parameter is not...MediumCWE-548@saltcorn/server arbitrary file zip read and download when downloading auto backupsA user with admin permission can read and download arbitrary zip files when downloading auto backups. The file name used to identify the zip file...MediumCWE-22Strapi Server-Side Request Forgery (SSRF)Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. This vulnerability allows attackers to scan for open ports or...HighCWE-918Saltcorn Server Stored Cross-Site Scripting (XSS) in event logs pageEvent log data is not properly sanitized leading to stored Cross-Site Scripting (XSS) vulnerability.MediumCWE-79Saltcorn Server allows logged-in users to delete arbitrary files because of a path traversal vulnerabilityA logged-in user with any role can delete arbitrary files on the filesystem by calling the sync/clean_sync_dir endpoint. The dir_name POST parameter is not validated/sanitized...HighCWE-22ReLaXed Cross-site Scripting vulnerabilityA vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown function of the component Pug to PDF...LowCWE-79Cross-Site Scripting in jqueryVersions of jquery prior to 1.9.0 are vulnerable to Cross-Site Scripting. The load method fails to recognize and remove <script> HTML tags that contain a...MediumCWE-79fast-xml-parser vulnerable to ReDOS at currency parsingA ReDOS that exists on currency.js was discovered by Gauss Security Labs R&D team.HighCWE-400angular-base64-upload vulnerable to unauthenticated remote code executionangular-base64-upload versions prior to v0.1.21 are vulnerable to unauthenticated remote code execution via the angular-base64-upload/demo/server.php endpoint. Exploitation of this vulnerability involves uploading arbitrary file content...HighCWE-434Cross-site scripting (XSS) in the clipboard package - ckeditor5During a recent internal audit, we identified a Cross-Site Scripting (XSS) vulnerability in the CKEditor 5 clipboard package.MediumCWE-79Cross-site scripting (XSS) in the clipboard packageDuring a recent internal audit, we identified a Cross-Site Scripting (XSS) vulnerability in the CKEditor 5 clipboard package.MediumCWE-79Cross site scripting in markdown-to-jsxVersions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can...MediumCWE-79Matrix JavaScript SDK's key history sharing could share keys to malicious devicesIn matrix-js-sdk versions 9.11.0 through 34.7.0, the method MatrixClient.sendSharedHistoryKeys is vulnerable to interception by malicious homeservers. The method implements functionality proposed in MSC3061 and can...HighCWE-287Signature Malleabillity in ellipticThe Elliptic package before version 6.5.3 for Node.js allows ECDSA signature malleability via variations in encoding, leading ‘\0’ bytes, or integer overflows. This could conceivably...HighCWE-190Slim Select has potential Cross-site Scripting issueSlim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:createOption(), the text variable from the user-provided Options object is...MediumCWE-79secp256k1-node allows private key extraction over ECDHIn elliptic-based version, loadUncompressedPublicKey has a check that the public key is on the curve: https://github.com/cryptocoinjs/secp256k1-node/blob/6d3474b81d073cc9c8cc8cfadb580c84f8df5248/lib/elliptic.js#L37-L39HighCWE-354Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary sectionThis can be leveraged to gain access to higher-privilege endpoints, e.g. if you get a user with admin privileges to run the code, you can...MediumCWE-80Prototype pollution vulnerability found in Mermaid's bundled version of DOMPurifyThe following bundled files within the Mermaid NPM package contain a bundled version of DOMPurify that is vulnerable to https://github.com/cure53/DOMPurify/security/advisories/GHSA-mmhx-hmjr-r674, potentially resulting in an XSS...HighCWE-1395ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML functionThe ReDoS can be exploited through the parseHTML function in the html-parser.ts file. This flaw allows attackers to slow down the application by providing specially...LowCWE-1333Knwl.js Regular Expression Denial of Service vulnerabilityKnwl.js is a Javascript library that parses through text for dates, times, phone numbers, emails, places, and more. Versions 1.0.2 and prior contain one or...MediumCWE-1333Generation of Error Message Containing Sensitive Information in zsaAll users are impacted. The zsa application transfers the parse error stack from the server to the client in production build mode. This can potentially...MediumCWE-209@langchain/community SQL Injection vulnerabilityA vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection.LowCWE-89Langchain Path Traversal vulnerabilityA path traversal vulnerability exists in the getFullPath method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite...MediumCWE-29Glossarizer Cross-site Scripting vulnerabilityGlossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these...MediumCWE-79lilconfig Code Injection vulnerabilityVersions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the...HighCWE-94XSS in jQuery as used in Drupal, Backdrop CMS, and other productsjQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized...MediumCWE-79@workos-inc/authkit-nextjs refresh tokens are logged when the debug flag is enabledRefresh tokens are logged to the console when the disabled by default debug flag, is enabled.LowCWE-532happy-dom allows for server side code to be executed by a <script> tagConsumers of the NPM package happy-domHighCWE-79Regular expression denial of service in jquery-validation - jquery-validationAn exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input...LowCWE-1333CommonRegexJS Regular Expression Denial of Service vulnerabilityCommonRegexJS is a CommonRegex port for JavaScript. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service...MediumCWE-1333Foundation Regular Expression Denial of Service vulnerabilityFoundation is a front-end framework. Versions 6.3.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS)....MediumCWE-1333insane vulnerable to Regular Expression Denial of Serviceinsane is a whitelist-oriented HTML sanitizer. Versions 2.6.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service...MediumCWE-1333JSZip contains Path Traversal via loadAsyncloadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.MediumCWE-22Insufficient validation when decoding a Socket.IO packetA specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process.MediumCWE-754EverShop at risk to unauthorized access via weak HMAC secretAn issue was discovered in NPM’s package @evershop/evershop before version 1.0.0-rc.9. The HMAC secret used for generating tokens is hardcoded as “secret”.HighCWE-798socket.io has an unhandled 'error' eventA specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process.MediumCWE-754rejetto HFS vulnerable to OS Command Execution by remote authenticated usersrejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have...HighCWE-78webcrack has an Arbitrary File Write Vulnerability on Windows when Parsing and Saving a Malicious BundleAn arbitrary file write vulnerability exists in the webcrack module when processing specifically crafted malicious code on Windows systems. This vulnerability is triggered when using...MediumCWE-22CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeoverThe issue impacts only editor instances with enabled version notifications.MediumCWE-79@blakeembrey/template vulnerable to code injection when attacker controls template inputIt is possible to inject and run code within the template if the attacker has access to write the template name.MediumCWE-94node-gettext vulnerable to Prototype PollutionAll versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.HighCWE-1321Firebase JavaScript SDK allows attackers to manipulate the "_authTokenSyncURL" to point to their own serverFirebase JavaScript SDK utilizes a “FIREBASE_DEFAULTS” cookie to store configuration data, including an “_authTokenSyncURL” field used for session synchronization.MediumCWE-79@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypassBy combining two vulnerabilities (an Open Redirect and session token sent as URL query parameter) in Strapi framework is its possible of an unauthenticated attacker...HighCWE-601Open Chinese Convert subject to Denial of Service via Out-of-bounds ReadOpen Chinese Convert (OpenCC) 1.0.5 allows attackers to cause a denial of service (segmentation fault) because BinaryDict::NewFromFile in BinaryDict.cpp may have out-of-bounds keyOffset and valueOffset...MediumCWE-125Cross-site scripting in bootstrap-selectbootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in...MediumCWE-79@sveltejs/kit has unescaped error message included on error pageThe static error.html template for errors contains placeholders that are replaced without escaping the content first.LowCWE-79Agnai vulnerable to Remote Code Execution via JS Upload using Directory TraversalA vulnerability has been discovered in Agnai that permits attackers to upload arbitrary files to attacker-chosen locations on the server, including JavaScript, enabling the execution...HighCWE-434Agnai File Disclosure Vulnerability: JSON via Path Traversalhttps://cwe.mitre.org/data/definitions/35.htmlLowCWE-35Agnai vulnerable to Relative Path Traversal in Image UploadA vulnerability has been discovered in Agnai that permits attackers to upload image files at attacker-chosen location on the server. This issue can lead to...LowCWE-35Nunjucks autoescape bypass leads to cross site scriptingIn Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two...MediumCWE-79@lobehub/chat Server Side Request Forgery vulnerabilitylobe-chat before 1.19.13 has an unauthorized ssrf vulnerability. An attacker can construct malicious requests to cause SSRF without logging in, attack intranet services, and leak...HighCWE-918vue-i18n has cross-site scripting vulnerability with prototype pollution - @intlify/core-baseXSSMediumCWE-79vue-i18n has cross-site scripting vulnerability with prototype pollution - @intlify/coreXSSMediumCWE-79vue-i18n has cross-site scripting vulnerability with prototype pollution - @intlify/vue-i18n-coreXSSMediumCWE-79vue-i18n has cross-site scripting vulnerability with prototype pollution - vue-i18nXSSMediumCWE-79vue-i18n has cross-site scripting vulnerability with prototype pollutionXSSMediumCWE-79@intlify/shared Prototype Pollution vulnerability - @intlify/sharedVulnerability type: Prototype PollutionMediumCWE-1321@intlify/shared Prototype Pollution vulnerability - @intlify/vue-i18n-coreVulnerability type: Prototype PollutionMediumCWE-1321@intlify/shared Prototype Pollution vulnerability - vue-i18nVulnerability type: Prototype PollutionMediumCWE-1321@intlify/shared Prototype Pollution vulnerabilityVulnerability type: Prototype PollutionMediumCWE-1321hull.js Code Injection VulnerabilityVersions of the library from 0.2.2 to 1.0.9 are vulnerable to the arbitrary code execution due to unsafe usage of new Function(...) in the module...HighCWE-94Firepad allows insecure document accessFirepad through 1.5.11 allows remote attackers, who have knowledge of a pad ID, to retrieve both the current text of a document and all content...LowCWE-200Prototype Pollution in the merge and clone helper methodsUsing merge and clone helper methods in the src/core/util.ts module will have prototype pollution. It will affect the popular data visualization library Apache ECharts, which...MediumCWE-915Trix editor subject to XSS vulnerabilities on copy & pasteThe Trix editor, in versions prior to 2.1.9 and 1.3.3, is vulnerable to XSS + mutation XSS attacks when pasting malicious code.MediumCWE-79Angular Expressions - Remote Code Execution when using localsAn attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the system.HighCWE-94Marp Core allows XSS by improper neutralization of HTML sanitizationMarp Core (@marp-team/marp-core) from v3.0.2 to v3.9.0 and v4.0.0, are vulnerable to cross-site scripting (XSS) due to improper neutralization of HTML sanitization.MediumCWE-79Trix allows Cross-site Scripting via `javascript:` url in a linkThe Trix editor, versions prior to 2.1.11, is vulnerable to XSS when pasting malicious code in the link field.MediumCWE-79dom-iterator code execution vulnerabilityVersions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function...MediumCWE-94json-schema is vulnerable to Prototype Pollutionjson-schema before version 0.4.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’).HighCWE-915XSS/HTML Injection Vulnerability in Umbraco Backoffice ComponentsAuthenticated users are able to exploit an XSS vulnerability when viewing certain localized backoffice components.MediumCWE-79@sveltejs/kit vulnerable to XSS on dev mode 404 page“Unsanitized input from the request URL flows into end, where it is used to render an HTML page returned to the user. This may result...LowCWE-79path-to-regexp outputs backtracking regular expressionsA bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.)....HighCWE-1333Cross Site Scripting vulnerability in store2Cross Site Scripting vulnerability in nbubna store v.2.14.2 and before allows a remote attacker to execute arbitrary code via the store.deep.js componentMediumCWE-79Opening a malicious website while running a Nuxt dev server could allow read-only access to code - @nuxt/vite-builderNuxt allows any websites to send any requests to the development server and read the response due to default CORS settings.MediumCWE-200Opening a malicious website while running a Nuxt dev server could allow read-only access to code - @nuxt/webpack-builderSource code may be stolen during dev when using webpack / rspack builder and you open a malicious web site.MediumCWE-749Opening a malicious website while running a Nuxt dev server could allow read-only access to codeSource code may be stolen during dev when using webpack / rspack builder and you open a malicious web site.MediumCWE-749Potential DoS when using ContextLines integration - @sentry/astroThe ContextLines integration uses readable streams to more efficiently use memory when reading files. The ContextLines integration is used to attach source context to outgoing...LowCWE-774Potential DoS when using ContextLines integration - @sentry/bunThe ContextLines integration uses readable streams to more efficiently use memory when reading files. The ContextLines integration is used to attach source context to outgoing...LowCWE-774Potential DoS when using ContextLines integration - @sentry/nextjsThe ContextLines integration uses readable streams to more efficiently use memory when reading files. The ContextLines integration is used to attach source context to outgoing...LowCWE-774Potential DoS when using ContextLines integration - @sentry/nuxtThe ContextLines integration uses readable streams to more efficiently use memory when reading files. The ContextLines integration is used to attach source context to outgoing...LowCWE-774Potential DoS when using ContextLines integration - @sentry/remixThe ContextLines integration uses readable streams to more efficiently use memory when reading files. The ContextLines integration is used to attach source context to outgoing...LowCWE-774Potential DoS when using ContextLines integration - @sentry/solidstartThe ContextLines integration uses readable streams to more efficiently use memory when reading files. The ContextLines integration is used to attach source context to outgoing...LowCWE-774Potential DoS when using ContextLines integrationThe ContextLines integration uses readable streams to more efficiently use memory when reading files. The ContextLines integration is used to attach source context to outgoing...LowCWE-774Remote Code Execution on click of <a> Link in markdown previewThere is a vulnerability in Joplin-desktop that leads to remote code execution (RCE) when a user clicks on an <a> link within untrusted notes. The...HighCWE-94files.photo.gallery command injectionA command injection vulnerability in the video thumbnail rendering component of files.photo.gallery v0.3.0 through 0.11.0 allows remote attackers to execute arbitrary code via a crafted...MediumCWE-77JSONPath Plus Remote Code Execution (RCE) VulnerabilityVersions of the package jsonpath-plus before 10.0.7 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code...HighCWE-94Parsed HTML anchor links in Markdown provided to parseMarkdown can result in XSS in @nuxtjs/mdcAn unsafe parsing logic of the URL from markdown can lead to arbitrary JavaScript code due to a bypass to the existing guards around the...HighCWE-79@ndhoule/defaults prototype pollutionA prototype pollution in the lib.deep function of @ndhoule/defaults v2.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.HighCWE-1321vxe-table prototype pollutionA prototype pollution in the lib.install function of vxe-table v4.8.10 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.HighCWE-1321esbuild enables any website to send any requests to the development server and read the responseesbuild allows any websites to send any request to the development server and read the response due to default CORS settings.MediumCWE-346Authentication bypass in @sap/approuterThe SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code, an attacker can steal the session...HighCWE-601Prototype Pollution in handlebars - handlebarsThe package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.HighCWE-1321Prototype Pollution in handlebarsVersions of handlebars prior to 3.0.8 or 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Objects’ __proto__ and...HighCWE-74dot-prop Prototype Pollution vulnerabilityPrototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language...HighCWE-471axios Inefficient Regular Expression Complexity vulnerabilityaxios before v0.21.2 is vulnerable to Inefficient Regular Expression Complexity.HighCWE-400Regular Expression Denial of Service in jsoneditorJSON Editor is a web-based tool to view, edit, format, and validate JSON. It has various modes such as a tree editor, a code editor,...MediumCWE-697Potential memory exposure in dns-packetThis affects the package dns-packet before versions 1.3.2 and 5.2.2. It creates buffers with allocUnsafe and does not always fill them before forming network packets....HighCWE-908Uncontrolled Resource Consumption in ansi-htmlThis affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long...HighCWE-400Denial of service in css-whatThe css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input....HighCWE-400Deserialization of Untrusted Data in bsonAll versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object’s _bsontype, leading...HighCWE-502parse-duration has a Regex Denial of Service that results in event loop delay and out of memoryThis report finds 2 availability issues due to the regex used in the parse-duration npm package: An event loop delay due to the CPU-bound operation...HighCWE-1333cookiejar Regular Expression Denial of Service via Cookie.parse functionVersions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Cookie.parse function and other aspects of the...MediumCWE-1333http-cache-semantics vulnerable to Regular Expression Denial of Servicehttp-cache semantics contains an Inefficient Regular Expression Complexity , leading to Denial of Service. This affects versions of the package http-cache-semantics before 4.1.1. The issue...HighCWE-1333engine.io Uncaught Exception vulnerabilityA specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process.MediumCWE-248word-wrap vulnerable to Regular Expression Denial of ServiceAll versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within...MediumCWE-1333browserify-sign upper bound check issue in `dsaVerify` leads to a signature forgery attackAn upper bound check issue in dsaVerify function allows an attacker to construct signatures that can be successfully verified by any public key, thus leading...HighCWE-347Vega allows Cross-site Scripting via the vlSelectionTuples function - vega-selectionsThe vlSelectionTuples function can be used to call JavaScript functions, leading to XSS.MediumCWE-79Vega allows Cross-site Scripting via the vlSelectionTuples functionThe vlSelectionTuples function can be used to call JavaScript functions, leading to XSS.MediumCWE-79@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic BacktrackA Regular Expression Denial of Service (ReDoS) vulnerability exists in the processing of HTTP request headers. By sending an authorization header containing an excessively long...MediumCWE-1333Insecure Direct Object Reference (IDOR)IDOR occurs when an application provides direct access to objects based on user input without proper authorization checks. This vulnerability allows attackers to manipulate object...HighCWE-639smartbanner.js rel noopener vulnerabilityNo description available.LowCWE-79Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerabilityThe vulnerability has been discovered in Code Snippet GeSHi plugin. All integrators that use GeSHi syntax highlighter on the backend side can be affected.MediumCWE-79@octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic BackFor the npm package @octokit/plugin-paginate-rest, when calling octokit.paginate.iterator(), a specially crafted octokit instance—particularly with a malicious link parameter in the headers section of the request—can...MediumCWE-1333JSONPath Plus allows Remote Code ExecutionVersions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code...HighCWE-94Unwanted access to the entire file system vulnerability due to a missing check in `staticFiles` HTTP handlerMissing check vulnerability in the static file handler allows any client to access the files in the server’s file systemMediumCWE-22Cross-site scripting (XSS) in the CKEditor 5 real-time collaboration packageDuring a recent internal audit, we identified a Cross-Site Scripting (XSS) vulnerability in the CKEditor 5 real-time collaboration package. This vulnerability can lead to unauthorized...MediumCWE-80@tanstack/form-core prototype pollutionA prototype pollution in the lib.mutateMergeDeep function of @tanstack/form-core v0.35.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.HighCWE-732@rpldy/uploader prototype pollutionA prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.HighCWE-1321Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)Private key can be extracted from ECDSA signature upon signing a malformed input (e.g. a string or a number), which could e.g. come from JSON...HighCWE-200tarteaucitron Cross-site Scripting (XSS)Versions of the package tarteaucitronjs before 1.17.0 are vulnerable to Cross-site Scripting (XSS) via the getElemWidth() and getElemHeight(). This is related to SNYK-JS-TARTEAUCITRONJS-8366541LowCWE-79Solid Lacks Escaping of HTML in JSX Fragments allows for Cross-Site Scripting (XSS)Inserts/JSX expressions inside illegal inlined JSX fragments lacked escaping, allowing user input to be rendered as HTML when put directly inside JSX fragments.HighCWE-79Matrix IRC Bridge allows IRC command injection to own puppeted userThe matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can...LowCWE-88ejson shell parser in MongoDB Compass maybe bypassedMongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass’ connection handling....HighCWE-94Cache variables with the operations when transforms exist on the root level even if variables change in the further requWhen you have transforms on the root level or single source with transforms, and the client sends the same query with different variables, the initial...MediumCWE-401mavo DOM Clobbering vulnerabilityA DOM Clobbering vulnerability in mavo v0.3.2 allows attackers to execute arbitrary code via supplying a crafted HTML element.MediumCWE-79seajs Cross-site Scripting vulnerabilityCross Site Scripting vulnerability in seajs v.2.2.3 allows a remote attacker to execute arbitrary code via the seajs packageLowCWE-79Manifest Uses a One-Way Hash without a SaltManifest employs a weak password hashing implementation that uses SHA3 without a salt. This exposes user passwords to a higher risk of being cracked if...MediumCWE-759Prototype pollution in json-pointer - json-pointerThis affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.MediumCWE-1321Vue I18n Allows Prototype Pollution in `handleFlatJson` - @intlify/core-baseVulnerability type:Prototype PollutionHighCWE-1321Vue I18n Allows Prototype Pollution in `handleFlatJson` - @intlify/coreVulnerability type:Prototype PollutionHighCWE-1321Vue I18n Allows Prototype Pollution in `handleFlatJson` - @intlify/message-resolverVulnerability type:Prototype PollutionHighCWE-1321Vue I18n Allows Prototype Pollution in `handleFlatJson` - @intlify/vue-i18n-coreVulnerability type:Prototype PollutionHighCWE-1321Vue I18n Allows Prototype Pollution in `handleFlatJson` - vue-i18nVulnerability type:Prototype PollutionHighCWE-1321Vue I18n Allows Prototype Pollution in `handleFlatJson`Vulnerability type:Prototype PollutionHighCWE-1321Froala Editor Cross-site Scripting vulnerabilityFroala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability.MediumCWE-79Froala WYSIWYG editor allows cross-site scripting (XSS)Inconsistent tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier.MediumCWE-79JS Html Sanitizer allows XSS when used with contentEditableXSS vulnerability when the sanitizer is used with a contentEditable element to set the elements innerHTML to a sanitized string produced by the package. If...MediumCWE-79canvg Prototype Pollution vulnerabilityAn issue in canvg prior to v.4.0.3 and v3.0.11 can lead to prototype pollution via the Constructor of the class StyleElement.HighCWE-1321jsPDF Bypass Regular Expression Denial of Service (ReDoS)User control of the first argument of the addImage method results in CPU utilization and denial of service.HighCWE-770@zag-js/core prototype pollutionA prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.HighCWE-400Open WebUI Uncontrolled Resource Consumption vulnerabilityIn version v0.3.32 of open-webui/open-webui, the application allows users to submit large payloads in the email and password fields during the sign-in process due to...HighCWE-400GetmeUK ContentTools Cross-Site Scripting (XSS)A vulnerability was found in GetmeUK ContentTools up to 1.6.16. It has been rated as problematic. Affected by this issue is some unknown functionality of...MediumCWE-79@mozilla/readability Denial of Service through RegexSpecially crafted titles may have caused a regular expression to excessively backtrack and cause a local denial of service.LowCWE-1333Directus's S3 assets become unavailable after a burst of HEAD requestsThere’s some tools that use Directus to sync content and assets.Some of those tools use HEAD method, like Shopify, to check the existence of files.Although,...MediumCWE-770Directus's S3 assets become unavailable after a burst of malformed transformationsWhen making many malformed transformation requests at once, at some point, all assets are being served as 403.MediumCWE-770Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace] - vegaUsers running Vega/Vega-lite JSON definitions could run unexpected JavaScript code when drawing graphs, unless the library is used with the vega-interpreter.MediumCWE-87Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace]Users running Vega/Vega-lite JSON definitions could run unexpected JavaScript code when drawing graphs, unless the library is used with the vega-interpreter.MediumCWE-87Jellyfin Web Cross-Site Scripting (XSS) via Collection NameIn Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to steal access tokens from the...MediumCWE-79Jellyfin Web Cross-Site Scripting (XSS) via Playlist NameIn Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the...MediumCWE-79depath and cool-path vulnerable to Prototype Pollution via `set()` Method - depathjanryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers...HighCWE-1321depath and cool-path vulnerable to Prototype Pollution via `set()` MethodjanryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers...HighCWE-1321Redoc Prototype Pollution via `Module.mergeObjects` ComponentA prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted...HighCWE-1321gifplayer XSS vulnerabilityXSS vulnerability. All versions under 0.3.7 are impactedMediumCWE-79Remix and React Router allow URL manipulation via Host / X-Forwarded-Host headersWe received a report about a vulnerability in Remix/React Router that affects all Remix 2 and React Router 7 consumers using the Express adapter.HighCWE-444Open WebUI Uncontrolled Resource Consumption vulnerability - open-webuiIn version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the api/v1/utils/code/format endpoint. If a malicious actor sends a...HighCWE-770MathLive's Lack of Escaping of HTML allows for XSSDespite normal text rendering as LaTeX expressions, preventing XSS, the library also provides users with commands which may modify HTML, such as the \htmlData command,...MediumCWE-79Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`The Tauri shell plugin exposes functionality to execute code and open programs on the system. The open endpoint of this plugin is designed to allow...HighCWE-20React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded ButtonAll versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in...LowCWE-79bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() FunctionVersions of the package bigint-buffer from 0.0.0 to 1.1.5 are vulnerable to Buffer Overflow in the toBigIntLE() function. Attackers can exploit this to crash the...HighCWE-120tarteaucitron.js allows UI manipulation via unrestricted CSS injectionA vulnerability was identified in tarteaucitron.js, where user-controlled inputs for element dimensions (width and height) were not properly validated.MediumCWE-1021tarteaucitron.js allows prototype pollution via custom text injectionA vulnerability was identified in tarteaucitron.js, where the addOrUpdate function, used for applying custom texts, did not properly validate input.MediumCWE-1321tarteaucitron.js allows url scheme injection via unfiltered inputsA vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site’s source code or a CMS plugin) to enter a...MediumCWE-79ts-asn1-der has Incorrect DER Encoding of Numbers Leading to Denial of Service and Incorrect Value RepresentationIncorrect number DER encoding can lead to denial on service for absolute values in the range 2**31 – 2**32 - 1. The arithmetic in the...MediumCWE-835node-opcua-alarm-condition prototype pollution vulnerabilityA prototype pollution in the function fieldsToJson of node-opcua-alarm-condition v2.134.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.HighCWE-1321Flowise Vulnerable to SQL Injection via `tableName` ParameterFlowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores.HighCWE-89Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter - vegaIn vega 5.30.0 and lower, vega-functions 5.15.0 and lower , it was possible to call JavaScript functions from the Vega expression language that were not...MediumCWE-79Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeterIn vega 5.30.0 and lower, vega-functions 5.15.0 and lower , it was possible to call JavaScript functions from the Vega expression language that were not...MediumCWE-79YUI Cross-site Scripting (XSS) vulnerability - yui - GHSA-x5hj-47vv-53p8Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.10.2, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x...MediumCWE-79YUI Cross-site Scripting (XSS) vulnerability - yuiCross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 3.2.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11,...MediumCWE-79YUI Cross-site Scripting (XSS) vulnerabilityCross-site scripting (XSS) vulnerability in flashuploader.swf in the Uploader component in Yahoo! YUI 3.5.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11,...MediumCWE-79Server-Side Request ForgeryServer-Side Request Forgery (SSRF) is a vulnerability where an attacker manipulates a server to make unintended requests to internal or external resources. SSRF can be...HighCWE-918Cross-site Scripting in jquery-uiCross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML...MediumCWE-79glob-parent 6.0.0 vulnerable to Regular Expression Denial of Serviceglob-parent 6.0.0 is vulnerable to Regular Expression Denial of Service (ReDoS). This issue is fixed in version 6.0.1.HighCWE-400cookie accepts cookie name, path, and domain with out of bounds charactersThe cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. For example, serialize("userName=<script>alert('XSS3')</script>; Max-Age=2592000; a", value)...LowCWE-74jquery-validation vulnerable to Cross-site ScriptingVersions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder...MediumCWE-79Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) VulnerabilityA Denial of Service (DoS) vulnerability exists in open-webui/open-webui version 0.3.21. This vulnerability affects multiple endpoints, including /ollama/models/upload, /audio/api/v1/transcriptions, and /rag/api/v1/doc. The application processes multipart...HighCWE-400@sveltejs/kit vulnerable to Cross-site Scripting via tracked search_paramsUnsanitized search param names cause XSS vulnerability. You are affected if you iterate over all entries of event.url.searchParams inside a server load function. Attackers can...MediumCWE-79Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups - @babel/helpersWhen using Babel to compile regular expression named capturing groups, Babel will generate a polyfill for the .replace method that has quadratic complexity on some...MediumCWE-1333Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups - @babel/runtimeWhen using Babel to compile regular expression named capturing groups, Babel will generate a polyfill for the .replace method that has quadratic complexity on some...MediumCWE-1333Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groupsWhen using Babel to compile regular expression named capturing groups, Babel will generate a polyfill for the .replace method that has quadratic complexity on some...MediumCWE-1333QMarkdown Cross-Site Scripting (XSS) vulnerabilityQMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set.MediumCWE-79Compromised xrpl.js versions 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2Versions 4.2.1, 4.2.2, 4.2.3, and 4.2.4 of xrpl.js were compromised and contained malicious code designed to exfiltrate private keys. If you are using one of...HighCWE-506tRPC 11 WebSocket DoS VulnerabilityAn unhandled error is thrown when validating invalid connectionParams which crashes a tRPC WebSocket server. This allows any unauthenticated user to crash a tRPC 11...HighCWE-460Pug allows JavaScript code execution if an application accepts untrusted inputPug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the compileClient, compileFileClient, or compileClientWithDependenciesTracked function. NOTE:...MediumCWE-94Prototype pollution in 101Prototype pollution vulnerability in ‘101’ versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to remote code execution....HighCWE-1321Homograph attack allows Unicode lookalike characters to bypass validation.Attackers can deceive users into sending funds to an unintended address.HighCWE-1007Information Disclosure via Flags override link - flagsAn information disclosure vulnerability affecting Flags SDK has been addressed. It impacted flags ≤3.2.0 and @vercel/flags ≤3.1.1 and in certain circumstances, allowed a bad actor...MediumCWE-200Information Disclosure via Flags override linkAn information disclosure vulnerability affecting Flags SDK has been addressed. It impacted flags ≤3.2.0 and @vercel/flags ≤3.1.1 and in certain circumstances, allowed a bad actor...MediumCWE-200Trix vulnerable to Cross-site Scripting on copy & pasteThe Trix editor, in versions prior to 2.1.15, is vulnerable to XSS attacks when pasting malicious code.LowCWE-79OpenPGP.js's message signature verification can be spoofedA maliciously modified message can be passed to either openpgp.verify or openpgp.decrypt, causing these functions to return a valid signature verification result while returning data...HighCWE-347css-what vulnerable to ReDoS due to use of insecure regular expressionThe package css-what before 2.1.3 is vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of insecure regular expression in the re_attr...HighCWE-400radashi Allows Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')This is a prototype pollution vulnerability. It impacts users of the set function within the Radashi library.MediumCWE-1321Marked allows Regular Expression Denial of Service (ReDoS) attacksMarked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used...MediumCWE-1333Formidable relies on hexoid to prevent guessing of filenames for untrusted executable contentFormidable (aka node-formidable) 2.x before 2.1.3 and 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is...LowCWE-338Remote code execution via the `pretty` option.If a remote attacker was able to control the pretty option of the pug compiler, e.g. if you spread a user provided object such as...MediumCWE-94Strapi allows Server-Side Request Forgery in Webhook functionIn Strapi latest version, at function Settings -> Webhooks, the application allows us to input a URL in order to create a Webook connection. However,...MediumCWE-918Resource exhaustion in engine.ioEngine.IO before 4.0.0 and 3.6.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.HighCWE-400path-to-regexp contains a ReDoSThe regular expression that is vulnerable to backtracking can be generated in versions before 0.1.12 of path-to-regexp, originally reported in CVE-2024-45296HighCWE-1333Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API EndpointAn unauthenticated information disclosure vulnerability exists in the PSU deployment of HAX CMS via the haxPsuUsage API endpoint. This allows any remote unauthenticated user to...MediumCWE-201Suspended Directus user can continue to use session token to access APISince the user status is not checked when verifying a session token a suspended user can use the token generated in session auth mode to...LowCWE-672Regular Expression Denial of Service in papaparseVersions of papaparse prior to 5.2.0 are vulnerable to Regular Expression Denial of Service (ReDos). The parse function contains a malformed regular expression that takes...HighCWE-185Passbolt Browser Extension leaks password informationAn issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results...MediumCWE-200OpenList (frontend) allows XSS Attacks in the built-in Markdown ViewerXSS via .py file containing script tag interpreted as HTMLMediumCWE-79pbkdf2 returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algosThis affects both: Unsupported algos (e.g. sha3-256 / sha3-512 / sha512-256) Supported but non-normalized algos (e.g. Sha256 / Sha512 / SHA1 / sha-1 / sha-256...HighCWE-20PrismJS DOM Clobbering vulnerabilityPrism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript...MediumCWE-94Stage.js DOM Clobbering vulnerabiltyStage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can...MediumCWE-94string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS)string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.LowCWE-1333tiny-secp256k1 vulnerable to private key extraction when signing a malicious JSON-stringifyable message in bundled envirPrivate key can be extracted on signing a malicious JSON-stringifiable object, when global Buffer is buffer packageHighCWE-522tiny-secp256k1 allows for verify() bypass when running in bundled environmentA malicious JSON-stringifyable message can be made passing on verify(), when global Buffer is buffer packageHighCWE-347react-native-keys insecurely stores encryption cipher and Base64 chunksreact-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers...HighCWE-312tarteaucitron.js vulnerable to DOM Clobbering via document.currentScriptA vulnerability was identified in tarteaucitron.js where document.currentScript was accessed without verifying that it referenced an actual <script> element. If an attacker injected an HTML...MediumCWE-138@clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/astroApplications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events.HighCWE-345@clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/backendApplications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events.HighCWE-345@clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/nextjsApplications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events.HighCWE-345@clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/nuxtApplications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events.HighCWE-345@clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/react-routerApplications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events.HighCWE-345@clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/remixApplications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events.HighCWE-345@clerk/backend Performs Insufficient Verification of Data AuthenticityApplications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events.HighCWE-345MCP Inspector proxy server lacks authentication between the Inspector client and proxyVersions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated...HighCWE-306Qwik's unhandled exception vulnerabilty can cause server crashes from malicious requestsPossibility to craft a request that will crash the Qwik Server in the default configuration.HighCWE-248docusaurus-plugin-content-gists vulnerability exposes GitHub Personal Access TokenNo description available.HighCWE-200@pdfme/common vulnerable to to XSS and Prototype Pollution through its expression evaluationThe expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading to XSS and prototype pollution attacks.MediumCWE-79chromedriver Downloads Resources over HTTPAffected versions of chromedriver insecurely download resources over HTTP.HighCWE-311Better Call routing bug can lead to Cache DeceptionUsing a CDN that caches (/**/*.png, /**/*.json, /**/*.css, etc…) requests, a cache deception can emerge. This could lead to unauthorized access to user sessions and...MediumCWE-525DiracX-Web is vulnerable to attack through an Open Redirect on its login pageAn attacker can forge a request to redirect an authenticated user to any arbitrary website.MediumCWE-601vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - @intlify/core-baseThe escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, this setting fails to prevent execution...MediumCWE-79vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - @intlify/coreThe escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, this setting fails to prevent execution...MediumCWE-79vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - @intlify/vue-i18n-coreThe escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, this setting fails to prevent execution...MediumCWE-79vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - vue-i18nThe escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, this setting fails to prevent execution...MediumCWE-79vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributesThe escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, this setting fails to prevent execution...MediumCWE-79Prototype pollution in min-dashThe set method is vulnerable to prototype pollution with specially crafted inputs.HighCWE-1321Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filteringA remote script-inclusion / stored XSS vulnerability in @nuxtjs/mdc lets a Markdown author inject a <base href="https://attacker.tld"> element.HighCWE-79jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text labelInitializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. If you call .checkboxradio(...MediumCWE-79Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege VulnerabilityAzure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability.MediumCWE-362pubnub Insufficient Entropy vulnerabilityVersions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the package...MediumCWE-331Bun has an Application-level Prototype Pollution vulnerability in the runtime native API for GloVersions of the package bun before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun’s...MediumCWE-1321Angular (deprecated package) Cross-site ScriptingAll versions of package angular are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of...MediumCWE-79billboard.js allows prototype pollution via the function generatebillboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a...HighCWE-1321Sensitive Data DisclosureSensitive data disclosure occurs when confidential information such as API tokens, access keys, secrets, or credentials are exposed in publicly accessible content. This can happen...MediumCWE-798webfinger.js Blind SSRF VulnerabilityThe lookup function takes a user address for checking accounts as a feature, however, as perthe ActivityPub spec (https://www.w3.org/TR/activitypub/#security-considerations), on thesecurity considerations section at B.3,...MediumCWE-918mcp-package-docs vulnerable to command injection in several toolsA command injection vulnerability exists in the mcp-package-docs MCP Server. The vulnerability is caused by the unsanitized use of input parameters within a call to...HighCWE-77IPX Allows Path Traversal via Prefix Matching BypassThe approach used to check whether a path is within allowed directories is vulnerable to path prefix bypass when the allowed directories do not end...MediumCWE-22js-toml Prototype Pollution VulnerabilityA prototype pollution vulnerability in js-toml allows a remote attacker to add or modify properties of the global Object.prototype by parsing a maliciously crafted TOML...HighCWE-1321The Thinbus Javascript Secure Remote Password (SRP) Client Generates Fewer Bits of Entropy Than IntendedA protocol compliance bug in thinbus-srp-npm versions prior to 2.0.1 causes the client to generate a fixed 252 bits of entropy instead of the intended...MediumCWE-331The AuthKit React Router Library rendered sensitive auth data in HTMLIn versions before 0.7.0, @workos-inc/authkit-react-router exposed sensitive authentication artifacts — specifically sealedSession and accessToken by returning them from the authkitLoader. This caused them to be...HighCWE-200content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCEA prototype pollution vulnerability exists in versions 0.5.0 and earlier, wherein if you provide a policy name called __proto__ you can override the Object prototype....HighCWE-1321HFS user adding a "web link" in HFS is vulnerable to "target=_blank" exploitWhen adding a “web link” to the HFS virtual filesystem, the frontend opens it with target="_blank" but without the rel="noopener noreferrer" attribute. This allows the...LowCWE-1022Prototype Pollution in lodash - lodashVersions of lodash before 4.17.11 are vulnerable to prototype pollution.HighCWE-400Prototype Pollution in lodashVersions of lodash before 4.17.5 are vulnerable to prototype pollution.MediumCWE-471Prototype Pollution in lodash - lodash - GHSA-jf85-cpcp-j695Versions of lodash before 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep allows a malicious user to modify the prototype of Object via {constructor:...HighCWE-20Prototype Pollution in lodash - lodash-amdVersions of lodash before 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep allows a malicious user to modify the prototype of Object via {constructor:...HighCWE-20Prototype Pollution in lodash - lodash.defaultsdeepVersions of lodash before 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep allows a malicious user to modify the prototype of Object via {constructor:...HighCWE-20Prototype Pollution in lodash - lodash-es - GHSA-jf85-cpcp-j695Versions of lodash before 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep allows a malicious user to modify the prototype of Object via {constructor:...HighCWE-20Prototype Pollution in lodash - lodash - GHSA-p6mc-m468-83gwVersions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions pick, set, setWith, update, updateWith, and zipObjectDeep allow a malicious user to...HighCWE-770Prototype Pollution in lodash - lodash-esVersions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions pick, set, setWith, update, updateWith, and zipObjectDeep allow a malicious user to...HighCWE-770Prototype Pollution in lodash - lodash.setVersions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions pick, set, setWith, update, updateWith, and zipObjectDeep allow a malicious user to...HighCWE-770Prototype Pollution in lodash - lodash.updateVersions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions pick, set, setWith, update, updateWith, and zipObjectDeep allow a malicious user to...HighCWE-770Prototype Pollution in lodash - lodash.updatewithVersions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions pick, set, setWith, update, updateWith, and zipObjectDeep allow a malicious user to...HighCWE-770Command Injection in lodash - lodash-eslodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.HighCWE-94Command Injection in lodash - lodash-templatelodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.HighCWE-94Command Injection in lodashlodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.HighCWE-94sweetalert2 contains potentially undesirable behaviorsweetalert2 versions from 11.6.14 to before 11.22.4 have potentially undesirable behavior. The package outputs audio and/or video messages that do not pertain to the functionality...LowCWE-440Prototype Pollution in jquery-deparamImproperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’) in jquery-deparam allows a malicious user to inject properties into Object.prototype.HighCWE-1321Mermaid does not properly sanitize architecture diagram iconText leading to XSSIn the default configuration of mermaid 11.9.0, user supplied input for architecture diagram icons is passed to the d3 html() method, creating a sink for...MediumCWE-79x402 SDK vulnerable in outdated versions in resource servers for builders - x402There is a security vulnerability in outdated versions of the x402 SDK. This does not directly affect users’ keys, smart contracts, or funds.Highx402 SDK vulnerable in outdated versions in resource servers for buildersThere is a security vulnerability in outdated versions of the x402 SDK. This does not directly affect users’ keys, smart contracts, or funds.Highsweetalert2 v10.16.10 and above contains hidden functionalitysweetalert2 versions 10.16.10 and up until 11.0.0 are vulnerable to hidden functionality that was introduced by the maintainer. The package outputs audio and/or video messages...LowCWE-912sweetalert2 v11.4.9 and above contains hidden functionalitysweetalert2 versions 11.4.9 and above are vulnerable to hidden functionality that was introduced by the maintainer. The package outputs audio and/or video messages that do...LowCWE-912Liferay Portal Reflected XSS in CKeditor 4.21.0 endpointA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.4, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13,...MediumCWE-79devalue prototype pollution vulnerabilityA string passed to devalue.parse could represent an object with a __proto__ property, which would assign a prototype to an object while allowing properties to...HighCWE-1321Payload does not invalidate JWTs after log out - payloadPayload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token...MediumCWE-613Payload does not invalidate JWTs after log out - @payloadcms/nextPayload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token...MediumCWE-613Payload does not invalidate JWTs after log outPayload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token...MediumCWE-613Payload's SQLite adapter Session Fixation vulnerability - payloadA Session Fixation vulnerability existed in Payload’s SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save...MediumCWE-384Payload's SQLite adapter Session Fixation vulnerability - @payloadcms/nextA Session Fixation vulnerability existed in Payload’s SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save...MediumCWE-384Payload's SQLite adapter Session Fixation vulnerabilityA Session Fixation vulnerability existed in Payload’s SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save...MediumCWE-384Spoofing attack in swagger-uiSwagger UI before 4.1.3 could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could...MediumCWE-922Denial of Service in jqueryAffected versions of jquery use a lowercasing logic on attribute names. When given a boolean attribute with a name that contains uppercase characters, jquery enters...HighCWE-674parse-uri Regular expression Denial of Service (ReDoS) - parse-uriAn issue in parse-uri v1.0.9 allows attackers to cause a Regular expression Denial of Service (ReDoS) via a crafted URL. ## PoCMediumCWE-185parse-uri Regular expression Denial of Service (ReDoS)An issue in parse-uri v1.0.9 allows attackers to cause a Regular expression Denial of Service (ReDoS) via a crafted URL. ## PoCMediumCWE-185domain-suffix RegEx Denial of ServiceRegEx Denial of Service in domain-suffix 1.0.8 allows attackers to crash the application via crafted input to the parse function.HighCWE-1333useragent Regular Expression Denial of Service vulnerabilityUseragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular expressions that are vulnerable to...MediumCWE-1333Mermaid improperly sanitizes sequence diagram labels leading to XSSIn the default configuration of mermaid 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of element size, causing XSS....MediumCWE-79CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package - ckeditor5A Cross-Site Scripting (XSS) vulnerability has been discovered in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading...LowCWE-79CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard packageA Cross-Site Scripting (XSS) vulnerability has been discovered in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading...LowCWE-79Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapterWhen using Astro’s Cloudflare adapter (@astrojs/cloudflare) configured with output: 'server' while using the default imageService: 'compile', the generated image optimization endpoint doesn’t check the URLs...HighCWE-918Webrecorder packages are vulnerable to XSS through 404 error handling logic - replaywebpageA Reflected Cross-Site Scripting (XSS) vulnerability exists in the 404 error handling logic of wabac.js v2.23.10 and below. The parameter requestURL (derived from the original...HighCWE-79Webrecorder packages are vulnerable to XSS through 404 error handling logic - @webrecorder/wabacA Reflected Cross-Site Scripting (XSS) vulnerability exists in the 404 error handling logic of wabac.js v2.23.10 and below. The parameter requestURL (derived from the original...HighCWE-79Webrecorder packages are vulnerable to XSS through 404 error handling logicA Reflected Cross-Site Scripting (XSS) vulnerability exists in the 404 error handling logic of wabac.js v2.23.10 and below. The parameter requestURL (derived from the original...HighCWE-79KaTeX \htmlData does not validate attribute namesKaTeX users who render untrusted mathematical expressions with renderToString could encounter malicious input using \htmlData that runs arbitrary JavaScript, or generate invalid HTML.MediumCWE-79jsPDF Denial of Service (DoS)User control of the first argument of the addImage method results in CPU utilization and denial of service.HighCWE-835DuckDB NPM packages 1.3.3 and 1.29.2 briefly compromised with malwareThe DuckDB distribution for Node.js on npm was compromised with malware (along with several other packages). An attacker published new versions of four of duckdb’s...HighCWE-506Angular SSR: Global Platform Injector Race Condition Leads to Cross-Request Data LeakageAngular uses a DI container (the “platform injector”) to hold request-specific state during server-side rendering. For historical reasons, the container was stored as a JavaScript...HighCWE-362Prebid.js NPM package briefly compromisedNPM users of prebid 10.9.2. The malicious code attempts to redirect crypto transactions on the site to the attackers’ wallet.HighCWE-506Prebid-universal-creative latest on npm briefly compromisedNpm users of PUC 1.17.3 or PUC latest were briefly affected by crypto-related malware detailed in the blog post below. This includes the extremely popular...HighCWE-506sanitize-html is vulnerable to XSS through incomprehensive sanitizationsanitize-html prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The sanitizeHtml() function in index.js does not sanitize content when using the custom transformTags...MediumCWE-79MetaMask SDK indirectly exposed via malicious [email protected] dependency - @metamask/sdk-reactThis advisory only applies to developers who use MetaMask SDK in the browser and who, on Sept 8th 2025 between 13:00–15:30 UTC, performed one of...MediumCWE-506MetaMask SDK indirectly exposed via malicious [email protected] dependency - @metamask/sdkThis advisory only applies to developers who use MetaMask SDK in the browser and who, on Sept 8th 2025 between 13:00–15:30 UTC, performed one of...MediumCWE-506MetaMask SDK indirectly exposed via malicious [email protected] dependencyThis advisory only applies to developers who use MetaMask SDK in the browser and who, on Sept 8th 2025 between 13:00–15:30 UTC, performed one of...MediumCWE-506[email protected] contains malware after npm account takeoverOn 8 September 2025, the npm publishing account for color-string was taken over after a phishing attack. Version 2.1.1 was published, functionally identical to the...HighCWE-506[email protected] contains malware after npm account takeoverOn 8 September 2025, the npm publishing account for color was taken over after a phishing attack. Version 5.0.1 was published, functionally identical to the...HighCWE-506[email protected] contains malware after npm account takeoverOn 8 September 2025, the npm publishing account for debug was taken over after a phishing attack. Version 4.4.2 was published, functionally identical to the...HighCWE-506Bootstrap Vulnerable to Cross-Site Scripting in its Popover and Tooltip ComponentsImproper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in Bootstrap allows Cross-Site Scripting (XSS). This issue affects Bootstrap version 3.4.1....MediumCWE-79jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBeginVersions of jsondiffpatch prior to 0.7.2 are vulnerable to Cross-site Scripting (XSS) in the HtmlFormatter (HtmlFormatter::nodeBegin). When diffs are rendered to HTML using the built-in...MediumCWE-79matrix-js-sdk has insufficient validation when considering a room to be upgraded by anothermatrix-js-sdk before 38.2.0 has insufficient validation of room predecessor links in MatrixClient::getJoinedRooms, allowing a remote attacker to attempt to replace a tombstoned room with an...MediumCWE-862CodeceptJS's incomprehensive sanitation can lead to Command InjectionCodeceptJS versions 3.5.0 through 3.7.5-beta.18 contain a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled directoryPath parameter without...HighCWE-77Decap CMS Cross Site Scripting (XSS) vulnerabilityDecap CMS through 3.8.3 is vulnerable to stored Cross-Site Scripting (XSS) in the admin preview pane. User-controlled fields (e.g., title, description, tags, and body) are...MediumCWE-79sweetalert2 v9.17.4 and above contains hidden functionalitysweetalert2 versions 9.17.4 and up until 10.0.0 are vulnerable to hidden functionality that was introduced by the maintainer. The package outputs audio and/or video messages...LowCWE-912sweetalert2 v8.19.1 and above contains hidden functionalitysweetalert2 versions 8.19.1 and up until 9.0.0 are vulnerable to hidden functionality that was introduced by the maintainer. The package outputs audio and/or video messages...LowCWE-912Malicious versions of Nx were publishedMalicious versions of the nx package, as well as some supporting plugin packages, were published to npm, containing code that scans the file system, collects...HighCWE-506messageformat has a prototype pollution vulnerabilityThe messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message key...LowCWE-1321ts-fns has prototype pollution vulnerabilityA prototype pollution vulnerability exists in the ts-fns package versions prior to 13.0.7, where insufficient validation of user-provided keys in the assign function allows attackers...MediumCWE-1321node-cube vulnerable to prototype pollutionThe node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initialization, which could allow an attacker to inject properties...LowCWE-1321mpregular vulnerable to prototype pollutionmpregular is a package that provides a small program development framework based on RegularJS. A Prototype Pollution vulnerability in the mp.addEventHandler function of mpregular version...HighCWE-1321Cattown is Vulnerable to Uncontrolled Resource Consumption through Inefficient Regular Expression ComplexityA security review of the Cattown identified multiple weaknesses that could potentially impact its stability and security.HighCWE-400private-ip vulnerable to Server-Side Request ForgeryAll versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF), where an attacker can provide an IP or hostname that resolves to...HighCWE-918csvjson vulnerable to prototype injectionA Prototype Pollution vulnerability in the toCsv function of csvjson versions thru 5.1.0 allows attackers to inject properties on Object.prototype via supplying a crafted payload,...HighCWE-1321json-schema-editor-visual vulnerable to prototype pollutionjson-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setData and deleteData function of json-schema-editor-visual versions thru 1.1.1 allows attackers...MediumCWE-1321dref is vulnerable to prototype pollutionA prototype pollution in the lib.set function of dref v0.1.2 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.HighCWE-1321lobe-chat has an Open RedirectMediumCWE-601Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat MessagesWe identified a cross-site scripting (XSS) vulnerability when handling chat message in lobe-chat that can be escalated to remote code execution on the user’s machine....MediumCWE-79counterpart vulnerable to prototype pollutionA vulnerability exists in the counterpart library for Node.js and the browser due to insufficient sanitization of user-controlled input in translation key processing. The affected...MediumCWE-1321MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP ServerAn XSS flaw exists in the MCP Inspector local development tool when it renders a redirect URL returned by a remote MCP server. If the...HighCWE-94Regular Expression Denial of Service (ReDoS) in lodash - lodash-amdlodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector...MediumCWE-400Regular Expression Denial of Service (ReDoS) in lodash - lodash-es - GHSA-x5rq-j2xg-h7qmlodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector...MediumCWE-400Regular Expression Denial of Service (ReDoS) in lodash - lodashlodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector...MediumCWE-400Regular Expression Denial of Service (ReDoS) in lodash - lodash-esAll versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.MediumCWE-400Regular Expression Denial of Service (ReDoS) in lodash - lodash.trimAll versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.MediumCWE-400Regular Expression Denial of Service (ReDoS) in lodash - lodash.trimendAll versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.MediumCWE-400Regular Expression Denial of Service (ReDoS) in lodashAll versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.MediumCWE-400Denial of Service in contentVersions of content are vulnerable to Denial of Service. The Content-Encoding HTTP header parser has a vulnerability which will cause the function to throw a...Highalgoliasearch-helper is vulnerable to Prototype Pollution in _merge()Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.prototype to...MediumCWE-1321Finance.js vulnerable to DoS via the seekZero() parameterAn issue in finance.js v.4.1.0 allows a remote attacker to cause a denial of service via the seekZero() parameter.HighCWE-770Fiora chat group avatar is vulnerable to XSS via SVG filesFile upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fails to validate SVG file content, allowing malicious SVG files...LowCWE-79@plone/volto vulnerable to potential DoS by invoking specific URL by anonymous userWhen visiting a specific URL, an anonymous user could cause the NodeJS server part of Volto to quit with an error.HighCWE-754DocsGPT Allows Remote Code ExecutionA vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an...HighCWE-95SillyTavern Web Interface Vulnerable DNS RebindingThe web UI for SillyTavern is susceptible to DNS rebinding, allowing attackers to perform actions like install malicious extensions, read chats, inject arbitrary HTML for...HighCWE-940Finance.js vulnerable to DoS via the IRR function’s depth parameterFinance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper handling of the recursion/iteration limit can lead to excessive...HighCWE-834pdfmake is vulnerable to Throttling via repeatedly redirecting URL in file embeddingVersions of the package pdfmake from 0.3.0-beta.1 to before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in...HighCWE-770MCPHub has an Improper Authorization vulnerability via its handleSseConnection functionA vulnerability was identified in samanhappy MCPHub up to 0.9.10. This vulnerability affects the function handleSseConnection of the file src/services/sseService.ts. Such manipulation leads to improper...MediumCWE-287MCPHub's ServerController is vulnerable to Command InjectionA vulnerability was found in samanhappy MCPHub up to 0.9.10. Affected by this issue is some unknown functionality of the file src/controllers/serverController.ts. The manipulation of...LowCWE-77Fiora chat user avatar is vulnerable to XSS via SVG filesCross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows arbitrary JavaScript execution when malicious SVG files are rendered by other users.LowCWE-79Happy DOM: VM Context Escape can lead to Remote Code ExecutionNo description available.HighCWE-94QGIS QWC2 Cross-Site Scripting vulnerabilityCross-Site Scripting vulnerability in attribute table in QGIS QWC2 < 2025.08.14 allows an authorized attacker to plant arbitrary JavaScript code in the page.MediumCWE-79Parse Javascript SDK vulnerable to prototype pollution in `Parse.Object` and internal APIsPrototype pollution capabilities on various APIs.MediumCWE-1321Expo SDK has an OAuth vulnerabilityA vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the “Expo AuthSession Redirect...HighCWE-522`sveltekit-superforms` has Prototype Pollution in `parseFormData` function of `formData.js`sveltekit-superforms v2.27.3 and prior are susceptible to a prototype pollution vulnerability within the parseFormData function of formData.js. An attacker can inject string and array properties...HighCWE-1321ReDoS Vulnerability in ua-parser-js versionA regular expression denial of service (ReDoS) vulnerability has been discovered in ua-parser-js.HighCWE-400Mammoth is vulnerable to Directory TraversalVersions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth...MediumCWE-22Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch moduleLowCWE-918rollbar vulnerable to prototype pollutionPrototype pollution potential with the utility function rollbar/src/utility.set(). No impact when using the published public interface.LowCWE-1321Potential XSS vulnerability in jQueryPassing HTML containing <option> elements from untrusted sources - even after sanitizing them - to one of jQuery’s DOM manipulation methods (i.e. .html(), .append(), and...MediumCWE-79Strapi is vulnerable to Insufficient Session ExpirationStrapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, which allows an attacker who has stolen...MediumCWE-613rollbar vulnerable to Prototype Pollution in merge()Prototype pollution vulnerability in merge(). If application code calls rollbar.configure() with untrusted input, prototype pollution is possible.MediumCWE-1321Playwright downloads and installs browsers without verifying the authenticity of the SSL certificateUse of curl with the -k (or --insecure) flag in installer scripts allows attackers to deliver arbitrary executables via Man-in-the-Middle (MitM) attacks. This can lead...HighCWE-347validator.js has a URL validation bypass vulnerability in its isURL functionA URL validation bypass vulnerability exists in validator.js prior to version 13.15.20. The isURL() function uses ‘://’ as a delimiter to parse protocols, while browsers...MediumCWE-79messageformat prototype pollution vulnerabilityThe Runtime components of messageformat package for Node.js version 3.0.1 contain a prototype pollution vulnerability. Due to insufficient validation of nested message keys during the...MediumCWE-1321TypeORM vulnerable to SQL injection via crafted request to repository.save or repository.updateSQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to the sqlstring call using stringifyObjects default to false.HighCWE-89Bootstrap Cross-Site Scripting (XSS) vulnerability for data-* attributesA security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the...MediumCWE-79cipher-base is missing type checks, leading to hash rewind and passing on crafted dataThis affects e.g. create-hash (and crypto-browserify), so I’ll describe the issue against that packageAlso affects create-hmac and other packagesHighCWE-20AngularJS improperly sanitizes SVG elementsImproper sanitization of the value of the ‘href’ and ‘xlink:href’ attributes in ‘' SVG elements in AngularJS allows attackers to bypass common image source restrictions....LowCWE-791AngularJS Incomplete Filtering of Special Elements vulnerabilityImproper sanitization of the value of the ‘href’ and ‘xlink:href’ attributes in ‘' SVG elements in AngularJS's 'ngSanitize' module allows attackers to bypass common image source restrictions....MediumCWE-791sha.js is missing type checks leading to hash rewind and passing on crafted dataThis is the same as GHSA-cpq7-6gpm-g9rc but just for sha.js, as it has its own implementation.HighCWE-20angular vulnerable to regular expression denial of service (ReDoS)AngularJS lets users write client-side web applications. The package angular after 1.7.0 is vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom...MediumCWE-770angular vulnerable to regular expression denial of service via the <input type="url"> elementAll versions of the package angular are vulnerable to Regular Expression Denial of Service (ReDoS) via the element due to the usage of an insecure...MediumCWE-1333angular vulnerable to regular expression denial of service via the $resource serviceAll versions of the package angular are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an...MediumCWE-1333angular vulnerable to regular expression denial of service via the angular.copy() utilityAll versions of the package angular are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of...MediumCWE-1333angular vulnerable to super-linear runtime due to backtrackingThis affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear...HighCWE-1333AngularJS allows attackers to bypass common image source restrictionsImproper sanitization of the value of the [srcset] attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a...LowCWE-1289AngularJS allows attackers to bypass common image source restrictions - angularImproper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can...LowCWE-791ansi_up cross-site scripting vulnerabilityThe npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to...MediumCWE-79Arbitrary Code Execution in underscoreThe package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when...HighCWE-94Prototype Pollution in jquery-bbqImproperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’) in jquery-bbq 1.2.1 allows a malicious user to inject properties into Object.prototype.HighCWE-1321Exposure of Sensitive Information to an Unauthorized Actor in nanoidThe package nanoid from 3.0.0, before 3.1.31, are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.MediumCWE-704Path Traversal: 'dir/../../filename' in moment.localeThis vulnerability impacts npm (server) users of moment.js, especially if user provided locale string, eg fr is directly used to switch moment locale.HighCWE-27Moment.js vulnerable to Inefficient Regular Expression ComplexityNo description available.HighCWE-400Vercel ms Inefficient Regular Expression Complexity vulnerabilityA vulnerability, which was classified as problematic, has been found in vercel ms up to 1.x. This issue affects the function parse of the file...MediumCWE-1333PostCSS line return parsing errorAn issue was discovered in PostCSS before 8.4.31. It affects linters using PostCSS to parse external Cascading Style Sheets (CSS). There may be \r discrepancies,...MediumCWE-74Elliptic's EDDSA missing signature length checkIn the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be...LowCWE-347Elliptic's ECDSA missing check for whether leading bit of r and s is zeroIn the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and...LowCWE-130Elliptic allows BER-encoded signaturesIn the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.LowCWE-347matrix-js-sdk has insufficient MXC URI validation which allows client-side path traversalmatrix-js-sdk before 34.11.0 is vulnerable to client-side path traversal via crafted MXC URIs. A malicious room member can trigger clients based on the matrix-js-sdk to...MediumCWE-22Predictable results in nanoid generation when given non-integer valuesWhen nanoid is called with a fractional value, there were a number of undesirable effects:MediumCWE-835XSS in the `of` option of the `.position()` util in jquery-uiAccepting the value of the of option of the .position() util from untrusted sources may execute untrusted code. For example, invoking the following code:MediumCWE-79Volto affected by possible DoS by invoking specific URL by anonymous userWhen visiting a specific URL, an anonymous user could cause the NodeJS server part of Volto to quit with an error.HighCWE-755min-document vulnerable to prototype pollutionA vulnerability exists in the ‘min-document’ package prior to version 2.19.1, stemming from improper handling of namespace operations in the removeAttributeNS method.LowCWE-1321Nuxt DevTools vulnerable to cross-site scripting (XSS)A vulnerability in Nuxt DevTools has been fixed in version 2.6.4*. This issue may have allowed Nuxt auth token extraction via XSS under certain configurations....MediumCWE-79Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia - vega-expressionApplications meeting 2 conditions are at risk of arbitrary JavaScript code execution, even if “safe mode” expressionInterpreter is used.HighCWE-79Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia - vega-interpreterApplications meeting 2 conditions are at risk of arbitrary JavaScript code execution, even if “safe mode” expressionInterpreter is used.HighCWE-79Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global variaApplications meeting 2 conditions are at risk of arbitrary JavaScript code execution, even if “safe mode” expressionInterpreter is used.HighCWE-79Flowise doesn't Prevent Bypass of Password Confirmation through Unverified Email Change (credentials)Unverified Email Change - Email as part of Credential / Unverified Account Recovery Channel ChangeHighCWE-620Flowise does not Prevent Bypass of Password Confirmation - Unverified Password ChangeBypass of Password Confirmation - Unverified Password Change (authenticated change without current password)HighCWE-620Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE EventsOpen WebUI v0.6.33 and below contains a code injection vulnerability in the Direct Connections feature that allows malicious external model servers to execute arbitrary JavaScript...HighCWE-95Flowise is vulnerable to arbitrary file write through its WriteFileToolThe WriteFileTool in Flowise does not restrict the file path for reading, allowing authenticated attackers to exploit this vulnerability to write arbitrary files to any...HighCWE-22expr-eval vulnerable to Prototype Pollution - expr-evalnpm package expr-eval is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary...HighCWE-1321expr-eval vulnerable to Prototype Pollutionnpm package expr-eval is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary...HighCWE-1321@dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via welcome messageSince version 4.12.0, Dependency-Track users with the SYSTEM_CONFIGURATION permission can configure a “welcome message”, which is HTML that is to be rendered on the login...MediumCWE-79Bootstrap Cross-site Scripting vulnerability - bootstrap - GHSA-pj7m-g53m-7638In Bootstrap 4.x before 4.1.2, XSS is possible in the data-target property of scrollspy. This is similar to CVE-2018-14042.MediumCWE-79angular Prototype Pollution vulnerabilityVersions of angular prior to 1.7.9 are vulnerable to prototype pollution. The deprecated API function merge() does not restrict the modification of an Object’s prototype...HighCWE-915Angular vulnerable to Cross-site Scriptingangular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping <option> elements in <select>...MediumCWE-79Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stageAn issue was discovered in Clerk-js 5.88.0 allowing attackers to bypass the OAuth authentication flow by manipulating the request at the OTP verification stage.MediumCWE-639authkit-nextjs may let session cookies be cached in CDNsIn authkit-nextjs version 2.11.0 and below, authenticated responses do not defensively apply anti-caching headers. In environments where CDN caching is enabled, this can result in...HighCWE-524@hpke/core reuses AEAD noncesThe public SenderContext Seal() API has a race condition which allows for the same AEAD nonce to be re-used for multiple Seal() calls. This can...HighCWE-323Regular Expression Denial of Service (ReDoS) in bracesA vulnerability was found in Braces versions from v2.2.0 up to but not including v2.3.1. Affected versions of this package are vulnerable to Regular Expression...LowCWE-400Valibot has a ReDoS vulnerability in `EMOJI_REGEX`The EMOJI_REGEX used in the emoji action is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. A short, maliciously crafted string (e.g., <100...HighCWE-1333Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` - @sentry/astroIn version 10.11.0, a change to how the SDK collects request data in Node.js applications caused certain incoming HTTP headers to be added as trace...MediumCWE-201Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` - @sentry/bunIn version 10.11.0, a change to how the SDK collects request data in Node.js applications caused certain incoming HTTP headers to be added as trace...MediumCWE-201Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` - @sentry/nextjsIn version 10.11.0, a change to how the SDK collects request data in Node.js applications caused certain incoming HTTP headers to be added as trace...MediumCWE-201Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` - @sentry/node-coreIn version 10.11.0, a change to how the SDK collects request data in Node.js applications caused certain incoming HTTP headers to be added as trace...MediumCWE-201Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` - @sentry/nuxtIn version 10.11.0, a change to how the SDK collects request data in Node.js applications caused certain incoming HTTP headers to be added as trace...MediumCWE-201Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` - @sentry/remixIn version 10.11.0, a change to how the SDK collects request data in Node.js applications caused certain incoming HTTP headers to be added as trace...MediumCWE-201Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` - @sentry/solidstartIn version 10.11.0, a change to how the SDK collects request data in Node.js applications caused certain incoming HTTP headers to be added as trace...MediumCWE-201Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true`In version 10.11.0, a change to how the SDK collects request data in Node.js applications caused certain incoming HTTP headers to be added as trace...MediumCWE-201Elliptic's verify function omits uniqueness validationThe Elliptic package 6.5.5 for Node.js for EDDSA implementation does not perform the required check if the signature proof(s) is within the bounds of the...LowCWE-347Valid ECDSA signatures erroneously rejected in EllipticThe Elliptic prior to 6.6.0 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four...LowCWE-347axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URLA previously reported issue in axios demonstrated that using protocol-relative URLs could lead to SSRF (Server-Side Request Forgery). Reference: axios/axios#6463HighCWE-918happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScriptThe mitigation proposed in GHSA-37j7-fg3j-429f for disabling eval/Function when executing untrusted code in happy-dom does not suffice, since it still allows prototype pollution payloads.HighCWE-1321parse is vulnerable to prototype pollutionparse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse allows attackers to inject properties on...MediumCWE-1321OneUptime is Vulnerable to Privilege Escalation via Login Response ManipulationDuring the login process, the server response included a parameter called isMasterAdmin. By intercepting and modifying this parameter value from false to true, a user...MediumCWE-863Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCEThe functionality that inserts custom prompts into the chat window is vulnerable to DOM XSS when ‘Insert Prompt as Rich Text’ is enabled, since the...HighCWE-79OneUptime Unauthorized User Creation via APIA low-permission user can create new accounts through a direct API request instead of being restricted to the intended interface.HighCWE-285Vercel’s AI SDK's filetype whitelists can be bypassed when uploading filesA vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists...LowCWE-682Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDFA Stored XSS vulnerability has been discovered in Open-WebUI’s Notes PDF download functionality. An attacker can import a Markdown file containing malicious SVG tags into...HighCWE-79expr-eval does not restrict functions passed to the evaluate function - expr-evalThe expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation,...HighCWE-94expr-eval does not restrict functions passed to the evaluate functionThe expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation,...HighCWE-94Authentication Bypass via Default JWT Secret in NocoBase docker-compose DeploymentsCVE-2025-13877 is an authentication bypass vulnerability caused by insecure default JWT key usage in NocoBase Docker deployments.MediumCWE-321Elysia vulnerable to prototype pollution with multiple standalone schema validationPrototype pollution vulnerability in mergeDeep after merging results of two standard schema validations with the same key. Due to the ordering of merging, there must...HighCWE-1321Elysia affected by arbitrary code injection through cookie configArbitrary code execution from cookie config. If dynamic cookies are enabled (ie there exists a schema for cookies), the cookie config is injected into the...HighCWE-94@tiptap/extension-link vulnerable to Cross-site Scripting (XSS)Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanitized user input allowed in setting or toggling links.LowCWE-79Formio improperly authorized permission elevation through specially crafted request pathSummary: A flaw in path handling could allow an attacker to access protected API endpoints by sending a crafted request path. This issue could result...HighCWE-178EverShop is vulnerable to Unauthorized Order Information Access (IDOR)A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation...LowCWE-99Altcha Proof-of-Work obfuscation mode cryptanalytic breakA cryptanalytic break in Altcha Proof-of-Work obfuscation mode version 0.8.0 and later allows for remote visitors to recover the Proof-of-Work nonce in constant time via...MediumCWE-327Vuetify has a Cross-site Scripting (XSS) vulnerability in the VDatePicker componentImproper neutralization of the title date in the ‘VDatePicker’ component in Vuetify, allows unsanitized HTML to be inserted into the page. This can lead to a...MediumCWE-79Vuetify has a Prototype Pollution vulnerabilityThe Preset configuration feature of Vuetify is vulnerable to Prototype Pollution due to the internal ‘mergeDeep’ utility function used to merge options with defaults.HighCWE-1321tRPC has possible prototype pollution in `experimental_nextAppDirCaller`Note that this vulnerability is only present when using experimental_caller / experimental_nextAppDirCaller.HighCWE-1321tinacms is vulnerable to arbitrary code execution - tinacmsuses the package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, to execute arbitrary...HighCWE-94tinacms is vulnerable to arbitrary code executionuses the package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, to execute arbitrary...HighCWE-94uppy's companion module is vulnerable to Server-Side Request Forgery (SSRF)uppy’s companion module is vulnerable to Server-Side Request Forgery (SSRF) via IPv4-mapped IPv6 addresses.HighCWE-918plotly.js prototype pollution vulnerabilityIn Plotly plotly.js before 2.25.2, plot API calls have a risk of proto being polluted in expandObjectPaths or nestedProperty.HighCWE-1321Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass - @apollo/sandboxA Cross-Site Request Forgery (CSRF) vulnerability was identified in Apollo’s Embedded Sandbox and Embedded Explorer.HighCWE-352Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypassA Cross-Site Request Forgery (CSRF) vulnerability was identified in Apollo’s Embedded Sandbox and Embedded Explorer.HighCWE-352hemmelig allows SSRF Filter bypass via Secret Request functionalityA Server-Side Request Forgery (SSRF) filter bypass vulnerability exists in the webhook URL validation of the Secret Requests feature. The application attempts to block internal/private...MediumCWE-918vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)A vulnerability has been discovered in vue-template-compiler, that allows an attacker to perform XSS via prototype pollution. The attacker could change the prototype chain of...MediumCWE-79axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary HeaderWhen a server calls an upstream service using different auth tokens, axios-cache-interceptor returns incorrect cached responses, leading to authorization bypass.MediumCWE-639evershop allows unauthenticated attackers to exhaust application server's resources via "GET /images" APIA Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the application server’s resources via the “GET /images” API....HighCWE-1050evershop allows unauthenticated attackers to force server to initiate HTTP request via "GET /images" APIA Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server to initiate an HTTP request via...MediumCWE-918Vega XSS via expression abusing vlSelectionTuples function array map calls in environments with satisfactory function gaApplications meeting these two conditions are at risk of arbitrary JavaScript code execution, even if “safe mode” expressionInterpreter is used.HighCWE-79`vega-functions` vulnerable to Cross-site Scripting via `setdata` functionFor sites that allow users to supply untrusted user input, malicious use of an internal function (not part of the public API) could be used...HighCWE-79misskey.js's export data contains private post dataAfter adding private posts (followers, direct) that you do not have permission to view to your favorites or clips, you can export them to view...HighCWE-862Misskey has a login rate limit bypass via spoofed X-Forwarded-For headerWhen using an untrusted reverse proxy or not using a reverse proxy at all, attackers can bypass IP rate limiting by adding a forged X-Forwarded-For...MediumCWE-307Storybook manager bundle may expose environment variables during buildOn December 11th, the Storybook team received a responsible disclosure alerting them to a potential vulnerability in certain built and published Storybooks.HighCWE-541Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server ToolsMicrosoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. This allows an attacker to perform a DNS...HighCWE-749Preact has JSON VNode Injection issueVulnerability Type: HTML Injection via JSON Type ConfusionHighCWE-843Trix has a stored XSS vulnerability through its attachment attributeThe Trix editor, in versions prior to 2.1.16, is vulnerable to XSS attacks through attachment payloads.MediumCWE-79Elliptic Uses a Cryptographic Primitive with a Risky ImplementationThe ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of ‘k’ (as computed based on step 3.2 of RFC 6979...LowCWE-1240React Router has XSS VulnerabilityA XSS vulnerability exists in in React Router’s meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR...HighCWE-79React Router has Path Traversal in File Session StorageIf applications use createFileSessionStorage() from @react-router/node (or @remix-run/node/@remix-run/deno in Remix v2) with an unsigned cookie, it is possible for an attacker to cause the session...HighCWE-22React Router SSR XSS in ScrollRestorationA XSS vulnerability exists in in React Router’s <ScrollRestoration> API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arbitrary...HighCWE-79Orejime has executable code in HTML attributesOn HTML elements handled by Orejime, one could run malicious code by embedding javascript: code within data attributes.When consenting to the related purpose, Orejime would...LowCWE-79QuestDB UI's Web Console is Vulnerable to Cross-Site ScriptingA security flaw has been discovered in questdb ui up to 1.11.9. Impacted is an unknown function of the component Web Console. The manipulation results...LowCWE-79orval MCP client is vulnerable to a code injection attack.The MCP server generation logic relies on string manipulation that incorporates the summary field from the OpenAPI specification without proper validation or escaping. This allows...HighCWE-77tarteaucitron.js has Regular Expression Denial of Service (ReDoS) vulnerabilityA potential Regular Expression Denial of Service (ReDoS) vulnerability was identified in tarteaucitron.js in the handling of the issuu_id parameter.MediumCWE-1333jQuery vulnerable to Cross-Site Scripting (XSS)Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via...MediumCWE-79enclave-vm Vulnerable to Sandbox Escape via Host Error Prototype ChainA critical sandbox escape vulnerability exists in enclave-vm (affected: < 2.6.0, patched: 2.7.0) that can allow untrusted, sandboxed JavaScript to execute arbitrary code in the...HighCWE-94devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parseCertain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input from untrusted...HighCWE-405SvelteKit is vulnerable to denial of service and possible SSRF when using prerenderingVersions of SvelteKit are vulnerable to a server side request forgery (SSRF) and denial of service (DoS) under certain conditions.HighCWE-918Devalue is vulnerable to denial of service due to memory exhaustion in devalue.parseCertain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input from untrusted...HighCWE-405@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveThe experimental form remote function uses a binary data format containing a representation of submitted form data. A specially-crafted payload can cause the server to...HighCWE-789Sandbox Breakout / Arbitrary Code Execution in localevalAll versions of localeval are vulnerable to Sandbox Escape leading to Remote Code Execution. The package fails to restrict access to the main context through...HighAxios is vulnerable to DoS attack through lack of data size checkWhen Axios runs on Node.js and is given a URL with the data: scheme, it does not perform HTTP. Instead, its Node http adapter decodes...HighCWE-770@octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic BacktracThe regular expression /<([^>]+)>; rel="deprecation"/ used to match the link header in HTTP responses is vulnerable to a ReDoS (Regular Expression Denial of Service) attack....MediumCWE-1333Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerabilityNu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including localhost...MediumCWE-918svelte is vulnerable to XSS with textarea bind:valueA server-side rendered <textarea> with two-way bound value does not have its value correctly escaped in the rendered HTML.HighCWE-79Veramo is Vulnerable to SQL Injection in Veramo Data Store ORMAn SQL injection vulnerability exists in the @veramo/data-store package that allows any authenticated user to execute arbitrary SQL queries against the database. The vulnerability is...MediumCWE-89jsPDF has Local File Inclusion/Path Traversal vulnerabilityUser control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal.HighCWE-73Unknown vulnerability in Coinbase Wallet SDKThere is a security vulnerability in outdated versions of Coinbase Wallet SDK. This does not directly affect users’ keys, smart contracts, or funds.HighCross-Site Scripting in backboneAffected versions of backbone are vulnerable to cross-site scripting when users are allowed to supply input to the Model#Escape function, and the output is then...MediumCWE-79svelte vulnerable to Cross-site ScriptingAn XSS vulnerability exists in Svelte 5.46.0-2 resulting from improper escaping of hydratable keys. If these keys incorporate untrusted user input, arbitrary JavaScript can be...MediumCWE-79Lobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File DeletionknowledgeBase.removeFilesFromKnowledgeBase tRPC ep allows authenticated users to delete files from any knowledge base without verifying ownership.LowCWE-284flat vulnerable to Prototype Pollutionflat helps flatten/unflatten nested Javascript objects. A vulnerability, which was classified as critical, was found in hughsk flat up to 5.0.0. This affects the function...HighCWE-1321@envelop/graphql-modules has a Race Condition vulnerabilityContext race condition when using useGraphQLModules pluginHighCWE-362html2pdf.js contains a cross-site scripting vulnerabilityhtml2pdf.js contains a cross-site scripting (XSS) vulnerability when given a text source rather than an element. This text is not sufficiently sanitized before being attached...HighCWE-79Turbo Frame responses can restore stale session cookiesA race condition in Turbo Frames allows delayed HTTP responses to restore stale session cookies after session-modifying operations.LowCWE-613seroval Affected by Prototype Pollution via JSON DeserializationDue to improper input validation, a malicious object key can lead to prototype pollution during JSON deserialization.This affects only JSON deserialization functionality.HighCWE-1321seroval Affected by Remote Code Execution via JSON DeserializationImproper input handling in the JSON deserialization component can lead to arbitrary JavaScript code execution.HighCWE-502Seroval affected by Denial of Service via Array serializationOverriding encoded array lengths by replacing them with an excessively large value causes the deserialization process to significantly increase processing time.HighCWE-770Seroval affected by Denial of Service via Deeply Nested ObjectsSerialization of objects with extreme depth can exceed the maximum call stack limit.HighCWE-770Modified package published to npm, containing malware that exfiltrates private key materialEarlier today, a publish-access account was compromised for @solana/web3.js, a JavaScript library that is commonly used by Solana dapps. This allowed an attacker to publish...HighCWE-200Prototype Pollution in extendVersions of extend prior to 3.0.2 (for 3.x) and 2.0.2 (for 2.x) are vulnerable to Prototype Pollution. The extend() function allows attackers to modify the...MediumCWE-400eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall have embedded malicious codeeslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches...HighCWE-506File restriction bypass in socket.io-fileAll versions of socket.io-fileare vulnerable to a file restriction bypass. The validation for valid file types only happens on the client-side, which allows an attacker...HighCWE-20Open Redirect in url-parseVersions of url-parse before 1.4.3 returns the wrong hostname which could lead to Open Redirect, Server Side Request Forgery (SSRF), or Bypass Authentication Protocol vulnerabilities....HighCWE-425Code Injection in node-rulesnode-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function “fromJSON()” can be controlled by users without any...HighCWE-94Saltcorn's Reflected XSS and Command Injection vulnerabilities can be chained for 1-click-RCEThere is a reflected XSS vulnerability in the GET /admin/edit-codepage/:name route through the name parameter. This can be used to hijack the session of an...HighCWE-79CSVTOJSON has a prototype pollution vulnerabilityThe csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototype pollution vulnerability in versions prior to 2.0.10....MediumCWE-1321billboard.js is vulnerable to XSS during chart option bindingbillboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding.HighCWE-79elysia-cors Origin Validation ErrorAn Origin Validation Error in the elysia-cors library thru 1.3.0 allows attackers to bypass Cross-Origin Resource Sharing (CORS) restrictions. The library incorrectly validates the supplied...MediumCWE-346dcap-qvl has Missing Verification for QE IdentityThis vulnerability involves a critical gap in the cryptographic verification process within the dcap-qvl.HighCWE-347StudioCMS has Authorization Bypass Through User-Controlled KeyStudioCMS contains a Broken Object Level Authorization (BOLA) vulnerability in the Content Management feature that allows users with the “Visitor” role to access draft content...MediumCWE-862Maker.js has Unsafe Property Copying in makerjs.extendObjectThe makerjs.extendObject function copies properties from source objects without proper validation, potentially exposing applications to security risks. The function lacks hasOwnProperty() checks and does not...MediumCWE-1321Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special ElementsVersions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that...HighCWE-792Orval has Code Injection via unsanitized x-enum-descriptions using JS commentsCVE-2026-23947 had an incomplete fixHighCWE-94LobeHub Vulnerable to Improper Authorization in Presigned UploadThe file upload feature in Knowledge Base > File Upload does not validate the integrity of the upload request, allowing users to intercept and modify...MediumCWE-73React2Shell (CVE-2025-66478)React2Shell is a critical unauthenticated remote code execution vulnerability affecting server-side usage of React Server Components and React Server Functions. The issue arises from a...HighCWE-78XML External Entity Injection (XXE)XML External Entity (XXE) injection occurs when an application parses untrusted XML input with external entity processing enabled. An attacker can define malicious external entities...HighCWE-918Flowise is vulnerable to arbitrary file exposure through its ReadFileToolThe ReadFileTool in Flowise does not restrict file path access, allowing authenticated attackers to exploit this vulnerability to read arbitrary files from the file system,...HighCWE-22jsPDF has Shared State Race Condition in addJS PluginThe addJS method in the jspdf Node.js build utilizes a shared module-scoped variable (text) to store JavaScript content. When used in a concurrent environment (e.g.,...MediumCWE-362jsPDF Vulnerable to Stored XMP Metadata Injection (Spoofing & Integrity Violation)User control of the first argument of the addMetadata function allows users to inject arbitrary XML.MediumCWE-74jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoderUser control of the first argument of the addImage method results in Denial of Service.HighCWE-770jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript ExecutionUser control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions.HighCWE-116Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email RoutingAn Insecure Direct Object Reference (CWE-639) has been found to exist in createHeaderBasedEmailResolver() function within the Cloudflare Agents SDK.MediumCWE-639url-parse incorrectly parses hostname / protocol due to unstripped leading control characters.Leading control characters in a URL are not stripped when passed into url-parse. This can cause input URLs to be mistakenly be interpreted as a...MediumCWE-639Path traversal in url-parseurl-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.MediumCWE-23Open redirect in url-parse - url-parseAffected versions of npm url-parse are vulnerable to URL Redirection to Untrusted Site.MediumCWE-601Improper Validation and Sanitization in url-parseInsufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.MediumCWE-20Qwik SSR XSS via Unsafe Virtual Node SerializationDescriptionA Cross-site Scripting (CWE-79) vulnerability in Qwik.js’ server-side rendering virtual attribute serialization allows a remote attacker to inject arbitrary web scripts into server-rendered pages via...MediumCWE-79Prototype Pollution via FormData Processing in Qwik CityA Prototype Pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city middleware. The function processes form field names with dot notation (e.g., user.name) to create...HighCWE-1321Qwik City has a CSRF Protection Bypass via Content-Type Header ValidationQwik City’s server-side request handler inconsistently interprets HTTP request headers, which can be abused by a remote attacker to circumvent form submission CSRF protections using...MediumCWE-352Qwik City Open Redirect via fixTrailingSlashDescriptionAn Open Redirect (CWE-601) vulnerability in Qwik City’s default request handler middleware allows a remote attacker to redirect users to arbitrary protocol-relative URLs.LowCWE-601@isaacs/brace-expansion has Uncontrolled Resource Consumption@isaacs/brace-expansion is vulnerable to a Denial of Service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric...HighCWE-1333Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE)A stored Cross-Site Scripting (XSS) vulnerability in the Mermaid artifact renderer allows attackers to execute arbitrary JavaScript within the application context. This XSS can be...HighCWE-94KaTeX's maxExpand bypassed by `\edef`KaTeX users who render untrusted mathematical expressions could encounter malicious input using \edef that causes a near-infinite loop, despite setting maxExpand to avoid such loops....MediumCWE-674survey-pdf Upgraded jsPDF Version Due to Security VulnerabilityThe following security vulnerability was identified in jsPDF versions <=3.0.4: Local File Inclusion/Path Traversal.HighCWE-73webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistenceWhen experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, but does not re-validate allowedUris after following HTTP 30x redirects....LowCWE-918webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behaviorWhen experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using crafted URLs that include userinfo...LowCWE-918SCEditor has DOM XSS via emoticon URL/HTML injectionIf an attacker has the ability control configuration options passed to sceditor.create(), like emoticons, charset, etc. then it’s possible for them to trigger an XSS...MediumCWE-79Open Chinese Convert has Out-of-bounds WriteA weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSegmentation of the file src/MaxMatchSegmentation.cpp. This manipulation causes heap-based...LowCWE-787Sandbox escape via infinite recursion and error objects - @enclave-vm/coreNote: The npm package has moved to @enclave-vm/core (formerly enclave-vm).All fixed versions and guidance refer to @enclave-vm/core.MediumCWE-835Sandbox escape via infinite recursion and error objectsNote: The npm package has moved to @enclave-vm/core (formerly enclave-vm).All fixed versions and guidance refer to @enclave-vm/core.MediumCWE-835@payloadcms/drizzle has SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite AdaptersWhen querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blind SQL Injection attacks. An unauthenticated attacker could extract...HighCWE-89payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments)A cross-collection Insecure Direct Object Reference (IDOR) vulnerability exists in the payload-preferences internal collection.MediumCWE-639LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header InjectionThe LangSmith SDK’s distributed tracing feature is vulnerable to Server-Side Request Forgery via malicious HTTP headers. An attacker can inject arbitrary api_url values through the...MediumCWE-918Cube Core is vulnerable to privilege escalation via a specially crafted requestIt is possible to make a specially crafted request with a valid API token that leads to privilege escalation.HighCWE-807Cube Core is vulnerable to Denial of Service (DoS) via crafted requestIt is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint.MediumCWE-755Lightning Flow Scanner Vulnerable to Code Injection via Unsafe Use of `new Function()` in APIVersion RuleThe APIVersion rule uses new Function() to evaluate expression strings. A malicious crafted flow metadata file can cause arbitrary JavaScript execution during scanning. An attacker...HighCWE-94Qwik City CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-A typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type headers.MediumCWE-352nanotar is vulnerable to path traversal in parseTar() and parseTarGzip()nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory...MediumCWE-22CASL Ability is Vulnerable to Prototype PollutionCASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.HighCWE-1321SQL Injection in typeorm - typeormVersions of typeorm before 0.1.15 are vulnerable to SQL Injection. Field names are not properly validated allowing attackers to inject SQL statements and execute arbitrary...HighCWE-89fast-xml-parser has RangeError DoS Numeric Entities BugA RangeError vulnerability exists in the numeric entity processing of fast-xml-parser when parsing XML with out-of-range entity code points (e.g., &#9999999; or &#xFFFFFF;). This causes...HighCWE-248@langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validationThe RecursiveUrlLoader class in @langchain/community is a web crawler that recursively follows links from a starting URL. Its preventOutside option (enabled by default) is intended...MediumCWE-918set-in Affected by Prototype PollutionA prototype pollution vulnerability exists in the the npm package set-in (>=2.0.1). Despite a previous fix that attempted to mitigate prototype pollution by checking whether...HighCWE-1321cap-go/capacitor-native-biometric Authentication BypassThere is a potential issue with the cap-go/capacitor-native-biometric library.MediumCWE-287@farmfe/core is Missing Origin Validation in WebSocketnpm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server does not validate origin when connecting to a WebSocket...MediumCWE-1385markdown-it is has a Regular Expression Denial of Service (ReDoS)Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the...MediumCWE-1333Cloudflare Agents is Vulnerable to Reflected Cross-Site Scripting in the AI Playground's OAuth callback handlerSummaryMediumCWE-79Cloudflare Agents has a Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground siteA Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground’s OAuth callback handler. The error_description query parameter was directly interpolated into an HTML...MediumCWE-79beautiful-mermaid contains an SVG attribute injection issue that can lead to cross-site scripting (XSS)beautiful-mermaid versions prior to 0.1.3 contain an SVG attribute injection issue that can lead to cross-site scripting (XSS) when rendering attacker-controlled Mermaid diagrams.MediumCWE-79@octokit/endpoint has a Regular Expression in parse that Leads to ReDoS Vulnerability Due to Catastrophic BacktrackingBy crafting specific options parameters, the endpoint.parse(options) call can be triggered, leading to a regular expression denial-of-service (ReDoS) attack. This causes the program to hang...MediumCWE-1333pbkdf2 silently disregards Uint8Array input, returning static keysOn historic but declared as supported Node.js versions (0.12-2.x), pbkdf2 silently disregards Uint8Array inputHighCWE-20BSV Blockchain SDK has an Authentication Signature Data Preparation VulnerabilityNo description available.MediumCWE-573Unauthorized npm publish of [email protected] with modified postinstall scriptOn February 17, 2026 at 3:26 AM PT, an unauthorized party used a compromised npm publish token to publish an update to Cline CLI on...LowjsPDF has a PDF Object Injection via Unsanitized Input in addJS MethodUser control of the argument of the addJS method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload...HighCWE-94devalue `uneval`ed code can create objects with polluted prototypes when `eval`edUnder certain circumstances, unevaling untrusted data can produce output code that will create objects with polluted prototypes when later evaled, meaning the output data can...LowCWE-1321devalue affected by CPU and memory amplification from sparse arraysUnder certain circumstances, serializing sparse arrays using uneval or stringify could cause CPU and/or memory exhaustion. When this occurs on the server, it results in...LowCWE-770Memory exhaustion in SvelteKit remote form deserialization (experimental only)Versions of @sveltejs/kit prior to 2.52.2 with remote functions enabled can be vulnerable to memory exhaustion. Malformed form data can cause the server process to...MediumCWE-770CPU exhaustion in SvelteKit remote form deserialization (experimental only)Versions of @sveltejs/kit prior to 2.52.2 with remote functions enabled are vulnerable to CPU exhaustion. Malformed form data can cause the server to become unresponsive...MediumCWE-843jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF DimensionsUser control of the first argument of the addImage method results in denial of service.HighCWE-770Fabric.js Affected by Stored XSS via SVG Exportfabric.js applies escapeXml() to text content during SVG export (src/shapes/Text/TextSVGExportMixin.ts:186) but fails to apply it to other user-controlled string values that are interpolated into SVG...HighCWE-79LangChain serialization injection vulnerability enables secret extraction - @langchain/coreA serialization injection vulnerability exists in LangChain JS’s toJSON() method (and subsequently when string-ifying objects using JSON.stringify(). The method did not escape objects with 'lc'...HighCWE-502LangChain serialization injection vulnerability enables secret extractionA serialization injection vulnerability exists in LangChain JS’s toJSON() method (and subsequently when string-ifying objects using JSON.stringify(). The method did not escape objects with 'lc'...HighCWE-502Improper Control of Generation of Code ('Code Injection') in @tygo-van-den-hurk/slydeThis is a remote code execution (RCE) vulnerability. Node.js automatically imports **/*.plugin.{js,mjs} files including those from node_modules, so any malicious package with a .plugin.js file...HighCWE-829Authorization bypass in url-parseAuthorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.MediumCWE-639url-parse Incorrectly parses URLs that include an '@A specially crafted URL with an ‘@’ sign but empty user info and no hostname, when parsed with url-parse, url-parse will return the incorrect href....MediumCWE-639RediSearch Query Injection in @langchain/langgraph-checkpoint-redisA query injection vulnerability exists in the @langchain/langgraph-checkpoint-redis package’s filter handling. The RedisSaver and ShallowRedisSaver classes construct RediSearch queries by directly interpolating user-provided filter keys...MediumCWE-74Svelte affected by XSS in SSR `<option>` elementIn certain circumstances, the server-side rendering output of an <option> element does not properly escape its content, potentially allowing HTML injection in the SSR output....MediumCWE-79Svelte affected by cross-site scripting via spread attributes in Svelte SSRVersions of svelte prior to 5.51.5 are vulnerable to cross-site scripting (XSS) during server-side rendering. When using spread syntax to render attributes from untrusted data,...MediumCWE-79Svelte SSR does not validate dynamic element tag names in `<svelte:element>`When using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the...MediumCWE-79Svelte SSR attribute spreading includes inherited properties from prototype chainIn server-side rendering, attribute spreading on elements (e.g. <div {...attrs}>) enumerates inherited properties from the object’s prototype chain rather than only own properties. In environments...MediumCWE-915Feathers has an open redirect in OAuth callback enables account takeoverThe redirect query parameter is appended to the base origin without validation, allowing attackers to steal access tokens via URL authority injection. This leads to...HighCWE-601Feathers has an origin validation bypass via prefix matchingThe origin validation uses startsWith() for comparison, allowing attackers to bypass the check by registering a domain that shares a common prefix with an allowed...HighCWE-346Feathers exposes internal headers via unencrypted session cookieAll HTTP request headers are stored in the session cookie, which is signed but not encrypted, exposing internal proxy/gateway headers to clients.HighCWE-200Prototype pollution in swiper - swiperA prototype pollution vulnerability exists in the the npm package swiper (>=6.5.1, < 12.1.2). Despite a previous fix that attempted to mitigate prototype pollution by...HighCWE-1321Pannellum has a XSS vulnerability in hot spot attributesThe hot spot attributes configuration property allowed any attribute to be set, including HTML event handler attributes, allowing for potential XSS attacks. This affects websites...MediumCWE-79bn.js affected by an infinite loopThis affects versions of the package bn.js before 4.12.3 and 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and...MediumCWE-835OneUptime:: node:vm sandbox escape in probe allows any project member to achieve RCEOneUptime lets project members write custom JavaScript that runs inside monitors. The problem is it executes that code using Node.js’s built-in vm module, which Node.js...HighCWE-94Payload: Server-Side Request Forgery (SSRF) in External File URL UploadsA Server-Side Request Forgery (SSRF) vulnerability exists in Payload’s external file upload functionality. When processing external URLs for file uploads, insufficient validation of HTTP redirects...MediumCWE-918repostat: Reflected Cross-Site Scripting (XSS) via repo prop in RepoCardThe RepoCard component is vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability occurs because the component uses React’s dangerouslySetInnerHTML to render the repository name (repo...MediumCWE-79Rollup 4 has Arbitrary File Write via Path TraversalThe Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization...HighCWE-22Angular SSR is vulnerable to SSRF and Header Injection via request handling pipelineA Server-Side Request Forgery (SSRF) vulnerability has been identified in the Angular SSR request handling pipeline.HighCWE-918LangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoaderA redirect-based Server-Side Request Forgery (SSRF) bypass exists in RecursiveUrlLoader in @langchain/community. The loader validates the initial URL but allows the underlying fetch to follow...MediumCWE-918Storybook Dev Server is Vulnerable to WebSocket HijackingThe WebSocket functionality in Storybook’s dev server, used to create and update stories, is vulnerable to WebSocket hijacking. This vulnerability only affects the Storybook dev...HighCWE-79FUXA has JWT Authentication Bypass via HTTP Referer header spoofingFUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts...HighCWE-288dottie is vulnerable to Prototype Pollution bypass via non-first path segments in set() and transform()dottie versions 2.0.4 through 2.0.6 contain an incomplete fix for CVE-2023-26132. The prototype pollution guard introduced in commit 7d3aee1 only validates the first segment of...MediumCWE-1321Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST DataAn issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a...MediumCWE-79Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration MarkersErrors from transformError were not correctly escaped prior to being embedded in the HTML output, causing potential HTML injection and XSS if attacker-controlled content is...MediumCWE-79fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)The XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the...HighCWE-776fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity namesNo description available.HighCWE-185deepHas vulnerable to Prototype Pollution via constructor.prototypeA prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. This issue was...HighCWE-1321OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in traceroute exec()An OS command injection vulnerability in NetworkPathMonitor.performTraceroute() allows any authenticated project user to execute arbitrary operating system commands on the Probe server by injecting shell...HighCWE-78Orval has a code injection via unsanitized x-enum-descriptions in enum generationArbitrary code execution in environments consuming generated clientsHighCWE-94Orval Mock Generation Code Injection via constI am reporting a code injection vulnerability in Orval’s mock generation pipeline affecting @orval/mock in both the 7.x and 8.x series. This issue is related...HighCWE-94SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimentaSome relatively small inputs can cause very large files arrays in form handlers. If the SvelteKit application code doesn’t check files.length or individual files’ sizes...LowCWE-770CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent functionCleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-site Scripting (XSS) via window.postMessage. The handleCustomHtmlPreviewPostMessageEvent function in src/util/campaignRender/nativeDisplay.js performs insufficient origin validation using...HighCWE-79CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessageCleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage in the Visual Builder module. The origin validation in...HighCWE-79Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()The serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660.HighCWE-96ajv has ReDoS when using `$data` optionajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern...MediumCWE-400Dark Reader gives users the ability to request style sheets from local web serversDark Reader versions prior to 4.9.117 included a behavior where a website could request a style sheet from a locally running web server, for example...LowCWE-668OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing creThe WebAuthn authentication implementation does not store the challenge on the server side. Instead, the challenge is returned to the client and accepted back from...HighCWE-294Vercel Workflow Allows Webhook Creation with Predictable User-Specified Tokens - workflowcreateWebhook() in Vercel Workflow DevKit accepts a user-specified token parameter that serves as the credential for the public webhook endpoint /.well-known/workflow/v1/webhook/{token}.MediumCWE-287Vercel Workflow Allows Webhook Creation with Predictable User-Specified TokenscreateWebhook() in Vercel Workflow DevKit accepts a user-specified token parameter that serves as the credential for the public webhook endpoint /.well-known/workflow/v1/webhook/{token}.MediumCWE-287fast-xml-parser has stack overflow in XMLBuilder with preserveOrderApplication crashes with stack overflow when user use XML builder with prserveOrder:true for following or similar inputLowCWE-120Backstage vulnerable to potential reading of SCM URLs using built in tokenA vulnerability in the SCM URL parsing used by Backstage integrations allowed path traversal sequences in encoded form to be included in file paths.LowCWE-22fast-xml-parser vulnerable to Regex Injection via Doctype Entities“fast-xml-parser” allows special characters in entity names, which are not escaped or sanitized. Since the entity name is used for creating a regex for searching...HighCWE-400OneUpTime's Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCEOneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test websites. However, the system executes this untrusted user code inside the...HighCWE-94OneUptime has broken access control in GitHub App installation flow that allows unauthorized project bindingOneUptime’s GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: true without validating that the caller is authorized for the...HighCWE-862OneUptime: Synthetic Monitor RCE via exposed Playwright browser objectSummaryHighCWE-749OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header that leads to cross‑tenant data exA low‑privileged user can bypass authorization and tenant isolation in OneUptime v10.0.20 by sending a forged is-multi-tenant-query header together with a controlled projectid header.HighCWE-862OneUptime has Synthetic Monitor RCE via exposed Playwright browser objectOneUptime Synthetic Monitors allow a low-privileged authenticated project user to execute arbitrary commands on the oneuptime-probe server/container.HighCWE-749OneUptime has WhatsApp Resend Verification Authorization BypassThe resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated (unlike the...MediumCWE-862StudioCMS has Privilege Escalation via Insecure API Token GenerationThe /studiocms_api/dashboard/api-tokens endpoint allows any authenticated user (at least Editor) to generate API tokens for any other user, including owner and admin accounts. The endpoint...HighCWE-863Feathers has an OAuth Callback Account Takeover issueAn unauthenticated attacker can send a crafted GET request directly to /oauth/:provider/callback with a forged profile in the query string. The OAuth service’s authentication payload...HighCWE-287Feathers has a NoSQL Injection via WebSocket id Parameter in MongoDB AdapterSocket.IO clients can send arbitrary JavaScript objects as the id argument to any service method (get, patch, update, remove). The transport layer performs no type...HighCWE-943Elysia has a string URL format ReDoSt.String({ format: 'url' }) is vulnerable to redosHighCWE-1333StudioCMS: IDOR — Arbitrary API Token Revocation Leading to Denial of ServiceThe DELETE /studiocms_api/dashboard/api-tokens endpoint allows any authenticated user with editor privileges or above to revoke API tokens belonging to any other user, including admin and...HighCWE-639@appium/support has a Zip Slip arbitrary file write in its ZIP extraction@appium/support contains a ZIP extraction implementation (extractAllTo() via ZipExtractor.extract()) with a path traversal (Zip Slip) check that is non-functional. The check at line 88 of...MediumCWE-22jsPDF has a PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" prUser control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions.HighCWE-116@siteboon/claude-code-ui is Vulnerable to Shell Command Injection in Git Routes| Field | Value ||——-|——-|| Severity | High || CVSS 3.1 | 8.HighCWE-94@siteboon/claude-code-ui Vulnerable to Unauthenticated RCE via WebSocket Shell InjectionDownload: cve_claudecodeui_submission_v2.zipHighCWE-78Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`The contents of bind:innerText and bind:textContent on contenteditable elements were not properly escaped. This could enable HTML injection and Cross-site Scripting (XSS) if rendering untrusted...MediumCWE-79devalue has prototype pollution in devalue.parse and devalue.unflattenIn devalue v5.6.3, devalue.parse and devalue.unflatten were susceptible to prototype pollution via maliciously crafted payloads. Successful exploitation could lead to Denial of Service (DoS) or...MediumCWE-1321liquidjs has a path traversal fallback vulnerabilityThe layout, render, and include tags allow arbitrary file access via absolute paths (either as string literals or through Liquid variables, the latter require dynamicPartials:...HighCWE-22StudioCMS S3 Storage Manager Authorization Bypass via Missing `await` on Async Auth CheckThe S3 storage manager’s isAuthorized() function is declared async (returns Promise<boolean>) but is called without await in both the POST and PUT handlers. Since a...HighCWE-863StudioCMS: IDOR — Admin-to-Owner Account Takeover via Password Reset Link GenerationThe POST /studiocms_api/dashboard/create-reset-link endpoint allows any authenticated user with admin privileges to generate a password reset token for any other user, including the owner account....MediumCWE-639StudioCMS: IDOR in User Notification Preferences Allows Any Authenticated User to Modify Any User's SettingsThe updateUserNotifications endpoint accepts a user ID from the request payload and uses it to update that user’s notification preferences. It checks that the caller...MediumCWE-639StudioCMS: REST API Missing Rank Check Allows Admin to Create Peer Admin AccountsThe REST API createUser endpoint uses string-based rank checks that only block creating owner accounts, while the Dashboard API uses indexOf-based rank comparison that prevents...MediumCWE-269Tina: Path Traversal in Media Upload Handle| Field | Value ||——-|——-|| Package | @tinacms/cli || Version | 2.0.5 (latest at time of discovery) || Vulnerable File | packages/@tinacms/cli/src/next/commands/dev-command/server/media.ts || Vulnerable Lines...HighCWE-22@tinacms/graphql has a Path Traversal issueTinaCMS allows users to create, update, and delete content documents using relative file paths (relativePath, newRelativePath) via GraphQL mutations. Under certain conditions, these paths are...MediumCWE-22Unhead has XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol checkuseHeadSafe() can be bypassed to inject arbitrary HTML attributes, including event handlers, into SSR-rendered <head> tags. This is the composable that Nuxt docs recommend for...MediumCWE-79Unhead Vulnerable to Bypass of URI Scheme Sanitization in makeTagSafe via Case-SensitivityThe link.href check in makeTagSafe (safe.ts, line 68-71) uses String.includes(), which is case-sensitive:LowCWE-79flatted vulnerable to unbounded recursion DoS in parse() revive phaseflatted’s parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential...HighCWE-674es5-ext vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`Passing functions with very long names or complex default argument names into function#copy orfunction#toStringTokens may put script to stallLowCWE-1333@nfid/embed has compromised private key due to @dfinity/auth-client producing insecure session keysUser sessions in the @nfid/embed SDK with Ed25519 keys are vulnerable due to a compromised private key 535yc-uxytb-gfk7h-tny7p-vjkoe-i4krp-3qmcl-uqfgr-cpgej-yqtjq-rqe. This exposes users to potential loss of...HighCWE-330XSS in @leanprover/unicode-input-componentProjects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element...LowCWE-80OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")The Markdown viewer component renders Mermaid diagrams with securityLevel: "loose" and injects the SVG output via innerHTML. This configuration explicitly allows interactive event bindings in...HighCWE-79OneUptime ClickHouse SQL Injection via Aggregate Query ParametersThe telemetry aggregation API accepts user-controlled aggregationType, aggregateColumnName, and aggregationTimestampColumnName parameters and interpolates them directly into ClickHouse SQL queries via the .append() method (documented as...HighCWE-89OneUptime: Password Reset Token Logged at INFO LevelThe password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by...MediumCWE-532crypto-js uses insecure random numbersThe crypto-js package 3.2.0 for Node.js generates random numbers by concatenating the string “0.” with an integer, which makes the output more predictable than necessary....MediumCWE-331mapshaper Path Traversal vulnerabilityPath Traversal in GitHub repository mbloch/mapshaper prior to 0.6.44.MediumCWE-400Cross-Site Scripting (XSS) via Select Schema Option Value Injection in @pdfme/schemasThe Select schema plugin in @pdfme/schemas constructs HTML from template-defined option values using unsanitized string interpolation and sets it via innerHTML, enabling arbitrary JavaScript execution....MediumCWE-79Cross-Site Scripting (XSS) via SVG Schema innerHTML Injection in @pdfme/schemasThe SVG schema plugin in @pdfme/schemas renders user-supplied SVG content using container.innerHTML = value without any sanitization, enabling arbitrary JavaScript execution in the user’s browser....MediumCWE-79StudioCMS REST getUsers Exposes Owner Account Records to Admin TokensThe REST API getUsers endpoint in StudioCMS uses the attacker-controlled rank query parameter to decide whether owner accounts should be filtered from the result set....LowCWE-639NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerabilityA stored cross-site scripting (XSS) vulnerability exists in the NotChatbot WebChat widget thru 1.4.4. User-supplied input is not properly sanitized before being stored and rendered...MediumCWE-79MCP Connect has unauthenticated remote OS command execution via /bridge endpointWhen AUTH_TOKEN and ACCESS_TOKEN environment variables are not set (which is the default out-of-the-box configuration) the /bridge HTTP endpoint is completely unauthenticated.HighCWE-306pdfmake is vulnerable to server-side request forgery (SSRF)Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitive information via the src/URLResolver.js component. The fix...HighCWE-918CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support package - @ckeditor/ckeditor5-html-supportA Cross-Site Scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading...MediumCWE-79CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support packageA Cross-Site Scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading...MediumCWE-79jsPDF has a PDF Object Injection via FreeText colorUser control of arguments of the createAnnotation method allows users to inject arbitrary PDF objects, such as JavaScript actions.HighCWE-116Uncontrolled memory allocation via crafted SVG dimensions in @dicebear/converterThe ensureSize() function in @dicebear/converter (versions < 9.4.0) read the width and height attributes from the input SVG to determine the output canvas size for...HighCWE-770jsPDF has HTML Injection in New Window pathsUser control of the options argument of the output function allows attackers to inject arbitrary HTML (such as scripts) into the browser context the created...HighCWE-79Qwik City has array method pollution in FormData processing allows type confusion and DoSSummaryHighCWE-843PDFME has XSS via Unsanitized i18n Label Injection into innerHTML in multiVariableText propPanelThe multiVariableText property panel in @pdfme/schemas constructs HTML via string concatenation and assigns it to innerHTML using unsanitized i18n label values. An attacker who can...MediumCWE-79PDFME has SSRF via Unvalidated URL Fetch in `getB64BasePdf` When `basePdf` Is Attacker-ControlledThe getB64BasePdf function in @pdfme/common fetches arbitrary URLs via fetch() without any validation when basePdf is a non-data-URI string and window is defined. An attacker...MediumCWE-918Vulnogram contains a stored cross-site scripting vulnerability in comment hypertext handlingVulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts. Remote attackers can inject XSS payloads...MediumCWE-79SQL Injection via unsanitized JSON path keys when ignoring/silencing compilation errors or using `Kysely<any>`.Kysely through 0.28.11 has a SQL injection vulnerability in JSON path compilation for MySQL and SQLite dialects. The visitJSONPathLeg() function appends user-controlled values from .key()...HighCWE-89OneUptime ClickHouse vulnerable to SQL Injection via unvalidated column identifiers in sort, select, and groupBy parametThe fix for GHSA-p5g2-jm85-8g35 (ClickHouse SQL injection via aggregate query parameters) added column name validation to the _aggregateBy method but did not apply the same...HighCWE-89OneUptime WhatsApp Webhook Missing Signature VerificationThe WhatsApp POST webhook handler (/notification/whatsapp/webhook) processes incoming status update events without verifying the Meta/WhatsApp X-Hub-Signature-256 HMAC signature, allowing any unauthenticated attacker to send forged...HighCWE-345socket.io allows an unbounded number of binary attachmentsA specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to...HighCWE-754agent-js: Insecure Key Generation in `Ed25519KeyIdentity.generate` - @dfinity/identityThe library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional param to provide a 32 byte seed value, which...HighCWE-330agent-js: Insecure Key Generation in `Ed25519KeyIdentity.generate`The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional param to provide a 32 byte seed value, which...HighCWE-330Potential leakage of Sentry auth tokens by React Native SDK with Expo pluginSDK versions between and including 5.16.0 and 5.19.0 allowed Sentry auth tokens to be set in the optional authToken configuration parameter, for debugging purposes.LowCWE-200Elysia Cookie Value Prototype PollutionElysia cookie can be overridden by prototype pollution , eg. __proto__MediumCWE-1321sanitize-html Information Exposure vulnerabilityVersions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration...MediumCWE-538PowerSync: Some sync filters ignored on 1.20.0 using `config.edition: 3` - @powersync/service-coreIn version 1.20.0, when using new sync streams with config.edition: 3, certain subquery filters were ignored when determining which data to sync to users.MediumCWE-285PowerSync: Some sync filters ignored on 1.20.0 using `config.edition: 3`In version 1.20.0, when using new sync streams with config.edition: 3, certain subquery filters were ignored when determining which data to sync to users.MediumCWE-285`@backstage/backend-common` vulnerable to path traversal through symlinksPaths checks with the resolveSafeChildPath utility were not exhaustive enough, leading to risk of path traversal vulnerabilities if symlinks can be injected by attackers.HighCWE-22fido2-lib is vulnerable to DoS via cbor-extract heap buffer over-read in CBOR attestation parsingfido2-lib v3.x depends on cbor-x (~1.6.0), which optionally pulls in cbor-extract (C++ native addon). cbor-extract <= 2.2.0 has a heap buffer over-read in extractStrings() —...HighCWE-1395fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-The fix for CVE-2026-26278 added entity expansion limits (maxTotalExpansions, maxExpandedLength, maxEntityCount, maxEntitySize) to prevent XML entity expansion Denial of Service. However, these limits are only...HighCWE-776sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKeyAll versions of the package sjcl are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover...HighCWE-347Effect `AsyncLocalStorage` context lost/contaminated inside Effect fibers under concurrent load with RPCNo description available.HighCWE-362Prototype Pollution via parse() in NodeJS flattedSummaryHighCWE-1321SVG Injection via Unsanitized Options in @dicebear/core and @dicebear/initials - @dicebear/coreSVG attribute values derived from user-supplied options (backgroundColor, fontFamily, textColor) were not XML-escaped before interpolation into SVG output. This could allow Cross-Site Scripting (XSS) when...MediumCWE-79SVG Injection via Unsanitized Options in @dicebear/core and @dicebear/initialsSVG attribute values derived from user-supplied options (backgroundColor, fontFamily, textColor) were not XML-escaped before interpolation into SVG output. This could allow Cross-Site Scripting (XSS) when...MediumCWE-79SVG Dimension Capping Bypass via XML Comment Injection in @dicebear/converter ensureSize()The ensureSize() function in @dicebear/converter used a regex-based approach to rewrite SVG width/height attributes, capping them at 2048px to prevent denial of service. This size...HighCWE-185path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parametersA bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a...HighCWE-1333Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods thatKysely’s DefaultQueryCompiler.sanitizeStringLiteral() only escapes single quotes by doubling them (' → '') but does not escape backslashes.HighCWE-89Kysely has a MySQL SQL Injection via Backslash Escape Bypass in non-type-safe usage of JSON path keys.The sanitizeStringLiteral method in Kysely’s query compiler escapes single quotes (' → '') but does not escape backslashes. On MySQL with the default BACKSLASH_ESCAPES SQL...HighCWE-89yaml is vulnerable to Stack Overflow via deeply nested YAML collectionsParsing a YAML document with yaml may throw a RangeError due to a stack overflow.MediumCWE-674Handlebars.js has Prototype Pollution Leading to XSS through Partial Template InjectionresolvePartial() in the Handlebars runtime resolves partial names via a plain property lookup on options.partials without guarding against prototype-chain traversal. When Object.prototype has been polluted...MediumCWE-79Handlebars.js has JavaScript Injection via AST Type ConfusionHandlebars.compile() accepts a pre-parsed AST object in addition to a template string. The value field of a NumberLiteral AST node is emitted directly into the...HighCWE-94Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-blockThe @partial-block special variable is stored in the template data context and is reachable and mutable from within a template via helpers that accept arbitrary...HighCWE-94path-to-regexp vulnerable to Denial of Service via sequential optional groupsA bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as {a}{b}{c}:z. The generated regex grows exponentially...HighCWE-400path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcardsWhen using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires...MediumCWE-1333Handlebars.js has a Property Access Validation Bypass in container.lookupIn lib/handlebars/runtime.js, the container.lookup() function uses container.lookupProperty() as a gate check to enforce prototype-access controls, but then discards the validated result and performs a second,...LowCWE-367Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist EntryThe prototype method blocklist in lib/handlebars/internal/proto-access.js blocks constructor, __defineGetter__, __defineSetter__, and __lookupGetter__, but omits the symmetric __lookupSetter__.MediumCWE-1321Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookieshappy-dom may attach cookies from the current page origin (window.location) instead of the request target URL when fetch(..., { credentials: "include" }) is used. This...HighCWE-201OpenCC has an Out-of-bounds read when processing truncated UTF-8 inputOpenCC versions before 1.2.0 contain two CWE-125: Out-of-bounds Read issues caused by length validation failures in UTF-8 processing. When handling malformed or truncated UTF-8 input,...MediumCWE-125jsrsasign: Missing cryptographic validation during DSA signing enables private key extractionVersions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation.HighCWE-325Cloud Metadata DisclosureCloud Metadata Disclosure occurs when a server retrieves and discloses sensitive information from cloud metadata services. This typically happens when user-controlled input is used to...HighCWE-918Possible Server-Side Request ForgeryA Possible Server-Side Request Forgery (SSRF) vulnerability occurs when a server appears to make outbound requests based on user-supplied input. Indicators such as response delays...HighCWE-918LiquidJS has Exponential Memory Amplification through its replace_first Filter $& PatternThe replace_first filter in LiquidJS uses JavaScript’s String.prototype.replace() which interprets $& as a backreference to the matched substring. The filter only charges memoryLimit for the...HighCWE-400LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process CrashLiquidJS’s memoryLimit security mechanism can be completely bypassed by using reverse range expressions (e.g., (100000000..1)), allowing an attacker to allocate unlimited memory. Combined with a...HighCWE-400jsrsasign: Division by Zero Allows Invalid JWK Modulus to Cause Deterministic Zero Output in RSA OperationsVersions of the package jsrsasign before 11.1.1 are vulnerable to Division by zero due to the RSASetPublic/KEYUTIL parsing path in ext/rsa.js and the BigInteger.modPowInt reduction...LowCWE-369Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable codeA code injection vulnerability in ECMAScriptModuleCompiler allows an attacker to achieve Remote Code Execution (RCE) by injecting arbitrary JavaScript expressions inside export { } declarations...HighCWE-94Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template CompilationWhen a Handlebars template contains decorator syntax referencing an unregistered decorator (e.g. ``), the compiled template calls lookupProperty(decorators, "n"), which returns undefined. The runtime then...HighCWE-754Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partialA crafted object placed in the template context can bypass all conditional guards in resolvePartial() and cause invokePartial() to return undefined. The Handlebars runtime then...HighCWE-94Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and OptionsThe Handlebars CLI precompiler (bin/handlebars / lib/precompiler.js) concatenates user-controlled strings — template file names and several CLI options — directly into the JavaScript it emits,...HighCWE-94NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node## SummaryHighCWE-913Nuxt OG Image vulnerable to Server-Side Request Forgery via user-controlled parametersProduct: Nuxt OG ImageVersion: < 6.2.5CWE-ID: CWE-918: Server-Side Request ForgeryMediumCWE-918Payload has a CSRF Protection Bypass in Authentication FlowA Cross-Site Request Forgery (CSRF) vulnerability existed in the authentication flow. Under certain conditions, the configured CSRF protection could be bypassed, allowing cross-site requests to...MediumCWE-352Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints - @payloadcms/storage-azureThe client-upload signed-URL endpoints for S3, GCS, Azure, and R2 did not properly sanitize filenames. An attacker could craft filenames to escape the intended storage...MediumCWE-22Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints - @payloadcms/storage-gcsThe client-upload signed-URL endpoints for S3, GCS, Azure, and R2 did not properly sanitize filenames. An attacker could craft filenames to escape the intended storage...MediumCWE-22Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints - @payloadcms/storage-r2The client-upload signed-URL endpoints for S3, GCS, Azure, and R2 did not properly sanitize filenames. An attacker could craft filenames to escape the intended storage...MediumCWE-22Payload has Insufficient Filename Validation in Client-Upload Signed-URL EndpointsThe client-upload signed-URL endpoints for S3, GCS, Azure, and R2 did not properly sanitize filenames. An attacker could craft filenames to escape the intended storage...MediumCWE-22lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - lodash-amdLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for CVE-2025-13465 only guards against string key...MediumCWE-1321lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - lodash-esLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for CVE-2025-13465 only guards against string key...MediumCWE-1321lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - lodash.unsetLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for CVE-2025-13465 only guards against string key...MediumCWE-1321lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for CVE-2025-13465 only guards against string key...MediumCWE-1321lodash vulnerable to Code Injection via `_.template` imports key names - lodash-amdThe fix for CVE-2021-23337 added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths...HighCWE-94lodash vulnerable to Code Injection via `_.template` imports key names - lodash-esThe fix for CVE-2021-23337 added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths...HighCWE-94lodash vulnerable to Code Injection via `_.template` imports key namesThe fix for CVE-2021-23337 added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths...HighCWE-94Axios supply chain attack - dependency in @lightdash/cli may resolve to compromised axios versionsA supply chain attack on the axios npm package (versions 1.14.1 and 0.30.4) introduced a malicious transitive dependency ([email protected]) that deploys a cross-platform remote access...HighCWE-508Nuxt OG Image is vulnerable to Denial of Service via unbounded image dimensionsProduct: Nuxt OG Image Version: 6.1.2CWE-ID: CWE-404: Improper Resource Shutdown or ReleaseDescription: Failure to limit the length and width of the generated image results in...MediumCWE-404Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributesProduct: Nuxt OG Image Version: 6.1.2CWE-ID: CWE-79: Improper Neutralization of Input During Web Page GenerationDescription: Incorrect parsing of GET parameters leads to the possibility of...MediumCWE-79@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary filesA Path Traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the...HighCWE-73Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host - @clerk/honoThe clerkFrontendApiProxy function in @clerk/backend is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can craft a request path that causes the proxy to...HighCWE-918Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended hostThe clerkFrontendApiProxy function in @clerk/backend is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can craft a request path that causes the proxy to...HighCWE-918@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions@tinacms/cli recently added lexical path-traversal checks to the dev media routes, but the implementation still validates only the path string and does not resolve symlink...HighCWE-59@tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions@tinacms/graphql uses string-based path containment checks in FilesystemBridge:HighCWE-59Payload has an SQL Injection via Query HandlingCertain request inputs were not properly validated. An attacker could craft requests that influence SQL query execution, potentially exposing or modifying data in collections.HighCWE-89@payloadcms/next has Stored XSS in Admin PanelA stored Cross-site Scripting (XSS) vulnerability existed in the admin panel. An authenticated user with write access to a collection could save content that, when...HighCWE-79Payload has Authenticated SSRF via Upload FunctionalityAn authenticated Server-Side Request Forgery (SSRF) vulnerability existed in the upload functionality.HighCWE-918SillyTavern: Path Traversal allows file existence oracleA path traversal vulnerability in the static file route handler allows any unauthenticated user to determine whether files exist anywhere on the server’s filesystem. By...MediumCWE-22SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within userA Path Traversal vulnerability in chat endpoints allows an authenticated attacker to read and delete arbitrary files under their user data root (for example secrets.json...HighCWE-22SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directoryA path traversal vulnerability in /api/chats/import allows an authenticated attacker to write attacker-controlled files outside the intended chats directory by injecting traversal sequences into character_name....HighCWE-73SillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and IPv6Distinct from CVE-2025-59159 and CVE-2026-26286 (all fixed in v1.16.0). This endpoint is still unpatched.MediumCWE-918dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configurationA stored XSS vulnerability exists in DbGate because attacker-controlled SVG icon strings are rendered as raw HTML without sanitization.HighCWE-94@elgentos/magento2-dev-mcp vulnerable to command injectionA vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/index.ts. Such manipulation leads to...LowCWE-77@stablelib/cbor: Stack exhaustion Denial of Service via deeply nested CBOR arrays, maps, or tags@stablelib/cbor decodes nested CBOR structures recursively and does not enforce a maximum nesting depth. A sufficiently deep attacker-controlled CBOR payload can therefore crash decoding with...HighCWE-674@stablelib/cbor: Prototype poisoning via `__proto__` map keys in CBOR decoding@stablelib/cbor decodes CBOR maps into ordinary JavaScript objects and assigns attacker-controlled keys directly onto those objects. A CBOR map key named __proto__ therefore changes the...HighCWE-1321StableLib Ed25519 Signature Malleability via Missing S < L CheckNo description available.MediumCWE-347RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requestsSummaryHighCWE-352Drizzle ORM has SQL injection via improperly escaped SQL identifiersDrizzle ORM improperly escaped quoted SQL identifiers in its dialect-specific escapeName() implementations. In affected versions, embedded identifier delimiters were not escaped before the identifier was...HighCWE-89@delmaredigital/payload-puc is missing authorization on /api/puck/* CRUD endpoints allows unauthenticated access to PuckAll /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload’s local API with the default overrideAccess: true, bypassing all collection-level access control. The access option...HighCWE-862x402 SDK Security AdvisoryA security vulnerability exists in outdated versions of the x402 SDK.HighPayload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery - payloadA vulnerability in the password recovery flow could allow an unauthenticated attacker to perform actions on behalf of a user who initiates a password reset....HighCWE-640Payload: Pre-Authentication Account Takeover via Parameter Injection in Password RecoveryA vulnerability in the password recovery flow could allow an unauthenticated attacker to perform actions on behalf of a user who initiates a password reset....HighCWE-640Pretext: Algorithmic Complexity (DoS) in the text analysis phaseisRepeatedSingleCharRun() in src/analysis.ts (line 285) re-scans the entire accumulated segment on every merge iteration during text analysis, producing O(n²) total work for input consisting of...HighCWE-407Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parserThe DocTypeReader in fast-xml-parser uses JavaScript truthy checks to evaluate maxEntityCount and maxEntitySize configuration limits.MediumCWE-1284LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` FilterThe replace filter in LiquidJS incorrectly accounts for memory usage when the memoryLimit option is enabled. It charges str.length + pattern.length + replacement.length bytes to...LowCWE-400LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` headerThe webapi authentication layer trusts a client-controlled X-lobe-chat-auth header that is only XOR-obfuscated, not signed or otherwise authenticated. Because the XOR key is hardcoded in...MediumCWE-345LiquidJS: ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting sidThe sort_natural filter bypasses the ownPropertyOnly security option, allowing template authors to extract values of prototype-inherited properties through a sorting side-channel attack. Applications relying on...MediumCWE-200LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file readliquidjs 10.25.0 documents root as constraining filenames passed to renderFile() and parseFile(), but top-level file loads do not enforce that boundary.MediumCWE-22Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()##EVIDENCEMediumCWE-184Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network AccessDescription:Flowise exposes an HTTP Node in AgentFlow and Chatflow that performs server-side HTTP requests using user-controlled URLs. By default, there are no restrictions on target...HighCWE-918Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory readTwo unauthenticated path traversal vulnerabilities exist in Saltcorn’s mobile sync endpoints. The POST /sync/offline_changes endpoint allows an unauthenticated attacker to create arbitrary directories and write...HighCWE-22@saltcorn/data vulnerable to SQL Injection via jsexprToSQL Literal HandlerThe jsexprToSQL() function in Saltcorn converts JavaScript expressions to SQL for use in database constraints. The Literal handler wraps string values in single quotes without...LowCWE-89Quill is vulnerable to XSS via HTML export featureA lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS).LowCWE-79@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypassUnder certain circumstances, requests could bypass the BODY_SIZE_LIMIT on SvelteKit applications running with adapter-node. This bypass does not affect body size limits at other layers...HighCWE-770@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Serviceredirect, when called from inside the handle server hook with a location parameter containing characters that are invalid in a HTTP header, will cause an...MediumCWE-755Zod jsVideoUrlParser vulnerable to ReDoS in util.jsA weakness has been identified in Zod jsVideoUrlParser up to 0.5.1. The impacted element is the function getTime in the library lib/util.js. This manipulation of...MediumCWE-400LiquidJS: Root restriction bypass for partial and layout loading through symlinked templatesLiquidJS enforces partial and layout root restrictions using the resolved pathname string, but it does not resolve the canonical filesystem path before opening the file....HighCWE-61LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set(Severity: Medium (CVSS ~5.6)Status: Fixed in 0.5.18MediumCWE-1321unhead: Streaming SSR `streamKey` injected into inline script without identifier validationcreateStreamableHead({ streamKey }) interpolated its streamKey argument directly into the streaming SSR bootstrap and suspense-chunk inline scripts without identifier validation or escaping. If an application...LowCWE-79DbGate has cross site scripting via the SVG Icon String Handler componentA security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon...LowCWE-79MCPHub has an authentication bypassMCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in...MediumCWE-639Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRFAxios does not correctly handle hostname normalization when checking NO_PROXY rules.Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip...MediumCWE-918sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags ElementsCommit 49d0bb7 introduced a regression in sanitize-html that bypasses allowedTags enforcement for text inside nonTextTagsArray elements (textarea and option). Entity-encoded HTML inside these elements passes...MediumCWE-79Flowise: Authenticated RCE Via MCP AdaptersDue to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command, achieving...HighCWE-78Flowise: Path Traversal in Vector Store basePathThe Faiss and SimpleStore (LlamaIndex) vector store implementations accept a basePath parameter from user-controlled input and pass it directly to filesystem write operations without any...MediumCWE-22Flowise Execute Flow function has an SSRF vulnerabilityThe attacker provides an intranet address through the base url field configured in the Execute Flow node → Bypass checkDenyList / resolveAndValidate in httpSecurity.ts (not...MediumCWE-918Paperclip: Arbitrary File Read via Agent-Controlled adapterConfig.instructionsFilePathPaperclip contains an arbitrary file read vulnerability that allows an attacker with an Agent API key to read files from the Paperclip server host filesystem.The...MediumCWE-73Paperclip: Stored XSS via javascript: URLs in MarkdownBody — urlTransform override disables react-markdown sanitizationMarkdownBody, the shared component used to render every Markdown surface in the Paperclip UI (issue documents, issue comments, chat threads, approvals, agent details, export previews,...MediumCWE-79Cross-site Scripting (XSS) in serialize-javascriptA flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript...MediumCWE-79@saltcorn/data: Tenant user role is used for tenant creation role checkWhen a tenant admin is logged out of the root domain (e.g., saltcorn.com) but logged in to their own tenant space as admin, they can...HighCWE-863Deep Merge is Vulnerable to Prototype Pollution Through Lack of SanitizationA Prototype Pollution vulnerability was determined in brikcss merge up to 1.3.0. Executing a manipulation of the argument proto/constructor.prototype/prototype can lead to improperly controlled modification...MediumCWE-94PostCSS has XSS via Unescaped </style> in its CSS Stringify OutputNo description available.MediumCWE-79Flowise: Cypher Injection in GraphCypherQAChainThe GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attacker can inject arbitrary Cypher commands that are...HighCWE-943Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsingShowdownjs, versions <= 2.1.0, anchors subparser used to parse links has a nested regular expression which can lead to denial of service conditions given malicious...MediumCWE-777Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering) - @excalidraw/mermaid-to-excalidraw@excalidraw/[email protected] depends on a Mermaid conversion package version that resolves to a Mermaid release affected by CVE-2025-54881 / GHSA-7rqq-prvp-x9jh. User-supplied Mermaid sequence diagram labels could...MediumCWE-79Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering)@excalidraw/[email protected] depends on a Mermaid conversion package version that resolves to a Mermaid release affected by CVE-2025-54881 / GHSA-7rqq-prvp-x9jh. User-supplied Mermaid sequence diagram labels could...MediumCWE-79Flowise: Code Injection in CSVAgent leads to Authenticated RCEThe CSVAgent allows providing a custom Pandas CSV read code. Due to lack of sanitization, an attacker can provide the following payload: DataFrame({'foo': ['bar!']});import os;os.system('whoami')...HighCWE-94Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `PandasNo description available.HighCWE-94Immutable is vulnerable to Prototype PollutionA Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs.HighCWE-1321LangSmith SDK: Streaming token events bypass output redactionThe LangSmith SDK’s output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces streaming...MediumCWE-532Flowise: Airtable_Agent Code Injection Remote Code Execution VulnerabilityZDI-CAN-29412: FlowiseAI Flowise Airtable_Agent Code Injection Remote Code Execution VulnerabilityHighCWE-77Flowise: Parameter Override Bypass Remote Command ExecutionFlowise is vulnerable to a critical unauthenticated remote command execution (RCE) vulnerability. It can be exploited via a parameter override bypass using the FILE-STORAGE:: keyword...HighCWE-20Flowise: APIChain Prompt Injection SSRF in GET/POST API ChainsA Server-Side Request Forgery (SSRF) vulnerability exists in FlowiseAI’s POST/GET API Chain components that allows unauthenticated attackers to force the server to make arbitrary HTTP...HighCWE-918Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)The core security wrappers (secureAxiosRequest and secureFetch) intended to prevent Server-Side Request Forgery (SSRF) contain multiple logic flaws. These flaws allow attackers to bypass the...HighCWE-918xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion - xmldom@xmldom/xmldom allows attacker-controlled strings containing the CDATA terminator ]]> to be inserted into a CDATASection node. During serialization, XMLSerializer emitted the CDATA content verbatim without...HighCWE-91xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion@xmldom/xmldom allows attacker-controlled strings containing the CDATA terminator ]]> to be inserted into a CDATASection node. During serialization, XMLSerializer emitted the CDATA content verbatim without...HighCWE-91Official Clerk JavaScript SDKs: Middleware-based route protection bypass - @clerk/astrocreateRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers.HighCWE-863Official Clerk JavaScript SDKs: Middleware-based route protection bypass - @clerk/nextjscreateRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers.HighCWE-863Official Clerk JavaScript SDKs: Middleware-based route protection bypass - @clerk/sharedcreateRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers.HighCWE-863Official Clerk JavaScript SDKs: Middleware-based route protection bypasscreateRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers.HighCWE-863Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function SandboxA Server-Side Request Forgery (SSRF) protection bypass vulnerability exists in the Custom Function feature. While the application implements SSRF protection via HTTP_DENY_LIST for axios and...HighCWE-918Saltcorn: SQL Injection via Unparameterized Sync Endpoints (maxLoadedId)A critical SQL injection vulnerability in Saltcorn’s mobile-sync routes allows any authenticated low-privilege user with read access to at least one table to inject arbitrary...HighCWE-89Flowise: CSV Agent Prompt Injection Remote Code Execution VulnerabilityTrend Micro’s Zero Day Initiative has identified a vulnerability affecting FlowiseAI Flowise.HighCWE-184Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4)The fetch() call for remote images in packages/integrations/cloudflare/src/utils/image-binding-transform.ts (line 28) uses the default redirect: 'follow' behavior. This allows the Cloudflare Worker to follow HTTP redirects...LowCWE-918Axios HTTP/2 Session Cleanup State Corruption VulnerabilityAxios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. This...MediumCWE-400Unsafe object property setter in mathjsThis security vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can...HighCWE-915Marked Vulnerable to OOM Denial of Service via Infinite Recursion in marked TokenizerA critical Denial of Service (DoS) vulnerability exists in [email protected]. By providing a specific 3-byte input sequence a tab, a vertical tab, and a newline...HighCWE-835copilot-api has Reliance on Reverse DNS Resolution for a Security-Critical ActionA vulnerability was determined in ericc-ch copilot-api up to 0.7.0. This impacts an unknown function of the file /token of the component Header Handler. Executing...LowCWE-350Arbitrary code execution in protobufjsprotobufjs could execute generated JavaScript code derived from protobuf schema metadata. When loading a crafted JSON descriptor, schema-controlled type names and type references could reach...HighCWE-94Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParamsNo description available.LowCWE-626Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`No description available.MediumCWE-915Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Ax1. Executive SummaryThis report documents an incomplete security patch for the previously disclosed vulnerability GHSA-3p68-rc4w-qgx5 (CVE-2025-62718), which affects the NO_PROXY hostname resolution logic in the...HighCWE-918Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge StrategyNo description available.MediumCWE-287Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean CoercionNo description available.MediumCWE-201Axios: Header Injection via Prototype PollutionA prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP headers into outgoing requests. The vulnerability...HighCWE-1321Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request HijackingWhen Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify...HighCWE-1321Axios: HTTP adapter streamed responses bypass maxContentLengthWhen responseType: ‘stream’ is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured response-size limits and allows unbounded downstream consumption.MediumCWE-770Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0For stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when...MediumCWE-770Axios: no_proxy bypass via IP alias allows SSRFThe fix for no_proxy hostname normalization bypass (#10661) is incomplete.When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route through the proxy instead of...MediumCWE-918Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStreamThe FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into the Content-Type header of each multipart part without sanitizing CRLF (\r\n) sequences. An attacker who controls...MediumCWE-93auth-js Vulnerable to Insecure Path Routing from Malformed User InputThe library functions getUserById, deleteUser, updateUserById, listFactors and deleteFactor did not require the user supplied values to be valid UUIDs. This could lead to a...LowCWE-22@tdurieux/anonymous_github Vulnerable to XSS via Unsanitized GitHub Repository Content Rendering in Anonymous GitHub OriAnonymous GitHub fetches repository content (e.g., markdown files) from GitHub’s API and renders it without sanitization. On the client side, markdown is parsed with marked...HighCWE-80MCPHub has Path Traversal via Malicious MCPB Manifest NameMCPB File Upload Handler extracts a ZIP file and reads manifest.json from it. The name field in the manifest is directly concatenated into a file...HighCWE-22Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attackIn simple words, some programs that use _.flatten or _.isEqual could be made to crash. Someone who wants to do harm may be able to...HighCWE-770mcp-data-vis vulnerable to denial of service via unsanitized `select` key lookup on `Object.prototype` with `precompile:icu-minify’s runtime formatter resolves select branches by looking up the runtime value as a plain property on a prototype-bearing object. When the value coerces to...LowCWE-1321BigSweetPotatoStudio HyperChat has a Server-Side Request Forgery issueA vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the function fetch of the file packages/core/src/http/aiProxyMiddleware.mts of the component...MediumCWE-918CyberChef has a Cross-site Scripting issueGCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets(‘%3Cscript substring.HighCWE-79@diplodoc/search-extension allows stored XSS via Markdown file title@diplodoc/search-extension 1.0.0 through 3.0.2 allows stored XSS via .md file title.MediumCWE-79Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfigNo description available.HighCWE-754Electerm runWidget has a path traversal that leads to arbitrary code executionThe runWidget function in src/app/widgets/load-widget.js constructs a file path by directly concatenating user‑supplied widget identifiers without any sanitisation:HighCWE-829Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link clickElecterm’s terminal hyperlink handler passes any URL clicked in the terminal directly to shell.openExternal without any protocol validation.HighCWE-88Electerm's full process.env exposed to renderer via window.pre.envThe getConstants() IPC handler in src/app/lib/ipc-sync.js serialises the entire process.env object and sends it to the renderer. The data is stored as window.pre.env and is...MediumCWE-312Electerm Security Vulnerability: RCE via malicious SSH server filename in openFileWithEditorA code execution (RCE) vulnerability exists in electerm’s SFTP open with system editor or “Edit with custom editor” feature. When a user opts to edit...HighCWE-88Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSSA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with...HighCWE-79@nocobase/database has SQL Injection via String Concatenation through Recursive Eager LoadingThe queryParentSQL() function in the core database package constructs a recursive CTE query by joining nodeIds with string concatenation instead of using parameterized queries. The...HighCWE-89mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object AttributesThis security vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can...HighCWE-915xmldom has XML node injection through unvalidated comment serialization - xmldomThe package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment breaking sequences. As a result, an attacker can terminate...HighCWE-91xmldom has XML node injection through unvalidated comment serializationThe package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment breaking sequences. As a result, an attacker can terminate...HighCWE-91xmldom has XML node injection through unvalidated processing instruction serialization - xmldomThe package allows attacker-controlled processing instruction data to be serialized into XML without validating or neutralizing the PI-closing sequence ?>. As a result, an attacker...HighCWE-91xmldom has XML node injection through unvalidated processing instruction serializationThe package allows attacker-controlled processing instruction data to be serialized into XML without validating or neutralizing the PI-closing sequence ?>. As a result, an attacker...HighCWE-91xmldom has XML injection through unvalidated DocumentType serialization - xmldomThe package serializes DocumentType node fields (internalSubset, publicId, systemId) verbatimwithout any escaping or validation. When these fields are set programmatically to attacker-controlledstrings, XMLSerializer.serializeToString can produce...HighCWE-91xmldom has XML injection through unvalidated DocumentType serializationThe package serializes DocumentType node fields (internalSubset, publicId, systemId) verbatimwithout any escaping or validation. When these fields are set programmatically to attacker-controlledstrings, XMLSerializer.serializeToString can produce...HighCWE-91xmldom: Uncontrolled recursion in XML serialization leads to DoS - xmldomSeven recursive traversals in lib/dom.js operate without a depth limit. A sufficiently deeplynested DOM tree causes a RangeError: Maximum call stack size exceeded, crashing the...HighCWE-674xmldom: Uncontrolled recursion in XML serialization leads to DoSSeven recursive traversals in lib/dom.js operate without a depth limit. A sufficiently deeplynested DOM tree causes a RangeError: Maximum call stack size exceeded, crashing the...HighCWE-674fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped DelimitersNo description available.MediumCWE-91Saltcorn: Open Redirect in `POST /auth/login` due to incomplete `is_relative_url` validation (backslash bypass)Saltcorn validates the post-login dest parameter with a string check that only blocks :/ and //. Because all WHATWG-compliant browsers normalise backslashes (\) to forward...MediumCWE-601i18next-http-backend has Path Traversal & URL Injection via Unsanitised lng/nsVersions of i18next-http-backend prior to 3.0.5 interpolate the lng and ns values directly into the configured loadPath / addPath URL template without any encoding, validation,...MediumCWE-74i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributesVersions of i18nextify prior to 4.0.8 substitute `` interpolation tokens inside src and href attribute values with the raw string returned by i18next.t(). The substitution...MediumCWE-94Inngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTTP methodsA vulnerability in the Inngest TypeScript SDK versions 3.22.0 through 3.53.1 allows unauthenticated remote attackers to exfiltrate environment variables from the host process via the...HighCWE-497electerm: electerm_install_script_CommandInjection Vulnerability ReportCommand Injection vulnerabilities in electerm:HighCWE-77OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution EnvironmentA critical Remote Code Execution (RCE) vulnerability was identified in the OpenLearnX code execution environment, allowing sandbox escape and arbitrary command execution. The issue has...HighCWE-94FUXA has a hardcoded fallback JWT signing secretFUXA used a static fallback JWT signing secret (frangoteam751) when no secretCode was configured.HighCWE-798electerm has Command Injection via runLinux funtionCommand Injection vulnerabilities in electerm:HighCWE-77Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijackingFive config properties in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype...HighCWE-1321protobuf.js: Code injection through bytes field defaults in generated toObject codeprotobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string...HighCWE-94query-parser-string is vulnerable to Prototype PollutionNPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly...HighCWE-1321youtube-regex vulnerable to Regex Denial of ServiceRegex Denial of Service in youtube-regex npm package through version 1.0.5.HighCWE-400SillyTavern has a Path Traversal issuePOST /api/extensions/delete endpoint accepts extensionName: "." which bypasses sanitize-filename validation, causing the entire user extensions directory to be recursively deleted. No authentication is required in...HighCWE-22Marko: XSS via case-insensitive script/style closing tag bypass in runtime HTML escaping - markoWhen dynamic text is interpolated into a <script> or <style> tag the Marko runtime failed to prevent tag breakout when the closing tag used non-lowercase...MediumCWE-79Marko: XSS via case-insensitive script/style closing tag bypass in runtime HTML escapingWhen dynamic text is interpolated into a <script> or <style> tag the Marko runtime failed to prevent tag breakout when the closing tag used non-lowercase...MediumCWE-79i18next-locize-backend has URL Injection via Unsanitized Path ParametersVersions of i18next-locize-backend prior to 9.0.2 interpolate lng, ns, projectId, and version directly into the configured loadPath / privatePath / addPath / updatePath / getLanguagesPath...MediumCWE-74locize Client SDK: Cross-origin DOM XSS & Handler Hijack Through Missing e.origin Validation in InContext EditorVersions of the locize client SDK (the browser module that wires up the locize InContext translation editor) prior to 4.0.21 register a window.addEventListener("message", …) handler...HighCWE-79Electerm users can run dangrous code through link or command lineNo description available.HighCWE-94RedwoodSDK has Same-site CSRF through lack of origin validation in its server actionsServer actions in rwsdk apply HTTP method enforcement but no origin validation. A request originating from a different origin that the browser treats as same-site...MediumCWE-352liquidjs has a Denial of Service via circular block reference in layoutA circular block reference in {% layout %} / {% block %} causes an infinite recursive loop, consuming all available memory (~4GB) and crashing the...HighCWE-674Angular Expressions - Remote Code Execution using filtersAn attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the system.HighCWE-95Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)Flowise introduced SSRF protections through a centralized HTTP security wrapper (httpSecurity.ts) that implements deny-list validation and IP pinning logic.MediumCWE-918@workos/authkit-session has an Open Redirect via state-derived redirect targetAn open redirect vulnerability exists in AuthService.handleCallback due to insufficient validation of the returnPathname value derived from the OAuth state parameter.MediumCWE-601link-preview-js vulnerable to IPv6 and internal loopback attacksThe library did not check for IPv6 loopback attacks. There was also a DNS attack, where an address could be resolved into an internal IP....HighCWE-918PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDFIf pdf.js is used to load a malicious PDF, and PDF.js is configured with isEvalSupported set to true (which is the default value), unrestricted attacker-controlled...HighCWE-754LobeHub has a Cross-Site Scripting issue that escalates to Remote Code ExecutionThe vulnerability was automatically discovered by an ai agent and then manually verified.MediumCWE-79Karakeep SDK has SSRF via metascraper-logo-favicon that bypasses validateUrl protectionsThe metascraper-logo-favicon plugin makes HTTP requests to URLs extracted from attacker-controlled HTML without going through the application’s validateUrl() SSRF protections. This allows any authenticated user...HighCWE-918Svelte: SSR XSS via Insecure Promise Serialization in hydratableContents of hydratable promises were not properly stringified, potentially leading to an XSS exploit. You are vulnerable if all of the following is true: you...MediumCWE-79protobuf.js: Denial of service through unbounded protobuf recursionprotobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message...HighCWE-674protobufjs has overlong UTF-8 decoding - @protobufjs/utf8protobufjs includes a minimal UTF-8 decoder used in non-Node and fallback decoding paths. The affected decoder accepted overlong UTF-8 byte sequences and decoded them to...MediumCWE-176protobufjs has overlong UTF-8 decodingprotobufjs includes a minimal UTF-8 decoder used in non-Node and fallback decoding paths. The affected decoder accepted overlong UTF-8 byte sequences and decoded them to...MediumCWE-176protobuf.js: Process-wide denial of service through unsafe option pathsprotobufjs allowed certain schema option paths to traverse through inherited object properties while applying options. A crafted protobuf schema or JSON descriptor could cause option...HighCWE-1321protobuf.js: Code generation gadget after prototype pollutionprotobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If Object.prototype had already been polluted,...HighCWE-94protobuf.js: Prototype injection in generated message constructorsprotobufjs generated message constructors copied enumerable properties from a provided properties object without filtering the __proto__ key. If an application constructed a message from an...MediumCWE-1321protobuf.js: Denial of service from crafted field names in generated codeprotobufjs generated JavaScript property accessors from schema-controlled field and oneof names. Certain control characters in field names were not escaped before being embedded into generated...MediumCWE-20NocoBase has SSRF in Workflow HTTP Request and Custom Request PluginsNocoBase’s workflow HTTP request plugin and custom request action plugin make server-side HTTP requests to user-provided URLs without any SSRF protection. An authenticated user can...MediumCWE-918Nitro has a proxy scope bypass via percent-encoded path traversal in `routeRules` - nitroA proxy route rule like:MediumCWE-22Nitro has a proxy scope bypass via percent-encoded path traversal in `routeRules`A proxy route rule like:MediumCWE-22@samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User ImpersonA critical identity spoofing vulnerability in MCPHub allows any unauthenticated user to impersonate any other user — including administrators — on SSE (Server-Sent Events) and...HighCWE-290Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks - @backstage/plugin-catalog-unprocessed-entities-commonThe unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This...MediumCWE-863Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checksThe unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This...MediumCWE-863Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keyingNo description available.MediumCWE-307Strapi: Password Reset Does Not Revoke Existing Refresh Sessions - @strapi/plugin-users-permissionsNo description available.LowCWE-613Strapi: Password Reset Does Not Revoke Existing Refresh SessionsNo description available.LowCWE-613nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)The isBlockedUrl() denylist introduced in [email protected] to remediate GHSA-pqhr-mp3f-hrpp (Dmitry Prokhorov / Positive Technologies, March 2026) is incomplete.LowCWE-918Flowise has an MCP Security Bypass that Enables RCEThere are three bypass methods for the security limitations of the Flowise MCP feature, and attackers can execute arbitrary commands by combining these three methods...HighCWE-184open-webui Vulnerable to Stored XSS via Model Description[!IMPORTANT] Relationship to CVE-2024-7990HighCWE-79Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code ExThe tool update endpoint (POST /api/v1/tools/id/{id}/update) is missing the workspace.tools permission check that is present on the tool create endpoint.HighCWE-862Sveltia CMS: Stored XSS in entry summary rendering via entity-decoded HTMLA stored cross-site scripting (XSS) vulnerability affected entry summary rendering in Sveltia CMS.LowCWE-79automagik-genie has a command injection vulnerabilityCommand injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka view) in the readTranscriptFromCommit function in dist/mcp/server.js...HighCWE-78@tmlmobilidade/utils has prototype pollution in its setValueAtPathPrototype pollution vulnerability in @tmlmobilidade/utils for setValueAtPath().HighCWE-1321Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp - @mistralai/mistralai-azureMistral npm @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp were compromised by a supply chain attack related to the TanStack security incident. An automated worm associated with the attack...LowCWE-506Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp - @mistralai/mistralaiMistral npm @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp were compromised by a supply chain attack related to the TanStack security incident. An automated worm associated with the attack...LowCWE-506Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcpMistral npm @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp were compromised by a supply chain attack related to the TanStack security incident. An automated worm associated with the attack...LowCWE-506Open WebUI Has Stored Cross-Site Scripting in SVG RendererThere is a Cross-Site Scripting vulnerability in Open WebUI SVG renderer implementation.MediumCWE-80Open WebUI has Stored XSS in Banner Component via Improper Sanitization OrderA Stored Cross-Site Scripting (XSS) vulnerability exists in the Banner component due to an improper sanitization order (specifically, DOMPurify is executed before the marked library)....HighCWE-79protobufjs: Denial of Service via unbounded recursive JSON descriptor expansionprotobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.fromJSON() and Namespace.addJSON().MediumCWE-674PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCEThe MCP module’s ReplServer binds to all interfaces (0.0.0.0:4403) and exposes a /execute endpoint that runs arbitrary code with zero authentication. Anyone on the network...HighCWE-749Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection ChainNo description available.MediumCWE-918seroval affected by Denial of Service via RegExp serializationOverriding RegExp serialization with extremely large patterns can exhaust JavaScript runtime memory during deserialization. Additionally, overriding RegExp serialization with patterns that trigger catastrophic backtracking can...HighCWE-1333electerm allows unauthorized users to execute arbitrary commandsAn issue was discovered in Electerm 1.3.22, allows attackers to execute arbitrary commands via unverified request to electerms service.HighCWE-78Strapi may leak sensitive data via relational filtering due to lack of query sanitizationNo description available.HighCWE-943@tootallnate/once vulnerable to Incorrect Control Flow ScopingVersions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains...LowCWE-705uuid: Missing buffer bounds check in v3/v5/v6 when buf is providedThe v3(), v5(), and v6() API methods (not uuid release versions) accept external output buffers but do not reject out-of-range writes (small buf or large...MediumCWE-787Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objectsWhat kind of vulnerability is it?MediumCWE-834@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnPropertyThe _copyProps function in lib/src/object/copy.ts uses for…in to iterate over source object properties without an Object.hasOwnProperty check, and does not filter dangerous keys (proto, constructor,...HighCWE-1321CryptPad has a Sanitizer Bypass in Diffmarked.js that Allows Arbitrary HTML Injection and Potential XSSCryptPad’s HTML sanitizer in Diffmarked.js can be bypassed due to incomplete filtering of restricted tags.Because the sanitizer only validates the src attribute of <iframe> <video>,...MediumCWE-79FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration InjectionPre-auth RCE in FUXA via Logic BypassHighCWE-94LiquidJS is Vulnerable to Remote Code ExecutionIt is possible to execute arbitrary code with crafted templatesHighCWE-94@kilocode/cli Vulnerable to Exposure of Sensitive Information to an Unauthorized ActorA flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of the component Environment...LowCWE-200@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issueA vulnerability was determined in Vercel AI up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils....LowCWE-400AgenticMail API/storage and outbound relay hardening fixesThe current upstream main branch at commit 7e0206d was reviewed, and the fix-first patch set was rebased on 2026-05-18.HighCWE-89Bootstrap Vulnerable to Cross-Site Scripting - bootstrapVersions of bootstrap prior to 3.4.1 for 3.x and 4.3.1 for 4.x are vulnerable to Cross-Site Scripting (XSS). The data-template attribute of the tooltip and...MediumCWE-79Bootstrap Vulnerable to Cross-Site ScriptingVersions of bootstrap prior to 3.4.1 for 3.x and 4.3.1 for 4.x are vulnerable to Cross-Site Scripting (XSS). The data-template attribute of the tooltip and...MediumCWE-79React Router vulnerable to DoS via unbounded path expansion in __manifest endpointThere exists a potential DOS attack vector in React Router Framework Mode applications (as well as Remix v2.10.0 - 2.17.4). Certain requests can be crafted...HighCWE-400React Router vulnerable to Denial of Service via reflected user input in single-fetchA DoS vulnerability exists in the React Router v7 Framework Mode, as well as Remix v2.9.0+ with Single Fetch enabled. In some scenarios the underlying...HighCWE-770DbGate: Unauthenticated Remote Code Execution via JSON Script RunnerDbGate’s JSON script runner (POST /runners/start) allows remote code execution via code injection in the functionName parameter of JSON script assign commands. The functionName value...HighCWE-94DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCEThe unzipDirectory() function in packages/api/src/shell/unzipDirectory.js (line 27) does not validate that extracted file paths stay within the output directory. A malicious ZIP with ../ entries...HighCWE-22Authenticated Remote Code Execution via loadReader functionName code injection in DbGateDbGate is vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an...HighCWE-78TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGsTinyMCE 6.8.x contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute...HighCWE-79Insufficient Entropy in cryptilesVersions of cryptiles prior to 4.1.2 are vulnerable to Insufficient Entropy. The randomDigits() method does not provide sufficient entropy and its generates digits that are...HighCWE-331Axios: unbounded recursion in toFormData causes DoS via deeply nested request datatoFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError....MediumCWE-674TeleJSON: DOM XSS via unsanitised constructor name in `new Function()`telejson versions prior to 6.0.0 (released 2022) are vulnerable to DOM-based Cross-Site Scripting (XSS) through unsafe deserialisation. Attacker-controlled input from the _constructor-name_ property in parsed...LowCWE-79MagicMirror vulnerable to unauthenticated SSRF via /cors endpointAn unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the /cors endpoint allows any remote attacker to force the MagicMirror² server to perform arbitrary HTTP requests...HighCWE-918Bootstrap Cross-site Scripting vulnerability - bootstrap - GHSA-7mvr-5x2g-wfc8In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar...MediumCWE-79Bootstrap Cross-site Scripting vulnerability - bootstrap-sassIn Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar...MediumCWE-79Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injectionThe state diagram and any other diagram type that routes user-controlled style strings through createCssStyles parser for Mermaid v11.14.0 and earlier captures classDef values with...MediumCWE-94Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injectionUnder the default configuration, Mermaid state diagram’s classDef allow DOM injection that escapes the SVG, although <script> tags are removed, preventing XSS.MediumCWE-94@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious inputUsing Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code.HighCWE-94Velocity.js has a Prototype Pollution vulnerability through #set path assignmentA prototype pollution vulnerability was discovered in Velocity.js <= 2.1.5. This issue occurs during the processing of #set directives in Velocity templates. If an application...HighCWE-1321Auth.js SDK has Improper Permission CheckingUnder specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is...HighCWE-863Cinny vulnerable to access token disclosure via invalidated emoji pack avatar URL in service workerA remote authenticated attacker who shares a room with a victim and has permissions to create room emotes (for example in a DM) can cause...HighCWE-20@rvf/set-get has a prototype pollution issue that's reachable via @rvf/core preprocessFormData (HTTP form data)setPath in @rvf/set-get (used by @rvf/core to flatten incoming form data into a nested object) does not block the keys __proto__, constructor, or prototype when...HighCWE-1321Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/arktype-adapterOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/eslint-plugin-routerOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/historyOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/react-router-devtoolsOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/react-router-ssr-queryOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/react-routerOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/react-start-clientOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/react-start-rscOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/react-startOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-coreOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-devtools-coreOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-devtoolsOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-generatorOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-pluginOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-ssr-query-coreOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-utilsOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-vite-pluginOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/solid-router-devtoolsOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/solid-router-ssr-queryOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/solid-routerOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/solid-start-clientOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/solid-startOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/start-client-coreOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/start-storage-contextOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/valibot-adapterOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/virtual-file-routesOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/vue-router-devtoolsOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/vue-router-ssr-queryOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/vue-routerOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/vue-start-clientOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/vue-startOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keysOn 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated...HighCWE-506Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()`Kysely 0.28.12 added a sanitizeStringLiteral() call inside DefaultQueryCompiler.visitJSONPathLeg (commit 0a602bf, PR #1727) to fix CVE-2026-32763 (GHSA-wmrf-hv6w-mr66). The fix only doubles single quotes (' → '');...HighCWE-915LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warningThe LangSmith SDK’s prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub....HighCWE-502OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account TakeoverA critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditions. The issue has been fixed.MediumCWE-347Nitro has an Open Redirect via Protocol-Relative URL Bypass in Wildcard Route Rules - nitroA redirect route rule like:MediumCWE-601Nitro has an Open Redirect via Protocol-Relative URL Bypass in Wildcard Route RulesA redirect route rule like:MediumCWE-601Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmarkNo description available.HighCWE-94electerm's encrypt method not safe enoughNo description available.MediumCWE-916@ranfdev/deepobj has a Prototype Pollution vulnerabilityPrototype pollution is possible when property paths contain __proto__/constructor/prototype. The property path must not be exposed as user input.HighCWE-1321form-data-objectizer: Prototype pollution in form-data-objectizer via bracket-notation form keysform-data-objectizer walks bracket-notation form keys (e.g. name[sub]) into nested objects without filtering __proto__, constructor, or prototype. A single HTTP form field whose name starts with...HighCWE-1321Mermaid Gantt Charts are vulnerable to an Infinite Loop DoSMermaid v11.14.0 and earlier are vulnerable to a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates.MediumCWE-835Mermaid: Improper sanitization of configuration leads to CSS injectionMermaid’s default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration options.MediumCWE-94Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypassNeotoma versions starting at v0.6.0 can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token...MediumCWE-306React Router has CSRF issue in Action/Server Action Request ProcessingReact Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side route action handlers in Framework...MediumCWE-352SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeoverChanging a user’s password does not invalidate existing sessions, allowing an attacker with a stolen cookie to retain access even after the victim resets their...HighCWE-613SillyTavern has Authentication Bypass via SSO Header InjectionSillyTavern 1.18.0 now includes a configuration option to limit which IP addresses can authorize using SSO headers, limiting to just loopback addresses by default. A...HighCWE-807SillyTavern has a reflected XSS vulnerability in the CORS proxy middlewareFixed in SillyTavern 1.18.0: a user-provided URL is no longer reflected in the HTTP response body.MediumCWE-79SillyTavern has a SSRF vulnerability in the CORS proxy middlewareSillyTavern 1.18.0 added a generic server-side request filter (Private Request Whitelisting).MediumCWE-918SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrlSillyTavern 1.18.0 added a generic server-side request filter (Private Request Whitelisting).HighCWE-918Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/astrohas(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result...HighCWE-863Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/backendhas(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result...HighCWE-863Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/chrome-extensionhas(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result...HighCWE-863Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/clerk-expohas(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result...HighCWE-863Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/clerk-jshas(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result...HighCWE-863Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/clerk-reacthas(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result...HighCWE-863Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/expohas(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result...HighCWE-863Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/honohas(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result...HighCWE-863Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/nextjshas(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result...HighCWE-863Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/nuxthas(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result...HighCWE-863Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/react-routerhas(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result...HighCWE-863Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/reacthas(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result...HighCWE-863Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/sharedhas(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result...HighCWE-863Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/vuehas(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result...HighCWE-863Clerk has an authorization bypass when combining organization, billing, or reverification checkshas(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result...HighCWE-863Cline Kanban Server has a Cross-Origin WebSocket Hijacking VulnerabilityThe kanban npm package (used by the cline CLI) starts a WebSocket server on 127.0.0.1:3484 with no Origin header validation. Any website a developer visits...HighCWE-306Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions - lodash-amdLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash...MediumCWE-1321Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions - lodash-esLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash...MediumCWE-1321Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions - lodash.unsetLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash...MediumCWE-1321Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functionsLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash...MediumCWE-1321Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution@fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-URL loop detection.HighCWE-770HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apisMultiple functions conduct substring-only matching to validate hostnames to which basic authorization should be sent. An attacker can append the matched substrings to an attacker-controlled...HighCWE-918HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theftA stored cross-site scripting (XSS) vulnerability exists in HAX CMS due to improper sanitization of the <video-player> component.MediumCWE-79Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover - @haxtheweb/video-playerA stored cross-site scripting (XSS) vulnerability exists in HAX CMS due to improper sanitization of <iframe> elements.HighCWE-79Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeoverA stored cross-site scripting (XSS) vulnerability exists in HAX CMS due to improper sanitization of <iframe> elements.HighCWE-79Svelte: ReDoS in `<svelte:element>` Tag ValidationAn internal regex in the Svelte runtime can take exponential time to test in <svelte:element this={tag}></svelte:element>. You are only vulnerable to this if you allow...MediumCWE-1333Svelte devalue: DoS via sparse array deserializationdevalue.parse could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to...HighCWE-770Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework StateSvelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks.MediumCWE-79Svelte SSR vulnerable to cross-site scripting via spread attributesWhen using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled...MediumCWE-79md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)A cross-site scripting (XSS) vulnerability exists in the application’s Markdown rendering logic. When user-supplied Markdown content is rendered, embedded raw HTML—includingHighCWE-87Papra HTTP redirect bypass can lead to SSRF via webhook delivery systemPapra’s webhook delivery system contains an SSRF protection bypass that allows any authenticated organisation member to cause the server to make HTTP requests to internal...LowCWE-918Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name InjectionAxios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name...HighCWE-400Element Call reports full URLs of visited pages to analytics serverElement Call versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when configured to by a posthog key in config.json or by the...HighCWE-200OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / optsThe OpenZeppelin Contracts Wizard generated Hardhat (test/test.ts) and Foundry (test/<Name>.t.sol) example test files that interpolated user-supplied strings (opts.name, opts.uri) into the test source without escaping....HighCWE-94@cyntler/react-doc-viewer's TXTRenderer fails to sanitize file content and explicitly casts raw data as a ReactNodeCross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanitize...MediumCWE-79JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injectionjs-cookie’s internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object’s "__proto__" member is...HighCWE-1321Cross-site scripting in Survey CreatorCross Site Scripting (XSS) vulnerability in SurveyJS Survey Creator v.1.9.132 and before, allows attackers to execute arbitrary code and obtain sensitive information via the title...MediumCWE-79wangEditor was discovered to contain a cross-site scripting (XSS) vulnerability via the image upload functionThere is a cross-site scripting (XSS) issue in wangEditor via the image upload function in version 4.7.11. This issue has been fixed in version 4.7.12....MediumLangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state accessA NoSQL injection vulnerability existed in MongoDBSaver where checkpoint identifier fields from config.configurable were used in MongoDB queries without strict type enforcement.MediumCWE-943Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connectionAxios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios...HighCWE-200Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP AdapterAxios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows.HighCWE-201Allocation of Resources Without Limits or Throttling in AxiosAxios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter.HighCWE-770Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype FixNo description available.LowCWE-1321axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functionsaxios 1.15.2 exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process (e.g. lodash _.merge / CVE-2018-16487), axios...MediumCWE-1321axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`No description available.HighCWE-441axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config MergeAxios versions before the fixed releases contain prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse,...HighCWE-94joi has an uncaught RangeError on deeply nested input through recursive `link()` schemasDenial of service via untrapped exception in services validating user-supplied JSON / object input with recursive link schemas.MediumCWE-400esbuild allows arbitrary file read when running the development server on WindowsThe development server contains a path traversal vulnerability on Windows when serving files from servedir.LowCWE-22Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowserThe iOS implementation of cordova-plugin-inappbrowser passes the id field from a WKScriptMessage body to commandDelegate sendPluginResult:callbackId: with no format validation (CDVWKInAppBrowser.m:560–574).HighCWE-20actual Allows Electron to Run As NodeA electron run as node vulnerability was identified in actual (macOS application, version 25.x (Electron 39.2.7)).MediumCWE-94Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`Under the default configuration, sanitize-html can turn attacker-controlled content inside a disallowed xmp element into live HTML or JavaScript. This is a sanitizer bypass in...HighCWE-79React Router: Potential CSRF via PUT/PATCH/DELETE document requestsCertain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE requests.LowCWE-352UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`A regular expression denial-of-service (ReDoS) vulnerability has been discovered in ua-parser-js when using the Client Hints API. By sending a crafted Sec-CH-UA-Model header to an...MediumCWE-400OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagationW3CBaggagePropagator.extract() in @opentelemetry/core does not enforce size limits when parsing inbound baggage HTTP headers. The W3C Baggage specification recommends a maximum of 8,192 bytes and...MediumCWE-770markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operationsA quadratic time complexity vulnerability exists in markdown-it’s smartquotes rule (enabled via the typographer: true option). An attacker can craft a markdown input consisting of...MediumCWE-407@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Re - @nuxt/webpack-builderThis is an incomplete fix for GHSA-6m52-m754-pw2g. Source code may still be stolen during dev when using the webpack / rspack builder if the dev...MediumCWE-749@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and ReThis is an incomplete fix for GHSA-6m52-m754-pw2g. Source code may still be stolen during dev when using the webpack / rspack builder if the dev...MediumCWE-749TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes - @tinacms/mdxTinaCMS rich-text parsing and the default link/image renderers did not sanitize the url field on Slate link/image nodes. Content containing javascript: or data:text/html URLs —...MediumCWE-87TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemesTinaCMS rich-text parsing and the default link/image renderers did not sanitize the url field on Slate link/image nodes. Content containing javascript: or data:text/html URLs —...MediumCWE-87Privilege Escalation in cordova-plugin-inappbrowserVersions of cordova-plugin-inappbrowser prior to 3.1.0 are vulnerable to Privilege Escalation. A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in...HighCWE-79OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated s - @openzeppelin/wizard-cairoThe Contracts Wizard generators printed info.securityContact and info.license verbatim into a single-line comment of the generated Solidity, Cairo, Stellar/Soroban, and Stylus source without rejecting line...LowCWE-94OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated s - @openzeppelin/wizard-stellarThe Contracts Wizard generators printed info.securityContact and info.license verbatim into a single-line comment of the generated Solidity, Cairo, Stellar/Soroban, and Stylus source without rejecting line...LowCWE-94OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated s - @openzeppelin/wizard-stylusThe Contracts Wizard generators printed info.securityContact and info.license verbatim into a single-line comment of the generated Solidity, Cairo, Stellar/Soroban, and Stylus source without rejecting line...LowCWE-94OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated sThe Contracts Wizard generators printed info.securityContact and info.license verbatim into a single-line comment of the generated Solidity, Cairo, Stellar/Soroban, and Stylus source without rejecting line...LowCWE-94TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB)Blind SQL injection vulnerability in UpdateQueryBuilder and SoftDeleteQueryBuilder affecting MySQL and MariaDB users.MediumCWE-89[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat - @theia/ai-chat-uiIn Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without...MediumCWE-201[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat - @theia/ai-chatIn Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without...MediumCWE-201[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat - @theia/ai-claude-codeIn Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without...MediumCWE-201[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat - @theia/ai-code-completionIn Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without...MediumCWE-201[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat - @theia/ai-coreIn Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without...MediumCWE-201[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat - @theia/ai-ideIn Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without...MediumCWE-201[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI ChatIn Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without...MediumCWE-201[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-chat-uiIn Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing...HighCWE-829[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-chatIn Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing...HighCWE-829[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-claude-codeIn Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing...HighCWE-829[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-code-completionIn Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing...HighCWE-829[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-coreIn Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing...HighCWE-829[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-ideIn Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing...HighCWE-829[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI ChatIn Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing...HighCWE-829[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions - @theia/debugIn Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker...HighCWE-829[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions - @theia/taskIn Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker...HighCWE-829[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task DefinitionsIn Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker...HighCWE-829[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat - @theia/ai-chat-uiIn Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI...HighCWE-829[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat - @theia/ai-chatIn Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI...HighCWE-829[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat - @theia/ai-claude-codeIn Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI...HighCWE-829[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat - @theia/ai-code-completionIn Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI...HighCWE-829[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat - @theia/ai-coreIn Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI...HighCWE-829[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI ChatIn Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI...HighCWE-829TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover - @tinacms/appTinaCMS registers window message listeners — the useTina overlay handler, the OAuth authentication popup handler, and the admin↔preview iframe GraphQL reducer — that act on...HighCWE-940TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeoverTinaCMS registers window message listeners — the useTina overlay handler, the OAuth authentication popup handler, and the admin↔preview iframe GraphQL reducer — that act on...HighCWE-940ts-deepmerge: Prototype Method Override leads to DoSVersions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype methods (such as toString, valueOf)....MediumCWE-248Sveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframeA stored cross-site scripting (XSS) vulnerability affected the Markdown/RichText field preview renderer in Sveltia CMS.LowCWE-79Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requestsUni-CLI versions before 0.225.2 exposed the legacy JSON-RPC-over-HTTP MCP transport on loopback without validating browser Origin headers before routing requests. A malicious web page could...HighCWE-352scimPatch vulnerable to prototype pollution via unfiltered keys in patchscim-patch performs prototype pollution when applying a SCIM PATCH operation whose value object contains a key like "__proto__.someProp". After one such patch,Object.prototype.someProp is set process-wide,...HighCWE-1321devbridge-autocomplete has XSS in its default formatters: formatGroup and formatResult fail to escape HTML in untrustedThe default formatGroup and formatResult functions in devbridge-autocomplete concatenate values into HTML without escaping, allowing XSS when an attacker controls (or can taint) the suggestion...MediumCWE-79neotoma has tenant isolation gap in relationship query endpointsThe /list_relationships and /retrieve_graph_neighborhood endpoints call getAuthenticatedUserId (confirming a valid session exists) but do not pass the resolved user ID into the Supabase query as...LowCWE-201Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)Prototype Pollution in internal assign() helper in Linkify allows remote attackers to execute arbitrary JavaScript (Stored or Reflected XSS) via injection of event handlers through...HighCWE-1321MJML allows mj-include directory traversal due to an incomplete fix for CVE-2020-12827MJML before 5.0.0-alpha.9 allows mj-include directory traversal to test file existence and (in the type=”css” case) read files. NOTE: this issue exists because of an...MediumCWE-36Sveltejs devalue's `devalue.parse` and `devalue.unflatten` emit objects with `__proto__` own propertiesIn some circumstances, devalue.parse and devalue.unflatten could emit objects with __proto__ own properties. This in and of itself is not a security vulnerability (and is...LowCWE-1321LinkifyIt#match scan loop has quadratic algorithmic complexityLinkifyIt.prototype.match — the package’s primary public API — has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails. This is not a regex...HighCWE-1333better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static ServerA directory traversal vulnerability exists in the production static file server of better-helperjs (<= 3.0.5). Attackers can read arbitrary files located in adjacent directory structures...HighCWE-22Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authenticationNo description available.HighCWE-862js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literalsjs-toml versions up to and including 1.1.0 parse hexadecimal / octal / binary integer literals via a hand-written parseBigInt loop that multiplies a BigInt accumulator...HighCWE-407@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub@microsoft/kiota-http-fetchlibrary’s RedirectHandler is documented as stripping Authorization and Cookie from cross-origin redirect targets, but the default scrubSensitiveHeaders callback in RedirectHandlerOptions uses case-sensitive property deletion (delete...MediumCWE-200TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injectionStored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users...HighCWE-79@sveltejs/kit: `query.batch` cross-talkquery.batch() could, under very rare and specific timings, cause concurrent requests from different users to merge and resolve under single request context, enabling cross-user data...MediumCWE-200@jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorizationThe network domain has a central SSRF authorization policy that blocks private, loopback, link-local, and reserved targets unless an explicit authorization object allows private network...MediumCWE-918wetty vulnerable to DOM XSS via file-download filenameThe wetty client decodes a base64 filename from the file-download escape sequence and interpolates it raw into a Toastify HTML string (escapeMarkup: false). Any output...HighCWE-79sigstore's `certificateOIDs` verification constraints are silently dropped and never enforcedThe documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked.HighCWE-347@asymmetric-effort/specifyjs: URL parse failure silently allows requestLocation: core/src/shared/secure-fetch.ts:42-45HighCWE-918@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injectionLocation: core/src/client/graphql.ts:66-80MediumCWE-943@asymmetric-effort/specifyjs: Production console warnings may leak internal framework stateLocation: core/src/core/scheduler.ts:23, core/src/hooks/dispatcher.ts:100, core/src/client/graphql.ts:71MediumCWE-209@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)Location: core/src/shared/secure-fetch.ts:52-54MediumCWE-918@asymmetric-effort/specifyjs: `data:` URI allowed without size restrictionLocation: core/src/shared/secure-fetch.ts:33-35MediumCWE-918@asymmetric-effort/specifyjs: No redirect target validation in secureFetchLocation: core/src/shared/secure-fetch.tsMediumCWE-918@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToStringLocation: core/src/server/render-to-string.ts:307-311MediumCWE-79@conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fieldsA CPU exhaustion vulnerability exists in Conform’s parseSubmission future API when parsing FormData or URLSearchParams submissions with many unique field names.HighCWE-407electerm has Path Traversal in Zmodem and Trzsz Download Filename HandlingA path traversal vulnerability exists in the Zmodem and Trzsz file download handlers in electerm. When receiving files via Zmodem or Trzsz protocols, electerm uses...HighCWE-22electerm has Command Injection in File System Operations (rmrf, mv, cp)A command injection vulnerability exists in electerm’s file system operations (rmrf, mv, cp) in src/app/lib/fs.js. These functions construct shell commands by interpolating file paths directly...HighCWE-78Electerm Local code through electerm's single-instance socketNo description available.HighCWE-940@enclave-vm/core is vulnerable to Sandbox EscapeIt is possible to escape the security boundraries set by @enclave-vm/core, which can be used to achieve remote code execution (RCE).HighCWE-94karma-mojo enables OS Command Injectionkarma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.HighCWE-78Injection in op-browserop-browser through 1.0.9 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.HighCWE-78Decompress: Archive extraction can create files and links outside of the target directoryWhen extracting an archive to a directory, a crafted archive can read or write files outside that directory. The flaw is in the code that...HighCWE-732TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributesStored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation.HighCWE-79Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99) - @nuxt/webpack-builderThis is an incomplete fix for GHSA-4gf7-ff8x-hq99. Source code may be stolen during dev when using the webpack / rspack builder if the dev server...MediumCWE-749Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)This is an incomplete fix for GHSA-4gf7-ff8x-hq99. Source code may be stolen during dev when using the webpack / rspack builder if the dev server...MediumCWE-749Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoningThe /__nuxt_island/* endpoint accepts attacker-controlled props query/body parameters and renders any island component without verifying that the URL-resident hash (<Name>_<hashId>.json) was actually issued for those...LowCWE-79Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`When experimental.componentIslands is enabled (default in Nuxt 4), any .server.vue file under pages/ is automatically registered as a server island under the key page_<routeName> and...MediumCWE-288DbGate: Remote Code Execution via functionName injection in loadReader endpointThe POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or validation.HighCWE-94Waku: Cross-Origin CSRF on RSC Server Action DispatchWaku’s RSC request dispatcher invokes server actions without validating the request’s Origin (or Sec-Fetch-Site) header. A cross-origin web attacker can therefore cause a victim browser...MediumCWE-352Waku has an Open Redirect via `unstable_redirect` HelperThe unstable_redirect() helper exported from waku/router/server (packages/waku/src/router/define-router.tsx:156–161) accepts an arbitrary string and reflects it unchanged into the HTTP Location response header with no URL validation,...LowCWE-601Claw Orchestrator is missing authentication for the component API EndpointA weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of the file src/embedded-server.ts of the component API Endpoint....MediumCWE-287Claw Orchestrator has inefficient regular expression complexity via validateRegex()A security vulnerability has been detected in Enderfga claw-orchestrator up to 3.7.0. The impacted element is the function validateRegex of the file claw-orchestrator/src/embedded-server.ts of the...MediumCWE-400Potential XSS vulnerability in jQuery - jqueryPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery’s DOM manipulation methods (i.e. .html(), .append(), and others) may execute...MediumCWE-79LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSSThe strip_html filter in liquidjs is intended to remove HTML tags from a string before rendering, and is widely used as an XSS sanitizer. The...MediumCWE-79LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` bodyThe renderLimit option — documented in docs/source/tutorials/dos.md as the mechanism that “mitigates this by limiting the time consumed by each render() call” — can be...MediumCWE-400LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`Context.spawn() in liquidjs creates a child Context for the {% render %} tag but does not propagate the parent context’s resolved ownPropertyOnly value. The new...MediumCWE-693LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)The date filter’s strftime implementation parses width specifiers like %9999999d and forwards the captured width unchecked into pad()/padStart() in src/util/underscore.ts.HighCWE-400LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter RegexThe built-in strip_html filter in liquidjs uses a regex containing four lazy-quantified alternatives. When the input contains many <script, <style, or <!-- opener tokens without...HighCWE-1333tarteaucitron: data-cookie attribute can be used to delete arbitrary cookiestarteaucitron provides a list of cookies and buttons to delete them. If an attacker can write HTML with data attributes, they could create an element...MediumCWE-285DesktopCommanderMCP is vulnerable to Uncontrolled Resource ConsumptionA security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function of the file src/search-manager.ts of the component start_search....LowCWE-400DesktopCommanderMCP is vulnerable to SSRFA vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the...LowCWE-918Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 rangesFedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding public URL validation before runtime document and media fetching. However, the current IPv4 validation logic...HighCWE-918Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__The _.merge(target, source) utility exported by @feathersjs/commons recursively merges source into target by iterating Object.keys(source). When source was produced by JSON.parse and contains a __proto__...LowCWE-1321TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` commentsStored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize...HighCWE-79obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/wrThe Local REST API’s /vault/{path} endpoints (GET/PUT/PATCH/POST/DELETE) percent-decode the request path inside the handler — after Express has already routed and normalized it, then hand...HighCWE-22Embedded malware in ua-parser-jsThe npm package ua-parser-js had three versions published with malicious code. Users of affected versions (0.7.29, 0.8.0, 1.0.0) should upgrade as soon as possible and...HighCWE-912protobufjs: Denial of service through unbounded Any expansion during JSON conversionprotobufjs could recurse without a depth limit while converting decoded messages to plain objects or JSON. This affected generated toObject() conversion and the custom google.protobuf.Any...HighCWE-674@babel/core: Arbitrary File Read via sourceMappingURL CommentUsing @babel/core to compile maliciously crafted code can allow ab attacker to read any source map from the system that is running Babel, if these...LowCWE-22protobufjs : Schema-derived names can shadow runtime-significant propertiesprotobufjs accepted certain schema-derived names that could collide with properties used by protobufjs runtime helpers. The known affected names are fields named hasOwnProperty, field or...MediumCWE-754protobufjs: Memory amplification from preserved unknown fields in binary decodeprotobufjs 8.2.0 added support for preserving unknown fields encountered during binary decode. Affected versions preserved unknown wire elements in message.$unknowns and did not provide a...MediumCWE-770websocket-driver: Message corruption via abuse of protocol length headersThe frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a...HighCWE-130websocket-driver: Resource limit bypass via message compressionIf this library is used in tandem with the permessage-deflate extension, a WebSocket server or client can be made to accept messages that are larger...MediumCWE-770ExifReader is vulnerable to denial of service via crafted ICC `mluc` tagWhen parsing an image with an embedded ICC profile that contains a crafted multiLocalizedUnicodeType (mluc) tag, ExifReader can be made to allocate memory proportional to...HighCWE-1284ExifReader is vulnerable to denial of service via unbounded decompression of image metadataVersions of ExifReader from 4.20.0 through 4.38.1 do not bound the size of decompressed metadata blocks. When a caller invokes the asynchronous API (e.g. ExifReader.load(file)...MediumCWE-409TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification gPUT /api/basemap (the basemap import endpoint) fetches an attacker-supplied URL server-side with no SSRF protection whatsoever. Any authenticated user can submit a JSON body {...MediumCWE-918Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loaderThe TypeScript Prompty loader used gray-matter without overriding executable frontmatter engines. gray-matter supports JavaScript frontmatter blocks such as ---js and evaluates them while parsing. An...HighCWE-94ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxesExifReader 4.40.0 can throw an uncaught RangeError: Offset is outside the bounds of the DataView while parsing crafted HEIC/AVIF files. The file only needs a...MediumCWE-755CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classificationNo description available.HighCWE-918Angular's deprecated package has a Cross-Site Scripting issueA flaw in AngularJS’ Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within...HighCWE-791@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default@andrea9293/mcp-documentation-server v1.13.0 documents that a Web UI starts automatically on port 3080. However, the Web UI/API appears to bind to all network interfaces by default...HighCWE-668Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serializationA potential Cross-Site Scripting (XSS) vulnerability exists in Fabric.js due to improper escaping of user-controlled input during SVG serialization via the toSVG() method.MediumCWE-79axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVshouldBypassProxy, introduced in v1.15.0 to fix CVE-2025-62718, does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a...HighCWE-918Dash apps vulnerable to Cross-site Scripting - dash-core-componentsVersions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package...MediumCWE-79Dash apps vulnerable to Cross-site ScriptingVersions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package...MediumCWE-79Axios: Deep formToJSON Key Recursion Can Cause Denial of ServiceAxios versions starting with 0.28.0 contain uncontrolled recursion in formDataToJSON, which is exposed as axios.formToJSON() and used internally when axios serialises FormData with Content-Type: application/json....MediumCWE-770Axios: Excessive recursion in formDataToJSON can cause denial of serviceAxios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON, the helper behind the public axios.formToJSON() / named formToJSON API and the default request transform...MediumCWE-674@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpointsUsers are affected if all of the following are true:HighCWE-918LobeHub: Unauthenticated SSRF in `/webapi/proxy`No description available.HighCWE-918@better-auth/sso: SSO provider may allow registration for any org member without a checking their roleYou are affected if all of the following are true:HighCWE-863defuddle vulnerable to XSS via unescaped string interpolation in _findContentBySchemaText image tagThe _findContentBySchemaText method in src/defuddle.ts interpolates image src and alt attributes directly into an HTML string without escaping:LowCWE-79Socket.IO: Engine.IO Polling Transport Connection ExhaustionAn unauthenticated remote attacker can cause a denial of service in affected versions of engine.io by opening Engine.IO polling sessions and sending an invalid binary...HighCWE-404protobufjs: Denial of Service via infinite loop in .proto option parsingprotobufjs parsed option names by advancing through schema tokens until it reached an = token, without checking for end of input. A crafted .proto schema...MediumCWE-835protobufjs: Text Format string map parsing can mutate returned map object prototypeThe protobuf.js text format extension parsed string-keyed map entries using ordinary property assignment. A text-format map entry with key __proto__ could therefore change the prototype...MediumCWE-1321Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axiosAxios versions containing lib/helpers/shouldBypassProxy.js do not treat 0.0.0.0 as a local address when evaluating NO_PROXY rules. In Node.js applications that use HTTP_PROXY or HTTPS_PROXY together...MediumCWE-918Axios: Prototype pollution gadgets can alter axios request constructionaxios is vulnerable to read-side prototype-pollution gadgets when Object.prototype has already been polluted by another vulnerability or dependency. The most broadly reachable issue is in...MediumCWE-1321Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`axios’ fetch adapter does not enforce maxBodyLength for live WHATWG ReadableStream request bodies whose size cannot be determined before dispatch. Applications that use adapter: "fetch"...MediumCWE-770Axios: HTTP/2 streamed uploads bypass `maxBodyLength`Axios versions with Node.js HTTP/2 support allow streamed request bodies to bypass maxBodyLength enforcement when requests are sent with httpVersion: 2.MediumCWE-400Axios: Nested axios option objects can consume polluted prototype valuesAxios can consume inherited properties from nested request option objects when the JavaScript process already has a polluted Object.prototype.MediumCWE-1321Axios form serializer maxDepth bypass via {} metatokenAxios versions in the fixed lines for GHSA-62hf-57xw-28j9 still contain an incomplete depth-limit bypass in lib/helpers/toFormData.js. When serializing an object with a top-level key ending...MediumCWE-674Axios Node HTTP adapter can use an inherited proxy after interceptor config cloningAxios’ Node.js HTTP adapter can route requests through an attacker-controlled proxy when Object.prototype.proxy is polluted and request configuration is materialized as a regular object before...HighCWE-200AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridgTwo inbound-mail handlers act on a privileged effect without verifying that the sender is the operator, while a sibling handler in the same repo does....HighCWE-306Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directoryThe chrome-devtools-mcp daemon writes its PID file with fs.writeFileSync() to a deterministic runtime path. On typical macOS environments, and on Linux sessions where $XDG_RUNTIME_DIR is...MediumCWE-59jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputsVersions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or...HighCWE-835jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce GenerationVersions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in...HighCWE-338jsrsasign: Negative Exponent Handling Leads to Signature Verification BypassVersions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can...HighCWE-681jsrsasign: DSA signatures or X.509 certificates can be forged via DSA domain-parameter validation in KJUR.crypto.DSA.setVersions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related...HighCWE-347js-toml has silent type confusion via falsy-primitive duplicate-key bypassjs-toml’s interpreter checks whether a key already exists in a parser-built container with if (object[key]) instead of if (key in object). When the prior value...MediumCWE-697Immutable.js `List` 32-bit trie overflow → unrecoverable DoSList#set, List#setSize, List#setIn, List#updateIn (and the functional set / setIn / updateIn) mishandle an index or size in the range [2 ** 30, 2 **...HighCWE-835Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/SetImmutable.Map and Immutable.Set keep keys that share the same 32-bit hash in a collision bucket that is scanned linearly.HighCWE-407linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker textlinkify-it’s schema-scan loop (.test() / .match(), the documented public API) invokes the mailto:schema validator at every mailto: occurrence in the input text. For each occurrence...HighCWE-407OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header@opentelemetry/propagator-jaeger decodes incoming HTTP header values with decodeURIComponent() without handling decode errors. A single request carrying a malformed percent-encoded value (for example a bare %)...HighCWE-248Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registryThis is a credential-exposure / credential-confusion issue.HighCWE-522fast-uri vulnerable to host confusion via literal backslash authority delimiterfast-uri v4.1.0 and earlier do not treat a literal backslash (U+005C) as an authority delimiter. Node’s native WHATWG URL (used by fetch(), undici, and Node’s...HighCWE-436PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS commentsPostCSS’s PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the local filesystem with no scheme,...HighCWE-22LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforceCWE: CWE-770 (Allocation of Resources Without Limits or Throttling) — sibling class of GHSA-8xx9-69p8-7jp3 and GHSA-2546-xv4c-mc8g, applied to memoryLimit instead of renderLimitHighCWE-770SvelteKit: Big remote form function payloads can cause Node process to crashBig remote form function payloads can cause the Node process to crash. Doing this repeatedly can cause DoS.MediumCWE-248SvelteKit: Prototype pollution in file input deletion path in remote-function formsIf you use remote form functions, have an input field of type file, and accept arbitrary user-controlled path names for the field, then you are...MediumCWE-1321seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserializationA type confusion issue in seroval.fromJSON() allowed attacker-controlled JSON input to cause Promise control nodes to operate on values from the general deserialization reference table...HighCWE-843Valibot: record() issue paths can make flatten() throw for inherited Object property namesvalibot 1.4.1 can throw a TypeError inside its flatten() helper when validation issues contain attacker-controlled object keys such as toString, valueOf, or hasOwnProperty.MediumCWE-755Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks RendererThe TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute...HighCWE-94mathlive's Lack of Escaping of HTML allows for XSS - mathliveDespite the 0.104.0 patch escaping attribute-bearing constructs (\htmlData, \href), text-content reflection was missed. The \text{}, \mbox{} commands accept arbitrary characters in their body and emit...MediumCWE-116degit has a Command Injection issueVersions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user input for...HighCWE-78d3-color vulnerable to ReDoSThe d3-color module provides representations for various color spaces in the browser. Versions prior to 3.1.0 are vulnerable to a Regular expression Denial of Service....HighCWE-400AWS Amplify Studio UI Component Properties Has an Input Validation IssueThe AWS Amplify Studio amplify-codegen-ui is a package that generates front-end code from UI Builder entities (components, forms, views, and themes) primarily used in AWS...HighCWE-95jodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()Jodit.modules.Helpers.set(chain, value, obj) walks the dot-separated chain, creating and following each path segment, without filtering prototype-mutating keys. A chain that begins with (or contains) __proto__,...MediumCWE-1321@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property MergingA prototype pollution vulnerability exists in @phun-ky/defaults-deep prior to version 2.0.5.HighCWE-1321Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSSjodit’s sanitizeHTMLElement neutralizes a javascript: href using a bare href.trim().indexOf('javascript') === 0 check. This omits the normalization jodit applies to every other URL attribute: isDangerousUrl...MediumCWE-83Jodit has prototype pollution via Jodit.configure() / ConfigMergeJodit.configure(options) — and the internal ConfigMerge / ConfigProto helpers — merged user-supplied options into the editor configuration without filtering prototype-mutating keys. A payload nested under...MediumCWE-1321Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrierjodit’s built-in clean-html sanitizer can be bypassed by a MathML/<style> carrier that hides a dangerous element from the sanitizer’s element walk, so a no-interaction event...HighCWE-83Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitizationA <script> element placed directly inside an <svg> (or MathML) container was not removed by Jodit’s clean-html sanitizer.MediumCWE-80sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, possanitize-html uses allowedSchemesAppliedToAttributes (default: ['href', 'src', 'cite']) to gate the naughtyHref() function that blocks dangerous URI schemes like javascript: and vbscript:.MediumCWE-79Prompty: Arbitrary file read via file reference expansionPrompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that the resolved path stayed within an authorized directory. An attacker-controlled prompt file could use...HighCWE-22PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `fThe fix for GHSA-6g55-p6wh-862q added a guard in lib/previous-map.js PreviousMap.loadFile() that restricts an attacker-controlled sourceMappingURL (from a CSS comment) to a .map extension and, for...MediumCWE-22Socket.IO: Zero-attachment Memory ExhaustionA specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to...HighCWE-754fast-uri vulnerable to host confusion via backslash authority introducerfast-uri v4.1.1 and earlier require a literal // to recognize a URI authority, so a reference that uses \\, /\, or \/ as the authority...HighCWE-436jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustionBefore JSONata 2.2.0 and 1.8.9, it is possible to craft non-matching inputs to the $toMillis function that cause superlinear backtracking in the ISO-8601 validation regex....HighCWE-1333Flowise RCE via TypeORM DataSource============================================================================= Security Advisory elttamHighCWE-94Flowise Sandbox Escape to RCE============================================================================= Security Advisory elttamHighCWE-95Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions OverrideA sandbox escape vulnerability in executeJavaScriptCode() allows any authenticated user to execute arbitrary system commands as root on the Flowise server.HighCWE-94Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell VerifiedThis is not theoretical — a Meterpreter reverse shell session as root has been established on Flowise 3.1.2.HighCWE-94Flowise RCE via SQLite Record Manager Node============================================================================= Security Advisory elttamHighCWE-94Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)The mitigation shipped for CVE-2025-8943 blocks the -y and --yes flags on npx to stop auto-installation of arbitrary packages. That flag filter works. The environment-variable...HighCWE-184Flowise: Pyodide validator Unicode homoglyph bypass leads to RCEThe validatePythonCodeForDataFrame blacklist in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allowing arbitrary Python execution inside Pyodide and full OS command execution on the...HighCWE-184Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keysFlowise on current main allows an authenticated user with documentStores:preview-process permission to trigger the S3 Directory document loader with attacker-controlled S3 object keys.HighCWE-73Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validationFlowise’s CSVAgent interpolates an attacker-controlled segment of thecsvFile data URI directly into a Python source-code template that is thenexecuted by Pyodide. Because Pyodide is loaded...HighCWE-95Flowise: Remote Code Execution Vulnerability in CSVAgentThe CSVAgent node was observed to allow users to write Python code which gets executed via pyodide. The original intent was to allow users to...HighCWE-94Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability - flowise-components– ABSTRACT ————————————-HighCWE-94@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL executionA SQL injection vulnerability exists in the escapeValue() function used for parameter substitution. escapeValue() dispatches on the type of the parameter value, and two of...HighCWE-89@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydrationUForm and UAuthForm render a server-side <form> element with no method and no action attribute, relying on a hydrated @submit.prevent handler to intercept submission. If...MediumCWE-598Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's hostNuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin.HighCWE-94Mermaid XY Charts are vulnerable to an infinite loop DoSMermaid XY Charts are vulnerable to an infinite loop DoS attack in the setXAxisRangeData(), when configuring an X-Axis with invalid parameters.MediumCWE-835Mermaid Architecture diagrams are vulnerable to prototype pollutionRendering an untrusted architecture-beta diagram lets the diagram author write an arbitrary property with the value horizontal or vertical onto Object.prototype. A group id of...MediumCWE-1321Mermaid allows CSS injection applying to sibling elements of the diagramMermaid does not fully restrict CSS to the rendered SVG subtree. Although selectors are prefixed with #mermaid-X, sibling (~ and +) combinators can still escape...MediumCWE-94Mermaid configuration APIs allow prototype pollutionMermaid’s configuration setters (mermaid.initialize, mermaidAPI.setConfig, and mermaidAPI.updateSiteConfig) merge the caller-supplied configuration object into Mermaid’s internal config using the assignWithDepth deep-merge helper that is vulnerable to...LowCWE-1321Mermaid radar diagrams are vulnerable to DoSMermaid radar diagrams allow arbitrary large values for ticks, which can cause high CPU usage, freezing the webpage/JavaScript process for long periods of time, until...MediumCWE-606PDF.js: Arbitrary JavaScript execution upon opening a malicious PDFIf PDF.js is used to load a malicious PDF, and PDF.js is configured with enableScripting set to true (which is the default value) and no...HighCWE-79ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633ngx-extended-pdf-viewer embeds a fork of Mozilla’s pdf.js rather than depending on pdfjs-dist, so this vulnerability is not visible to dependency scanners through package.json.HighCWE-1103SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept headerSvelteKit is vulnerable to remote CPU-exhaustion DoS attacks via specifically-crafted Accept headers. The impact is mitigated by default header length limits on most platforms, but...MediumCWE-1333Axios: Prototype pollution auth subfields can inject Basic authAxios versions after the GHSA-q8qp-cvcw-x6jj fix still contain prototype-pollution read-side gadgets in Basic auth subfield handling. If a host application is already affected by prototype...MediumCWE-1321crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency ChainCryptoJS.lib.WordArray.random() in affected versions is not a cryptographically secure random number generator. Nominal requests for 128 or 256 bits of entropy produce effective search spaces...HighCWE-338nanoid: non-secure generators can loop indefinitely with negative sizenanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given...HighCWE-835showdown allows stored cross-site scripting through table header ID injectionshowdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properly escape table header ID attributes.MediumCWE-79showdown metadata title handling allows cross-site scriptingshowdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript.MediumCWE-79fast-uri vulnerable to path traversal via percent-encoded dot segmentsfast-uri v3.1.0 and earlier decodes percent-encoded path separators (%2F) and dot segments (%2E) before applying dot-segment removal in normalize() and equal(). This makes encoded path...HighCWE-22Trix has a Stored XSS vulnerability through serialized attributesThe Trix editor, in versions prior to 2.1.17, is vulnerable to XSS attacks when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer.MediumCWE-79Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)The Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when a crafted application/x-trix-document JSON payload is dropped into the editor in environments...LowCWE-79Trix: Stored XSS via HTMLParser attribute injection on pasteThe Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when crafted HTML is pasted into the editor. The HTMLParser processed a mock...MediumCWE-79ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path HeaderSeverity: MediumCVSS v3.1 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NCVSS suggested base score: ~6.1 — Medium *(Re-validate in the first.gov calculator before filing.MediumCWE-79ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts both compute their temporary working-file paths as:MediumCWE-59ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartexEtherpad’s device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token in the GET response bodyMediumCWE-294fast-uri vulnerable to host confusion via percent-encoded authority delimitersfast-uri v3.1.1 and earlier decodes percent-encoded authority delimiters (%40 as @, %3A as :) inside the host component and serializes them back as raw characters....HighCWE-436nanoid: custom generators can loop indefinitely when size is zeronanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0,...HighCWE-835@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion@anephenix/hub starts a setInterval polling loop for every incoming WebSocket connection to request a client ID via RPC. If the remote client never replies —...HighCWE-400fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limitsfast-xml-parser processes multiple “DOCTYPE” declarations within a single XML document. Each declaration passes its entities to @nodable/entities through addInputEntities().HighCWE-776PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File DisclosureFile: lib/previous-map.jsLine: 87-98 (loadFile), 129-144 (loadMap)HighCWE-22Quasar: Prototype pollution in the extend() utility[email protected], the latest published version at the time of testing, appears to be vulnerable to prototype pollution through the public extend() utility exported from the...MediumCWE-1321Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)Remote Code Execution (RCE) in velocityjs v2.1.6 via property-read to the Function constructor. This bypasses the fix for GHSA-j658-c2gf-x6pq (“Prototype Pollution in #set path assignment”)...HighCWE-94TypeORM: migration:generate template-literal code injectiontypeorm migration:generate embeds database schema metadata into JS/TS template literals, escaping backticks but not ${...}. An attacker who can write schema metadata (column comments, defaults,...MediumCWE-94fast-uri vulnerable to host confusion via failed IDN canonicalizationfast-uri versions >= 2.3.1, <= 4.0.0 fail to canonicalize Unicode/IDN hostnames for HTTP-family URLs. The IDN conversion path calls URL.domainToASCII(...) on the global WHATWG URL...HighCWE-551Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/SetImmutable.Map and Immutable.Set keep keys that share the same 32-bit hash in a collision bucket that is scanned linearly.HighCWE-407Vulnerable Apache VersionThe Apache HTTP Server version used is outdated and has security flaws. Vulnerabilities in older versions could be exploited by attackers to compromise the server,...MediumVulnerable Nginx VersionThe Nginx version used is outdated and has security flaws. Vulnerabilities in older versions could be exploited by attackers to compromise the server, leading to...MediumVulnerable OpenSSL VersionThe OpenSSL version used is outdated and has security flaws. Vulnerabilities in older versions could be exploited by attackers to compromise the server, leading to...MediumVulnerable PHP VersionThe PHP version used is outdated and has security flaws. Vulnerabilities in older versions could be exploited by attackers to compromise the server, leading to...MediumVulnerable Tomcat VersionThe Apache Tomcat version used is outdated and has security flaws. Vulnerabilities in older versions could be exploited by attackers to compromise the server, leading...MediumVulnerable WordPress VersionThe WordPress version used is outdated and has security flaws. Vulnerabilities in older versions could be exploited by attackers to compromise the website, leading to...High