Vulnerabilities
Last updated 3 hours ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
@nx/docker: OS command injection in the @nx/docker release pipeline | High Risk 8.0 | 9 hours ago | 9 hours ago |
|
|
Nx: Path traversal in nx migrate package-migrations extraction | Medium Risk 6.0 | 9 hours ago | 9 hours ago |
|
|
Nx daemon and plugin worker sockets are accessible to other local users | High Risk 8.0 | 9 hours ago | 9 hours ago |
|
|
Nx: OS command injection via git revisions and remote refs | High Risk 8.0 | 9 hours ago | 9 hours ago |
|
|
Malicious code in @baanx/solana-lib (npm) | Unknown | 15 days ago | 6 days ago |
|
|
Malicious code in @baanx/abis (npm) | Unknown | 14 days ago | 6 days ago |
|
|
Malicious code in @baanx/blockchain-config (npm) | Unknown | 14 days ago | 6 days ago |
|
|
Malicious code in @baanx/common (npm) | Unknown | 12 days ago | 6 days ago |
|
|
Malicious code in @baanx/domain (npm) | Unknown | 12 days ago | 6 days ago |
|
|
nginx ignition has TOTP Reuse During Validity Window | Medium Risk 4.2 | 14 days ago | 7 days ago |
|
|
nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware | High Risk 7.5 | 14 days ago | 7 days ago |
|
|
nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition | High Risk 8.1 | 14 days ago | 7 days ago |
|
|
nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition in github.com/lucasdillmann/nginx-ignition | Unknown | 7 days ago | 7 days ago |
|
|
nginx ignition has TOTP Reuse During Validity Window in github.com/lucasdillmann/nginx-ignition | Unknown | 7 days ago | 7 days ago |
|
|
nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware in github.com/lucasdillmann/nginx-ignition | Unknown | 7 days ago | 7 days ago |
|
|
Malicious code in nx-app (npm) | Unknown | 1 month ago | 11 days ago |
|
|
Malicious code in bunnxler (RubyGems) | Unknown | 13 days ago | 11 days ago |
|
|
Malicious code in bunxlef (RubyGems) | Unknown | 13 days ago | 11 days ago |
|
|
Malicious code in bunxler (RubyGems) | Unknown | 13 days ago | 11 days ago |
|
|
Malicious code in bunxlser (RubyGems) | Unknown | 13 days ago | 11 days ago |
|
|
Malicious code in bunxlenr (RubyGems) | Unknown | 13 days ago | 11 days ago |
|
|
Malicious code in bunxler-rb (RubyGems) | Unknown | 13 days ago | 11 days ago |
|
|
Malicious code in bunxlers (RubyGems) | Unknown | 13 days ago | 11 days ago |
|
|
Malicious code in bunxlner (RubyGems) | Unknown | 13 days ago | 11 days ago |
|
|
Malicious code in bunxlre (RubyGems) | Unknown | 13 days ago | 11 days ago |
|
|
Malicious code in bunxlerl (RubyGems) | Unknown | 13 days ago | 11 days ago |
|
|
Malicious code in bunxlir (RubyGems) | Unknown | 13 days ago | 11 days ago |
|
|
Malicious code in bunxloer (RubyGems) | Unknown | 13 days ago | 11 days ago |
|
|
Malicious code in bunxuer (RubyGems) | Unknown | 13 days ago | 11 days ago |
|
|
Malicious code in bunxlerr (RubyGems) | Unknown | 13 days ago | 11 days ago |
|
|
ONNX: TOCTOU arbitrary file read/write in save_external_dat | High Risk 7.1 | 6 months ago | 25 days ago |
|
|
ONNX: TOCTOU arbitrary file read/write in save_external_dat | High Risk 7.1 | 25 days ago | 25 days ago |
|
|
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse | High Risk 8.0 | 6 months ago | 26 days ago |
|
|
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation | Medium Risk 6.0 | 6 months ago | 26 days ago |
|
|
ingress-nginx's `rules.http.paths.path` Ingress field can be used to inject configuration into nginx | High Risk 8.8 | 8 months ago | 26 days ago |
|
|
ingress-nginx admission controller RCE escalation | Critical 9.8 | 1 year ago | 26 days ago |
tract-onnx
|
tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx | Medium Risk 6.1 | 3 months ago | 26 days ago |
|
|
ONNX: External Data Symlink Traversal | Medium Risk 5.5 | 6 months ago | 26 days ago |
|
|
ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load | Medium Risk 4.7 | 6 months ago | 26 days ago |
|
|
ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings. | High Risk 8.6 | 6 months ago | 26 days ago |
|
|
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover | Critical 9.8 | 6 months ago | 26 days ago |
|
|
ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack | High Risk 8.6 | 6 months ago | 26 days ago |
|
|
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval | Medium Risk 6.0 | 6 months ago | 26 days ago |
|
|
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys | High Risk 8.8 | 6 months ago | 26 days ago |
|
|
ingress-nginx has Improper Check for Unusual or Exceptional Conditions | Low Risk 3.1 | 8 months ago | 26 days ago |
|
|
ingress-nginx's `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx | High Risk 8.8 | 8 months ago | 26 days ago |
|
|
ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling | Medium Risk 6.5 | 8 months ago | 26 days ago |
|
|
ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs) | Medium Risk 5.5 | 3 months ago | 26 days ago |
|
|
ingress-nginx controller - auth secret file path traversal vulnerability | Medium Risk 4.8 | 1 year ago | 26 days ago |
|
|
php-svg-lib lacks path validation on font through SVG inline styles | Medium Risk 6.8 | 2 years ago | 26 days ago |
Page 1