We’ve disclosed 1724 vulnerabilities
by Snyk Security
How to fix?
org.springframework:spring-beans to version 5.2.20, 5.3.18 or higher.
raneto is a Markdown powered Knowledgebase
Affected versions of this package are vulnerable to Denial of Service (DoS) via a crafted payload injected into the Search parameter.
nova is an OpenStack Nova provides a cloud computing fabric controller, supporting a wide variety of compute technologies, including: libvirt (KVM, Xen, LXC and more), Hyper-V, VMware, XenServer, OpenStack Ironic and PowerVM.
Affected versions of this package are vulnerable to Denial of Service (DoS) by creating a neutron port with the direct
vnic_type, then creating an instance bound to that port, and then changing the
vnic_type of the bound port to
Note: Only Nova deployments configured with SR-IOV are affected.
org.apache.hadoop:hadoop-common is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models.
Affected versions of this package are vulnerable to Arbitrary Code Execution via the
FileUtil.unTar() API due to improper escape of the input file name before it passed to the shell.
In vulnerable 3.3.x versions
FileUtil.unTar() is used through
InMemoryAliasMap.completeBootstrapTransfer, which is only ever run by a local user.
Malicious Package in performance-quality-models-nodejs (npm)
Malicious Package in com.google.play.billing (npm)
Malicious Package in sxg-playground (npm)
Malicious Package in node-example.ts (npm)
Malicious Package in gcore-cdn-stats (npm)
by Snyk Security
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.