
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
SQL Injection
nocodb is a NocoDB
Affected versions of this package are vulnerable to SQL Injection via the ARRAYSORT formula argument processing in Postgres-backed deployments. An attacker can execute arbitrary SQL commands and cause significant query delays by injecting malicious input into the direction argument, which is improperly validated and embedded into a raw SQL fragment during column creation and on every subsequent record read.
Arbitrary Code Injection
chromadb is a Chroma.
Affected versions of this package are vulnerable to Arbitrary Code Injection in the api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} endpoint when a malicious model repository is sent and trust_remote_code is set to true. An attacker can execute arbitrary code on the server by leveraging the UPDATE_COLLECTION permission and sending crafted requests.
Note: This is only exploitable if the attacker is authenticated and has the UPDATE_COLLECTION permission, and if trust_remote_code is enabled.
Cross-site Scripting (XSS)
org.jenkins-ci.main:jenkins-core is an open source automation server.
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the description field of a generic 'offline' cause set via the POST config.xml API. An attacker with Agent/Configure permission can execute arbitrary JavaScript in the context of other users by submitting specially crafted input.
Note:
- On Jenkins 2.539 and newer, LTS 2.541.1 and newer, enforcing Content Security Policy protection mitigates this vulnerability.
Recent vulnerabilities disclosed by Snyk
- H
Command Injection in degit (npm)- C
Malicious Package in moustick (npm)- C
Malicious Package in cookie-parser-legacy (npm)- M
Arbitrary File Write via Archive Extraction (Zip Slip) in decompress (npm)- H
CSV Injection in json-2-csv (npm)
Snyk security
researchers
have disclosed
3497
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




