
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
SQL Injection
sequelize is a promise-based Node.js ORM for Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server.
Affected versions of this package are vulnerable to SQL Injection via the _traverseJSON() function, which escapes JSON path values but not cast types (after the :: operator). An attacker can read data from arbitrary database tables by injecting malicious SQL in JSON object keys in a WHERE clause.
Directory Traversal
dbt-common is a The shared common utilities that dbt-core and adapter implementations use
Affected versions of this package are vulnerable to Directory Traversal via the safe_extract function. An attacker can write files outside the intended extraction directory by supplying a malicious tarball archive that exploits character-based path prefix validation. The only target paths that can be written to are ones that share a prefix with valid paths.
Infinite loop
Affected versions of this package are vulnerable to Infinite loop in the FileTypeParser class. This is triggered when the ASF (WMV/WMA) parser receives input including an ASF sub-header with a size value of 0. An attacker can interrupt service with a 55-byte payload.
Recent vulnerabilities disclosed by Snyk
- C
Improper Handling of Case Sensitivity in @whyour/qinglong (npm)- C
Remote Code Execution (RCE) in @whyour/qinglong (npm)- M
Cross-site Scripting (XSS) in spin.js (npm)- C
Arbitrary Code Injection in es-toolkit (npm)- M
Cross-site Scripting (XSS) in mailparser (npm)
Snyk security
researchers
have disclosed
3473
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




