
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Cross-site Scripting (XSS)
unhead is a Full-stack manager built for any framework.
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the streamKey configuration parameter on the streaming server-side. An attacker can execute arbitrary JavaScript code in the context of the rendered page by injecting a specially crafted value into the streamKey parameter, which is then embedded directly into inline scripts without proper validation or escaping.
Note: This is only exploitable if untrusted input is explicitly routed into the streamKey configuration parameter by the application.
XML Entity Expansion
pypdf is an A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files
Affected versions of this package are vulnerable to XML Entity Expansion when parsing XMP metadata. An attacker can cause excessive memory consumption with excessive DOCTYPE entity declarations.
Improper Authentication
org.apache.tomcat:tomcat-coyote is a Tomcat Connectors and HTTP parser.
Affected versions of this package are vulnerable to Improper Authentication in processOCSPRequest(), which is part of the the CLIENT_CERT authentication process. An attacker can trigger a soft-fail of OCSP checks when soft-fail is disabled.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in github.com/yuin/goldmark/renderer/html (golang)- M
Division by zero in jsrsasign (npm)- H
Incorrect Conversion between Numeric Types in jsrsasign (npm)- C
Missing Cryptographic Step in jsrsasign (npm)- C
Improper Verification of Cryptographic Signature in jsrsasign (npm)
Snyk security
researchers
have disclosed
3483
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




