
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Missing Authorization
@geolens/sdk is an Auto-generated TypeScript SDK for the GeoLens API. Typed clients with Bearer + API-key auth helpers.
Affected versions of this package are vulnerable to Missing Authorization inadequate authorization checks on cross-dataset references in multiple API endpoints. An attacker can access sensitive metadata, schema details, sample values, table rows, and raster/vector tile data from private datasets by crafting requests that exploit relationships, map layers, VRT mosaics, or AI metadata endpoints. This exposure can occur anonymously or with minimal privileges, allowing unauthorized data retrieval through manipulation of request parameters and endpoint paths.
Protection Mechanism Failure
Affected versions of this package are vulnerable to Protection Mechanism Failure in the format and format_map functions of Python string subclasses. An attacker can access sensitive information by supplying crafted format strings that leverage unrestricted attribute and item access.
Missing Authentication for Critical Function
org.apache.activemq:artemis-server is a server package for the ActiveMQ-Artemis project.
Affected versions of this package are vulnerable to Missing Authentication for Critical Function via the initial cluster connection handshake. An attacker can obtain administrative credentials by capturing network traffic during the handshake.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




