
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Missing Authorization
flowise-ui is a
Affected versions of this package are vulnerable to Missing Authorization in the /api/v1/files route, which lacks proper permission checks for file listing and deletion operations. An attacker can access and remove files belonging to other workspaces within the same organization by using a low-privileged API key.
Missing Authorization
zenml is a ZenML: Write production-ready ML code.
Affected versions of this package are vulnerable to Missing Authorization in the get_deployed_stack endpoint. An attacker can access sensitive information, including infrastructure topology, service connector details, stack ownership, and deployment metadata, by sending authenticated requests to the affected endpoint, which lacks proper authorization checks. This exposure may enable cross-tenant reconnaissance and facilitate further attacks in multi-tenant environments.
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
org.webjars.npm:crypto-js is a library of crypto standards.
Affected versions of this package are vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the WordArray.random function. An attacker can recover security-sensitive values by enumerating the reduced output space of the underlying pseudo-random number generator. This is only exploitable if the application uses the affected function to generate security-sensitive values.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




