
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
External Control of File Name or Path
kibana is an open source (Apache Licensed), browser-based analytics and search dashboard for Elasticsearch.
Affected versions of this package are vulnerable to External Control of File Name or Path via the processing of JSON credentials in the Google Gemini connector configuration. An attacker can access arbitrary files and perform unauthorized network requests by submitting malicious input to the connectors.
Allocation of Resources Without Limits or Throttling
keras is a Keras is a high-level neural networks API for Python..
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in HDF5 dataset metadata validation. An attacker can cause excessive memory consumption and crash the Python interpreter by supplying a crafted .keras archive containing a model.weights.h5 file with a dataset that declares an extremely large shape.
Improper Validation of Syntactic Correctness of Input
Affected versions of this package are vulnerable to Improper Validation of Syntactic Correctness of Input due to the improper validation of matrix parameters in URL paths in JAX-RS routing layer. An attacker can gain access to administrative or sensitive endpoints by crafting requests that mask path segments, potentially bypassing proxy-level path filtering.
Recent vulnerabilities disclosed by Snyk
- M
Stored XSS in net.sourceforge.plantuml:plantuml (maven)- M
Permissive List of Allowed Inputs in n8n-nodes-base (npm)- H
Prototype Pollution in pace-js (npm)- C
Remote Code Execution (RCE) in n8n-workflow (npm)- C
Remote Code Execution (RCE) in n8n-nodes-base (npm)
Snyk security
researchers
have disclosed
3457
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




