
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Embedded Malicious Code
mgc is a Module Generate Cli
Affected versions of this package are vulnerable to Embedded Malicious Code. While this package might be attempting to impersonate a valid organization, there is no connection between that organization and the author of this package.
Improper Input Validation
vllm is an A high-throughput and memory-efficient inference and serving engine for LLMs
Affected versions of this package are vulnerable to Improper Input Validation due to inconsistent downmixing behavior in the to_mono process. An attacker can manipulate audio inputs to cause the AI model to interpret audio differently from how it is perceived by humans, potentially leading to incorrect or malicious outputs by exploiting the discrepancy between standard audio playback and model processing.
Unquoted Search Path or Element
org.webjars.npm:electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS.
Affected versions of this package are vulnerable to Unquoted Search Path or Element in the app.setLoginItemSettings function on Windows when the executable path is written to the Run registry key without proper quoting. An attacker can execute arbitrary code at login by placing a malicious executable in an ancestor directory if the application is installed to a path containing spaces and the attacker has write access to that directory.
Note:
This is only exploitable if the application is installed in a non-standard location where ancestor directories are not protected against unauthorized writes.
Recent vulnerabilities disclosed by Snyk
- M
Division by zero in jsrsasign (npm)- H
Incorrect Conversion between Numeric Types in jsrsasign (npm)- C
Missing Cryptographic Step in jsrsasign (npm)- C
Improper Verification of Cryptographic Signature in jsrsasign (npm)- C
Incomplete Comparison with Missing Factors in jsrsasign (npm)
Snyk security
researchers
have disclosed
3482
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




