Commit 43d639b
committed
File tree
- 404
- assets
- data
- 404
- malicious-packages
- model-threats
- gguf-ssti
- h5-lambda
- keras-custom
- keras-lambda
- noautoload-suscode
- onnx-backdoor
- pickle-getattr
- pickle-malcode
- pytorch-getattr
- pytorch-malcode
- tflow-lambda
- tflow-malops
- zipslip
- oss
- post
- 3-malicious-mcps-pypi-reverse-shell
- achieving-remote-code-execution-on-n8n-via-sandbox-escape
- amazon-q-vs-code-extension-compromised-with-malicious-code
- arrayref-proc-macro1-crates-io
- astral-injection
- axios-compromise
- big-red-npm-campaign
- bitwarden-cli-hijack
- canister-worm
- check-your-socks-a-deep-dive-into-soopsocks-pypi
- crypto-packages-npm-deliver-heracles-malware
- dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503
- duer-js-malicious-package
- easy-day-js
- eslint-config-prettier-hijack-10-1-6-safe
- from-postcss-typosquat-to-windows-rat
- ghostclaw-unmasked
- hermes-px-pypi
- hijacked-npm-vscode-tasks-blockchain
- hugging-face-exfil
- image-magick-cve-2025-53101
- injective-sdk-supply-chain-attack
- iron-worm-shai-hulud-rustier-cousin
- ironworm-returns-rustier-than-ever
- langflow-latest-version-was-not-fixed
- litellm-compromised-teampcp
- lofygang-returns-a-dual-payload-npm-package
- lucide-proxy-npm-malware-campaign
- malicious-ai-models-hit-pypi
- miasma-worm-returns-to-npm
- new-crypto-stealer-npm
- npm-backdoored-packages
- nx-supply-chain-attack-targets-ai-tool-users
- omnicogg-malicious-skill
- part-1-pull-request-target-exploitation
- part-2-pull-request-target-exploitation
- part-3-pull-request-target-exploitation
- potential-rce-vulnerabilityin-openssl-cve-2025-15467
- prompt-injection-vs-scanners
- react2shell
- rollup-polyfill-masquerading
- shai-hulud-here-we-go-again-may19
- shai-hulud-here-we-go-again
- shai-hulud-is-back-august
- shai-hulud-miasma-alright-lets-see-if-this-works
- shai-hulud-miasma-redhat-cloud-services
- shai-hulud-the-second-coming-remediation-guidance
- shai-hulud-the-second-coming
- solana-fakefix
- solara-cipher-npm
- sqlite-critical-cves-or-llm-slops
- team-pcp-strikes-again-telnyx-popular-library-hit
- three-stages-deep-a-malicious-npm-package
- xinference-compromise
- vulnerabilities
- anythingllm-path-traversal-dos
- apache-httpd-mod-sed-dos-xray-228464
- apache-sharding-sphere-agent-deserialization-rce-xray-526292
- archiver-zip-slip
- axum-core-dos
- busybox-ash-dos-xray-189473
- busybox-awk-clrvar-uaf-xray-189477
- busybox-awk-evaluate-uaf-xray-189480
- busybox-awk-evaluate-uaf-xray-189482
- busybox-awk-getvar-i-uaf-xray-189475
- busybox-awk-getvar-s-uaf-xray-189479
- busybox-awk-handle-special-uaf-xray-189481
- busybox-awk-hash-init-uaf-xray-189478
- busybox-awk-next-input-file-uaf-xray-189476
- busybox-awk-nvalloc-uaf-xray-189483
- busybox-hush-null-pointer-dereference-xray-189794
- busybox-hush-untrusted-free-xray-189474
- busybox-lzma-oob-r-xray-189472
- busybox-man-null-pointer-dereference-xray-189471
- caret-xss-rce
- cassandra-udf-rce-197962
- chaos-mesh-command-injection-clean-tcs-jfsa-2025-001449534
- chaos-mesh-command-injection-cleaniptables-jfsa-2025-001449536
- chaos-mesh-command-injection-killprocesses-jfsa-2025-001449535
- chaos-mesh-debugging-server-denial-of-service-jfsa-2025-001449533
- civetweb-file-upload-rce-xray-188861
- cleo-redos-xray-257186
- clickhouse-delta-divide-by-zero-dos-xray-199946
- clickhouse-doubledelta-divide-by-zero-dos-xray-199947
- clickhouse-gorilla-divide-by-zero-dos-xray-199948
- clickhouse-lz4-oob-r-xray-199962
- clickhouse-lz4-oob-r-xray-199963
- clickhouse-lz4-rce-xray-199960
- clickhouse-lz4-rce-xray-199961
- codex-cli-symlink-arbitrary-file-overwrite-jfsa-2025-001378631
- conduit-hyper-dos
- couchdb-session-hijacking-localpriv
- cursor-cli-untrusted-project-rce
- deeplake-kaggle-command-injection-jfsa-2024-001035320
- devcert-redos-xray-211352
- dspy-sandbox-escape-arbitrary-file-read-jfsa-2025-001495652
- envoy-decompressor-dos-xray-227941
- eth-account-redos-xray-248681
- fedify-infinite-loop-blind-ssrf
- ffmpeg-is-vulnerable-to-a-heap-out-of-bounds-write-in-the-magicyuv-decoder-cve-2026-8461
- flowise-js-injection-remote-code-exection-jfsa-2025-001379925
- flowise-os-command-remote-code-execution-jfsa-2025-001380578
- goahead-timing-attack-auth-bypass-xray-194044
- guardrails-rail-xxe-jfsa-2024-001035519
- h2-console-jndi-rce-xray-193805
- h2o-model-deserialization-rce-jfsa-2024-001035518
- hawk-redos-xray-209780
- integer-overflow-in-haproxy-leads-to-http-smuggling-xray-184496
- interniche-dns-client-heap-overflow-xray-194045
- interniche-http-server-heap-overflow-xray-194046
- javassist-lce
- jettison-json-array-dos-xray-427911
- jetty-xml-parser-xxe-xray-523189
- jquery-validation-redos-xray-211348
- keras-untrusted-model-arbitrary-file-write
- kimi-code-is-vulnerable-to-a-fetchurl-ssrf-protection-bypass-via-dns-resolving-hostnames-and-redirects-cve-2026-17534
- lemmynet-activitypub-federation-blind-ssrf
- libmodbus-modbus-fc-write-multiple-coils-oob-r-xray-150047
- libmodbus-modbus-fc-write-multiple-registers-oob-r-xray-150046
- libtiff-buffer-overflow-dos-xray-259933
- libtiff-nullderef-dos-xray-522144
- libxmljs-attrs-type-confusion-rce-jfsa-2024-001033988
- libxmljs-namespaces-type-confusion-rce-jfsa-2024-001034096
- libxmljs2-attrs-type-confusion-rce-jfsa-2024-001034097
- libxmljs2-namespaces-type-confusion-rce-jfsa-2024-001034098
- libxpm-heap-overflow-rce-xray-532777
- libxpm-stack-exhaustion-dos-xray-532775
- litmus-jwt-missing-entropy-elevation-jfsa-2025-001648159
- lollms-webui-dos-jfsa-2024-001028813
- lollms-webui-exposed-endpoints-dos-jfsa-2024-001028815
- lollms-webui-exposed-endpoints-dos-jfsa-2024-001028816
- lollms-webui-sqli-dos-jfsa-2024-001028814
- mage-ai-deleted-users-rce-jfsa-2024-001039602
- mage-ai-file-content-request-remote-arbitrary-file-leak-jfsa-2024-001039603
- mage-ai-git-content-request-remote-arbitrary-file-leak-jfsa-2024-001039604
- mage-ai-pipeline-interaction-request-remote-arbitrary-file-leak-jfsa-2024-001039605
- mage-ai-terminal-server-infoleak-jfsa-2024-001039574
- markdown-link-extractor-redos-xray-211350
- mcp-remote-command-injection-rce-jfsa-2025-001290844
- mcp-run-python-deno-ssrf-jfsa-2026-001653029
- mcp-run-python-lack-of-isolation-mcp-takeover-jfsa-2026-001653030
- minissdpd-updatedevice-uaf-xray-161552
- miniupnpd-addportmapping-null-pointer-dereference-xray-148211
- miniupnpd-copyipv6-ifdifferent-null-pointer-dereference-xray-162485
- miniupnpd-getoutboundpinholetimeout-null-pointer-dereference-xray-148212
- miniupnpd-getoutboundpinholetimeout-null-pointer-dereference-xray-148213
- miniupnpd-upnp-event-prepare-infoleak-xray-148214
- mleap-path-traversal-rce-xray-532656
- mlflow-spark-udf-localpriv-jfsa-2024-000639017
- mlflow-untrusted-dataset-xss-jfsa-2024-000631932
- mlflow-untrusted-recipe-xss-jfsa-2024-000631930
- n8n-expression-node-rce
- n8n-git-node-rce
- n8n-python-runner-sandbox-escape-jfsa-2026-001651077
- netty-bzip2-decoder-dos-xray-186801
- netty-snappy-decoder-dos-xray-186810
- nichestack-dns-client-does-not-set-sufficiently-random-source-ports-xray-194058
- nichestack-dns-client-oob-r-xray-194047
- nichestack-dns-client-oob-r-xray-194048
- nichestack-dns-client-txid-weak-random-xray-194057
- nichestack-http-server-dos-xray-194049
- nichestack-icmp-payload-oob-r-xray-194052
- nichestack-icmp-payload-oob-r-xray-194053
- nichestack-ip-length-dos-xray-194051
- nichestack-tcp-isns-are-generated-in-a-predictable-manner-xray-194054
- nichestack-tcp-urg-dos-xray-194050
- nichestack-tftp-filename-oob-r-xray-194059
- nichestack-unknown-http-panic-xray-194055
- nodejs-fs-permissions-bypass-cve-2025-55130
- nodejs-http-smuggling-xray-231662
- notegen-is-vulnerable-to-arbitrary-os-command-execution-via-tauri-shell-allow-execute-cve-2026-17497
- notegen-is-vulnerable-to-chat-preview-xss-via-unsanitized-ai-skill-html-rendering-cve-2026-17496
- oatpp-mcp-prompt-hijacking-jfsa-2025-001494691
- okhttp-client-brotli-dos
- okio-gzip-source-unhandled-exception-dos-xray-589879
- peertube-activitypub-crawl-dos
- peertube-activitypub-playlist-creation-blind-ssrf-dos
- peertube-arbitrary-playlist-creation-activitypub
- peertube-arbitrary-playlist-creation-rest
- peertube-archive-persistent-dos
- peertube-archive-resource-exhaustion
- peertube-hls-path-traversal
- pengutronix-rauc-signature-bypass-xray-194062
- picklescan-cve-2025-10155
- picklescan-cve-2025-10156
- picklescan-cve-2025-10157
- pjlib-pjsua-call-dump-dos-xray-198028
- pjlib-pjsua-player-create-rce-xray-198024
- pjlib-pjsua-playlist-create-rce-xray-198026
- pjlib-pjsua-recorder-create-oob-r-xray-198027
- pjlib-pjsua-recorder-create-rce-xray-198025
- plexus-archiver-arbitrary-file-overwrite-xray-526292
- pymatgen-redos-xray-257184
- python-utcp-untrusted-manual-command-execution-jfsa-2025-001648329
- qcmap-cli-command-injection-xray-194065
- qcmap-web-interface-null-pointer-dereference-xray-194064
- qcmap-web-interface-rce-xray-194063
- qemu-rce-xray-520621
- qnx-slinger-path-traversal-rce-xray-194072
- react-native-cli-command-injection-jfsa-2025-001495618
- realtek-8710-wpa2-stack-overflow-xray-194060
- realtek-8710-wpa2-stack-overflow-xray-194061
- realtek-multiple-wi-fi-modules-rce-xray-194071
- realtek-rtl8195-a-dos-xray-194066
- realtek-rtl8195-a-rce-xray-194067
- realtek-rtl8195-a-rce-xray-194068
- realtek-rtl8195-a-rce-xray-194069
- realtek-rtl8195-a-rce-xray-194070
- rust-cargo-symlink-arbitrary-file-overwrite
- rust-cargo-zip-bomb-dos
- semver-regex-redos-xray-211349
- smolagents-local-python-sandbox-escape-jfsa-2025-001434277
- snappy-java-integer-overflow-in-compress-leads-to-dos-xray-522075
- snappy-java-integer-overflow-in-shuffle-leads-to-dos-xray-522076
- snappy-java-unchecked-chunk-length-dos-xray-522074
- snowflake-connector-python-redos-xray-257185
- sqlparse-stack-exhaustion-dos-jfsa-2024-001031292
- stack-exhaustion-in-json-smart-leads-to-denial-of-service-when-parsing-malformed-json-xray-427633
- tensorflow-python-code-injection-xray-189178
- tensorflow-serving-stacko-dos
- the-reachy-mini-bluetooth-command-handler-is-vulnerable-to-arbitrary-root-script-execution-via-path-traversal-cve-2026-62661
- the-reachy-mini-daemon-is-vulnerable-to-an-unrestricted-file-upload-in-the-media-sounds-upload-api-cve-2026-55419
- the-reachy-mini-wireless-image-is-vulnerable-to-a-local-privilege-escalation-via-an-unrestricted-sudo-systemctl-grant-jfsa-2026-001667223
- txtai-arbitrary-file-write-jfsa-2025-001471363
- ua-cpp-replaceargs-oob-write-xray-75751
- ua-cpp-ua-extensionobject-type-confusion-xray-75752
- ua-cpp-ua-int32-null-deref-xray-75753
- ua-cpp-uaunistring-1-byte-oob-xray-75754
- ua-cpp-uaunistring-infoleak-xray-75755
- ua-cpp-uavariant-null-deref-xray-75756
- ua-cpp-uavariant-oob-read-xray-75757
- ua-cpp-unlimited-file-handles-dos-xray-75758
- ua-net-standard-stack-dos-xray-229139
- ua-net-standard-stack-dos-xray-229142
- undefined-variable-usage-in-proxy-leads-to-remote-denial-of-service-xray-520917
- uri-template-lite-redos-xray-211351
- vanna-prompt-injection-rce-jfsa-2024-001034449
- vector-admin-filter-bypass
- vite-arbitrary-html-file-leak
- vite-arbitrary-private-file-leak
- wandb-weave-server-remote-arbitrary-file-leak-jfsa-2024-001039248
- webfingerjs-blind-ssrf
- wget-shorthand-urls-ssrf-jfsa-2024-001063927
- xss-in-nanohttpd-xray-141192
- yamale-schema-code-injection-xray-182135
- js
- malicious-packages
- model-threats
- gguf-ssti
- h5-lambda
- keras-custom
- keras-lambda
- noautoload-suscode
- onnx-backdoor
- pickle-getattr
- pickle-malcode
- pytorch-getattr
- pytorch-malcode
- tflow-lambda
- tflow-malops
- zipslip
- oss
- post
- 3-malicious-mcps-pypi-reverse-shell
- achieving-remote-code-execution-on-n8n-via-sandbox-escape
- amazon-q-vs-code-extension-compromised-with-malicious-code
- arrayref-proc-macro1-crates-io
- astral-injection
- axios-compromise
- big-red-npm-campaign
- bitwarden-cli-hijack
- canister-worm
- check-your-socks-a-deep-dive-into-soopsocks-pypi
- crypto-packages-npm-deliver-heracles-malware
- dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503
- duer-js-malicious-package
- easy-day-js
- eslint-config-prettier-hijack-10-1-6-safe
- from-postcss-typosquat-to-windows-rat
- ghostclaw-unmasked
- hermes-px-pypi
- hijacked-npm-vscode-tasks-blockchain
- hugging-face-exfil
- image-magick-cve-2025-53101
- injective-sdk-supply-chain-attack
- iron-worm-shai-hulud-rustier-cousin
- ironworm-returns-rustier-than-ever
- langflow-latest-version-was-not-fixed
- litellm-compromised-teampcp
- lofygang-returns-a-dual-payload-npm-package
- lucide-proxy-npm-malware-campaign
- malicious-ai-models-hit-pypi
- miasma-worm-returns-to-npm
- new-crypto-stealer-npm
- npm-backdoored-packages
- nx-supply-chain-attack-targets-ai-tool-users
- omnicogg-malicious-skill
- part-1-pull-request-target-exploitation
- part-2-pull-request-target-exploitation
- part-3-pull-request-target-exploitation
- potential-rce-vulnerabilityin-openssl-cve-2025-15467
- prompt-injection-vs-scanners
- react2shell
- rollup-polyfill-masquerading
- shai-hulud-here-we-go-again-may19
- shai-hulud-here-we-go-again
- shai-hulud-is-back-august
- shai-hulud-miasma-alright-lets-see-if-this-works
- shai-hulud-miasma-redhat-cloud-services
- shai-hulud-the-second-coming-remediation-guidance
- shai-hulud-the-second-coming
- solana-fakefix
- solara-cipher-npm
- sqlite-critical-cves-or-llm-slops
- team-pcp-strikes-again-telnyx-popular-library-hit
- three-stages-deep-a-malicious-npm-package
- xinference-compromise
- vulnerabilities
- anythingllm-path-traversal-dos
- apache-httpd-mod-sed-dos-xray-228464
- apache-sharding-sphere-agent-deserialization-rce-xray-526292
- archiver-zip-slip
- axum-core-dos
- busybox-ash-dos-xray-189473
- busybox-awk-clrvar-uaf-xray-189477
- busybox-awk-evaluate-uaf-xray-189480
- busybox-awk-evaluate-uaf-xray-189482
- busybox-awk-getvar-i-uaf-xray-189475
- busybox-awk-getvar-s-uaf-xray-189479
- busybox-awk-handle-special-uaf-xray-189481
- busybox-awk-hash-init-uaf-xray-189478
- busybox-awk-next-input-file-uaf-xray-189476
- busybox-awk-nvalloc-uaf-xray-189483
- busybox-hush-null-pointer-dereference-xray-189794
- busybox-hush-untrusted-free-xray-189474
- busybox-lzma-oob-r-xray-189472
- busybox-man-null-pointer-dereference-xray-189471
- caret-xss-rce
- cassandra-udf-rce-197962
- chaos-mesh-command-injection-clean-tcs-jfsa-2025-001449534
- chaos-mesh-command-injection-cleaniptables-jfsa-2025-001449536
- chaos-mesh-command-injection-killprocesses-jfsa-2025-001449535
- chaos-mesh-debugging-server-denial-of-service-jfsa-2025-001449533
- civetweb-file-upload-rce-xray-188861
- cleo-redos-xray-257186
- clickhouse-delta-divide-by-zero-dos-xray-199946
- clickhouse-doubledelta-divide-by-zero-dos-xray-199947
- clickhouse-gorilla-divide-by-zero-dos-xray-199948
- clickhouse-lz4-oob-r-xray-199962
- clickhouse-lz4-oob-r-xray-199963
- clickhouse-lz4-rce-xray-199960
- clickhouse-lz4-rce-xray-199961
- codex-cli-symlink-arbitrary-file-overwrite-jfsa-2025-001378631
- conduit-hyper-dos
- couchdb-session-hijacking-localpriv
- cursor-cli-untrusted-project-rce
- deeplake-kaggle-command-injection-jfsa-2024-001035320
- devcert-redos-xray-211352
- dspy-sandbox-escape-arbitrary-file-read-jfsa-2025-001495652
- envoy-decompressor-dos-xray-227941
- eth-account-redos-xray-248681
- fedify-infinite-loop-blind-ssrf
- ffmpeg-is-vulnerable-to-a-heap-out-of-bounds-write-in-the-magicyuv-decoder-cve-2026-8461
- flowise-js-injection-remote-code-exection-jfsa-2025-001379925
- flowise-os-command-remote-code-execution-jfsa-2025-001380578
- goahead-timing-attack-auth-bypass-xray-194044
- guardrails-rail-xxe-jfsa-2024-001035519
- h2-console-jndi-rce-xray-193805
- h2o-model-deserialization-rce-jfsa-2024-001035518
- hawk-redos-xray-209780
- integer-overflow-in-haproxy-leads-to-http-smuggling-xray-184496
- interniche-dns-client-heap-overflow-xray-194045
- interniche-http-server-heap-overflow-xray-194046
- javassist-lce
- jettison-json-array-dos-xray-427911
- jetty-xml-parser-xxe-xray-523189
- jquery-validation-redos-xray-211348
- keras-untrusted-model-arbitrary-file-write
- kimi-code-is-vulnerable-to-a-fetchurl-ssrf-protection-bypass-via-dns-resolving-hostnames-and-redirects-cve-2026-17534
- lemmynet-activitypub-federation-blind-ssrf
- libmodbus-modbus-fc-write-multiple-coils-oob-r-xray-150047
- libmodbus-modbus-fc-write-multiple-registers-oob-r-xray-150046
- libtiff-buffer-overflow-dos-xray-259933
- libtiff-nullderef-dos-xray-522144
- libxmljs-attrs-type-confusion-rce-jfsa-2024-001033988
- libxmljs-namespaces-type-confusion-rce-jfsa-2024-001034096
- libxmljs2-attrs-type-confusion-rce-jfsa-2024-001034097
- libxmljs2-namespaces-type-confusion-rce-jfsa-2024-001034098
- libxpm-heap-overflow-rce-xray-532777
- libxpm-stack-exhaustion-dos-xray-532775
- litmus-jwt-missing-entropy-elevation-jfsa-2025-001648159
- lollms-webui-dos-jfsa-2024-001028813
- lollms-webui-exposed-endpoints-dos-jfsa-2024-001028815
- lollms-webui-exposed-endpoints-dos-jfsa-2024-001028816
- lollms-webui-sqli-dos-jfsa-2024-001028814
- mage-ai-deleted-users-rce-jfsa-2024-001039602
- mage-ai-file-content-request-remote-arbitrary-file-leak-jfsa-2024-001039603
- mage-ai-git-content-request-remote-arbitrary-file-leak-jfsa-2024-001039604
- mage-ai-pipeline-interaction-request-remote-arbitrary-file-leak-jfsa-2024-001039605
- mage-ai-terminal-server-infoleak-jfsa-2024-001039574
- markdown-link-extractor-redos-xray-211350
- mcp-remote-command-injection-rce-jfsa-2025-001290844
- mcp-run-python-deno-ssrf-jfsa-2026-001653029
- mcp-run-python-lack-of-isolation-mcp-takeover-jfsa-2026-001653030
- minissdpd-updatedevice-uaf-xray-161552
- miniupnpd-addportmapping-null-pointer-dereference-xray-148211
- miniupnpd-copyipv6-ifdifferent-null-pointer-dereference-xray-162485
- miniupnpd-getoutboundpinholetimeout-null-pointer-dereference-xray-148212
- miniupnpd-getoutboundpinholetimeout-null-pointer-dereference-xray-148213
- miniupnpd-upnp-event-prepare-infoleak-xray-148214
- mleap-path-traversal-rce-xray-532656
- mlflow-spark-udf-localpriv-jfsa-2024-000639017
- mlflow-untrusted-dataset-xss-jfsa-2024-000631932
- mlflow-untrusted-recipe-xss-jfsa-2024-000631930
- n8n-expression-node-rce
- n8n-git-node-rce
- n8n-python-runner-sandbox-escape-jfsa-2026-001651077
- netty-bzip2-decoder-dos-xray-186801
- netty-snappy-decoder-dos-xray-186810
- nichestack-dns-client-does-not-set-sufficiently-random-source-ports-xray-194058
- nichestack-dns-client-oob-r-xray-194047
- nichestack-dns-client-oob-r-xray-194048
- nichestack-dns-client-txid-weak-random-xray-194057
- nichestack-http-server-dos-xray-194049
- nichestack-icmp-payload-oob-r-xray-194052
- nichestack-icmp-payload-oob-r-xray-194053
- nichestack-ip-length-dos-xray-194051
- nichestack-tcp-isns-are-generated-in-a-predictable-manner-xray-194054
- nichestack-tcp-urg-dos-xray-194050
- nichestack-tftp-filename-oob-r-xray-194059
- nichestack-unknown-http-panic-xray-194055
- nodejs-fs-permissions-bypass-cve-2025-55130
- nodejs-http-smuggling-xray-231662
- notegen-is-vulnerable-to-arbitrary-os-command-execution-via-tauri-shell-allow-execute-cve-2026-17497
- notegen-is-vulnerable-to-chat-preview-xss-via-unsanitized-ai-skill-html-rendering-cve-2026-17496
- oatpp-mcp-prompt-hijacking-jfsa-2025-001494691
- okhttp-client-brotli-dos
- okio-gzip-source-unhandled-exception-dos-xray-589879
- peertube-activitypub-crawl-dos
- peertube-activitypub-playlist-creation-blind-ssrf-dos
- peertube-arbitrary-playlist-creation-activitypub
- peertube-arbitrary-playlist-creation-rest
- peertube-archive-persistent-dos
- peertube-archive-resource-exhaustion
- peertube-hls-path-traversal
- pengutronix-rauc-signature-bypass-xray-194062
- picklescan-cve-2025-10155
- picklescan-cve-2025-10156
- picklescan-cve-2025-10157
- pjlib-pjsua-call-dump-dos-xray-198028
- pjlib-pjsua-player-create-rce-xray-198024
- pjlib-pjsua-playlist-create-rce-xray-198026
- pjlib-pjsua-recorder-create-oob-r-xray-198027
- pjlib-pjsua-recorder-create-rce-xray-198025
- plexus-archiver-arbitrary-file-overwrite-xray-526292
- pymatgen-redos-xray-257184
- python-utcp-untrusted-manual-command-execution-jfsa-2025-001648329
- qcmap-cli-command-injection-xray-194065
- qcmap-web-interface-null-pointer-dereference-xray-194064
- qcmap-web-interface-rce-xray-194063
- qemu-rce-xray-520621
- qnx-slinger-path-traversal-rce-xray-194072
- react-native-cli-command-injection-jfsa-2025-001495618
- realtek-8710-wpa2-stack-overflow-xray-194060
- realtek-8710-wpa2-stack-overflow-xray-194061
- realtek-multiple-wi-fi-modules-rce-xray-194071
- realtek-rtl8195-a-dos-xray-194066
- realtek-rtl8195-a-rce-xray-194067
- realtek-rtl8195-a-rce-xray-194068
- realtek-rtl8195-a-rce-xray-194069
- realtek-rtl8195-a-rce-xray-194070
- rust-cargo-symlink-arbitrary-file-overwrite
- rust-cargo-zip-bomb-dos
- semver-regex-redos-xray-211349
- smolagents-local-python-sandbox-escape-jfsa-2025-001434277
- snappy-java-integer-overflow-in-compress-leads-to-dos-xray-522075
- snappy-java-integer-overflow-in-shuffle-leads-to-dos-xray-522076
- snappy-java-unchecked-chunk-length-dos-xray-522074
- snowflake-connector-python-redos-xray-257185
- sqlparse-stack-exhaustion-dos-jfsa-2024-001031292
- stack-exhaustion-in-json-smart-leads-to-denial-of-service-when-parsing-malformed-json-xray-427633
- tensorflow-python-code-injection-xray-189178
- tensorflow-serving-stacko-dos
- the-reachy-mini-bluetooth-command-handler-is-vulnerable-to-arbitrary-root-script-execution-via-path-traversal-cve-2026-62661
- the-reachy-mini-daemon-is-vulnerable-to-an-unrestricted-file-upload-in-the-media-sounds-upload-api-cve-2026-55419
- the-reachy-mini-wireless-image-is-vulnerable-to-a-local-privilege-escalation-via-an-unrestricted-sudo-systemctl-grant-jfsa-2026-001667223
- txtai-arbitrary-file-write-jfsa-2025-001471363
- ua-cpp-replaceargs-oob-write-xray-75751
- ua-cpp-ua-extensionobject-type-confusion-xray-75752
- ua-cpp-ua-int32-null-deref-xray-75753
- ua-cpp-uaunistring-1-byte-oob-xray-75754
- ua-cpp-uaunistring-infoleak-xray-75755
- ua-cpp-uavariant-null-deref-xray-75756
- ua-cpp-uavariant-oob-read-xray-75757
- ua-cpp-unlimited-file-handles-dos-xray-75758
- ua-net-standard-stack-dos-xray-229139
- ua-net-standard-stack-dos-xray-229142
- undefined-variable-usage-in-proxy-leads-to-remote-denial-of-service-xray-520917
- uri-template-lite-redos-xray-211351
- vanna-prompt-injection-rce-jfsa-2024-001034449
- vector-admin-filter-bypass
- vite-arbitrary-html-file-leak
- vite-arbitrary-private-file-leak
- wandb-weave-server-remote-arbitrary-file-leak-jfsa-2024-001039248
- webfingerjs-blind-ssrf
- wget-shorthand-urls-ssrf-jfsa-2024-001063927
- xss-in-nanohttpd-xray-141192
- yamale-schema-code-injection-xray-182135
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
4 | | - | |
| 4 | + | |
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| |||
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
42 | | - | |
| 42 | + | |
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
| |||
0 commit comments