Published issues
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
7 packages
- vite
- vitess
- vitetris
- python312Packages.django-vite
- python313Packages.django-vite
- python314Packages.django-vite
- vscode-extensions.vitest.explorer
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
vite
-
==>= 6.0.0, < 6.4.2
-
==>= 8.0.0, < 8.0.5
-
==>= 7.0.0, < 7.3.2
vite-plus
Permalink
CVE-2026-35520
8.8 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
5 packages
- swiftlint
- python312Packages.softlayer
- python313Packages.softlayer
- python314Packages.softlayer
- chickenPackages_5.chickenEggs.ftl
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Pi-hole FTL affected by Remote Code Execution (RCE) via dhcp.leaseTime Newline Injection
Permalink
CVE-2026-35460
4.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Papra has an HTML Injection in Transactional Emails via Unescaped User Display Name
Permalink
CVE-2026-35592
5.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
5 packages
- python312Packages.pyloadapi
- python313Packages.pyloadapi
- python314Packages.pyloadapi
- home-assistant-component-tests.pyload
- tests.home-assistant-component-tests.pyload
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
pyLoad has an Incomplete Tar Path Traversal Fix in UnTar._safe_extractall via os.path.commonprefix Bypass
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
4 packages
- filebrowser-quantum
- python312Packages.filebrowser-safe
- python313Packages.filebrowser-safe
- python314Packages.filebrowser-safe
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
File Browser has a Command Injection via Hook Runner
filebrowser
-
==>= 2.0.0-rc.1, <= 2.63.1
Permalink
CVE-2026-35176
7.1 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
openFPGALoader has a heap buffer overflow in POFParser::parseSection() via crafted .pof file
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs
Permalink
CVE-2026-35044
8.8 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
BentoML has a Server-Side Template Injection via unsandboxed Jinja2 Environment in Dockerfile generation
Permalink
CVE-2026-35170
7.1 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
openFPGALoader has a heap buffer overflow in BitParser::parseHeader() via crafted .bit file