Automatically generated suggestions

Create Draft to queue a suggestion for refinement.

Dismiss to remove a suggestion from the queue.

CVE-2023-44150
7.5 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 1 month, 1 week ago
WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data Exposure

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This issue affects Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: from n/a through 4.13.2.

wp-user-avatar
=<4.13.2

pkgs.wordpressPackages.plugins.wp-user-avatars

CVE-2024-7201
9.8 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 1 month, 1 week ago
Simopro Technology WinMatrix3 Web package - SQL Injection

The login functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.

Web
=<1.2.33.3

pkgs.DisnixWebService

SOAP interface and client for Disnix

pkgs.perlPackages.WebMachine

Perl port of Webmachine

pkgs.perlPackages.WebScraper

Web Scraping Toolkit using HTML and CSS Selectors or XPath expressions

pkgs.perlPackages.MusicBrainz

API to search the musicbrainz.org database

pkgs.perlPackages.JSONWebToken

JSON Web Token (JWT) implementation

pkgs.perl538Packages.WebMachine

Perl port of Webmachine

pkgs.perl538Packages.WebScraper

Web Scraping Toolkit using HTML and CSS Selectors or XPath expressions

pkgs.perl540Packages.WebMachine

Perl port of Webmachine

pkgs.perl540Packages.WebScraper

Web Scraping Toolkit using HTML and CSS Selectors or XPath expressions

pkgs.perl538Packages.MusicBrainz

API to search the musicbrainz.org database

pkgs.perl540Packages.MusicBrainz

API to search the musicbrainz.org database

pkgs.perl538Packages.JSONWebToken

JSON Web Token (JWT) implementation

pkgs.perl540Packages.JSONWebToken

JSON Web Token (JWT) implementation

pkgs.perlPackages.WebServiceLinode

Perl Interface to the Linode.com API

pkgs.perlPackages.NetAsyncWebSocket

Use WebSockets with IO::Async

pkgs.perlPackages.ProtocolWebSocket

WebSocket protocol

pkgs.perl538Packages.WebServiceLinode

Perl Interface to the Linode.com API

pkgs.perl540Packages.WebServiceLinode

Perl Interface to the Linode.com API

pkgs.perl538Packages.NetAsyncWebSocket

Use WebSockets with IO::Async

pkgs.perl538Packages.ProtocolWebSocket

WebSocket protocol

pkgs.perl540Packages.NetAsyncWebSocket

Use WebSockets with IO::Async

pkgs.perl540Packages.ProtocolWebSocket

WebSocket protocol

pkgs.perlPackages.MojoliciousPluginWebpack

Mojolicious <3 Webpack

pkgs.perlPackages.WebServiceValidatorHTMLW3C

Access the W3Cs online HTML validator

pkgs.perl538Packages.MojoliciousPluginWebpack

Mojolicious <3 Webpack

pkgs.perl540Packages.MojoliciousPluginWebpack

Mojolicious <3 Webpack

pkgs.perl538Packages.WebServiceValidatorHTMLW3C

Access the W3Cs online HTML validator

pkgs.perl540Packages.WebServiceValidatorHTMLW3C

Access the W3Cs online HTML validator

pkgs.vscode-extensions.amazonwebservices.amazon-q-vscode

Amazon Q, CodeCatalyst, Local Lambda debug, SAM/CFN syntax, ECS Terminal, AWS resources
Package maintainers: 3
CVE-2024-29069
4.8 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 1 month, 1 week ago
snapd will follow archived symlinks when unpacking a filesystem

In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so can contain symbolic links and other file types. Various file entries within the snap squashfs image (such as icons and desktop files etc) are directly read by snapd when it is extracted. An attacker who could convince a user to install a malicious snap which contained symbolic links at these paths could then cause snapd to write out the contents of the symbolic link destination into a world-readable directory. This in-turn could allow an unprivileged user to gain access to privileged information.

snapd
<2.62

pkgs.snapdragon-profiler

Profiler for Android devices running Snapdragon chips
CVE-2024-40873
4.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): HIGH
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 1 month, 1 week ago
XSS in Secure Access administrative console

There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.07. Attackers with system administrator permissions can interfere with another system administrator’s use of the publishing UI when the administrators are editing the same management object. The scope is unchanged, there is no loss of confidentiality. Impact to system availability is none, impact to system integrity is high.

Console
<13.07

pkgs.haskellPackages.ConsoleAsk

Simple CLI user input library

pkgs.dotnetPackages.NUnitConsole

pkgs.perlPackages.PlackMiddlewareConsoleLogger

Write logs to Firebug or Webkit Inspector

pkgs.perl538Packages.PlackMiddlewareConsoleLogger

Write logs to Firebug or Webkit Inspector

pkgs.perl540Packages.PlackMiddlewareConsoleLogger

Write logs to Firebug or Webkit Inspector
CVE-2024-1724
6.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 1 month, 1 week ago
snapd allows $HOME/bin symlink

In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatically added to the users PATH. An attacker who could convince a user to install a malicious snap which used the 'home' plug could use this vulnerability to install arbitrary scripts into the users PATH which may then be run by the user outside of the expected snap sandbox and hence allow them to escape confinement.

snapd
<2.62

pkgs.snapdragon-profiler

Profiler for Android devices running Snapdragon chips
CVE-2024-29068
5.8 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): HIGH
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 1 month, 1 week ago
snapd non-regular file indefinite blocking read

In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system image and so can contain files that are non-regular files (such as pipes or sockets etc). Various file entries within the snap squashfs image (such as icons etc) are directly read by snapd when it is extracted. An attacker who could convince a user to install a malicious snap which contained non-regular files at these paths could then cause snapd to block indefinitely trying to read from such files and cause a denial of service.

snapd
<2.62

pkgs.snapdragon-profiler

Profiler for Android devices running Snapdragon chips
CVE-2024-37061
8.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 1 month, 1 week ago
Remote Code Execution can occur in versions of the MLflow …

Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run.

mlflow
=<*

pkgs.mlflow-server

Open source platform for the machine learning lifecycle

pkgs.python312Packages.mlflow

Open source platform for the machine learning lifecycle

pkgs.python313Packages.mlflow

Open source platform for the machine learning lifecycle

pkgs.python312Packages.sagemaker-mlflow

MLFlow plugin for SageMaker

pkgs.python313Packages.sagemaker-mlflow

MLFlow plugin for SageMaker
Package maintainers: 2
CVE-2024-37053
8.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 1 month, 1 week ago
Deserialization of untrusted data can occur in versions of the …

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.

mlflow
=<*

pkgs.mlflow-server

Open source platform for the machine learning lifecycle

pkgs.python312Packages.mlflow

Open source platform for the machine learning lifecycle

pkgs.python313Packages.mlflow

Open source platform for the machine learning lifecycle

pkgs.python312Packages.sagemaker-mlflow

MLFlow plugin for SageMaker

pkgs.python313Packages.sagemaker-mlflow

MLFlow plugin for SageMaker
Package maintainers: 2
CVE-2024-37052
8.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 1 month, 1 week ago
Deserialization of untrusted data can occur in versions of the …

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.

mlflow
=<*

pkgs.mlflow-server

Open source platform for the machine learning lifecycle

pkgs.python312Packages.mlflow

Open source platform for the machine learning lifecycle

pkgs.python313Packages.mlflow

Open source platform for the machine learning lifecycle

pkgs.python312Packages.sagemaker-mlflow

MLFlow plugin for SageMaker

pkgs.python313Packages.sagemaker-mlflow

MLFlow plugin for SageMaker
Package maintainers: 2
CVE-2024-37060
8.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 1 month, 1 week ago
Deserialization of untrusted data can occur in versions of the …

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on an end user’s system when run.

mlflow
=<*

pkgs.mlflow-server

Open source platform for the machine learning lifecycle

pkgs.python312Packages.mlflow

Open source platform for the machine learning lifecycle

pkgs.python313Packages.mlflow

Open source platform for the machine learning lifecycle

pkgs.python312Packages.sagemaker-mlflow

MLFlow plugin for SageMaker

pkgs.python313Packages.sagemaker-mlflow

MLFlow plugin for SageMaker
Package maintainers: 2