CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
SmokeDetector intentionally does automatic deployments of updated copies of SmokeDetector without server operator authority.
Misskey before 10.102.4 allows hijacking a user's token.
Fleet before 2.1.2 allows exposure of SMTP credentials.
stacktable.js before 1.0.4 allows XSS.
Dependency-Track before 3.5.1 allows XSS.
invenio-app before 1.1.1 allows host header injection.
invenio-communities before 1.0.0a20 allows XSS.
Tridactyl before 1.16.0 allows fake key events.
invenio-records before 1.2.2 allows XSS.
Pterodactyl before 0.7.14 with 2FA allows credential sniffing.
