Live feed · Tech
Heuristically tagged from vendor / product / title. Use the chips to switch industries or clear the filter.
Jenkins: Stored XSS vulnerability in node offline cause description
Malicious code in houzidawang807 (npm)
Malicious code in houzidawang806 (npm)
Malicious code in houzidawang808 (npm)
Malicious code in postcss-minify-selector-parser (npm)
Malicious code in class-synth (npm)
Malicious code in postinstall-logger-7x9z (npm)
Malicious code in node-stack-frames (npm)
Malicious code in node-denv (npm)
Malicious code in sheratan_haha (npm)
Malicious code in node-multi-downloader (npm)
Malicious code in node-app-doctor (npm)
We have released version 5.24.0 of the Grafana Operator. This patch includes a CRITICAL severity security fix for a path traversal/privilege escalation vulnerability in the Grafana Operator. ### Summary The Grafana Operator supports l
Malicious code in beamz (npm)
Malicious code in vite-config-react (npm)
Malicious code in vite-config-optimizer (npm)
Malicious code in ecto_module (npm)
tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the prefix, postfix,
Malicious code in @ci-lifecycle-test/postinstall-ping (npm)
Malicious code in acme-widget-layout-utils (PyPI)
Malicious code in dash-grid-normalizer (PyPI)
Malicious code in warp-dependency (npm)
File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection
Malicious code in textwrap-toolkit-stager (PyPI)
@hapi/inert has a static-file confinement bypass via sibling-prefix path
Parse Server's GraphQL "Did you mean ...?" validation suggestions disclose schema to unauthenticated callers
@agenticmail/mcp Missing Authentication for Critical Function
File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames
File Browser has a DoS Vulnerability via Public Login API
File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
Malicious code in ect-472839-ctf (npm)
Malicious code in ect-839201-ctf (npm)
Malicious code in ect-839201 (npm)
Malicious code in ect-654321 (npm)
Malicious code in claudechor (npm)
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
Malicious code in chalk-plus-ts (npm)
Malicious code in chalk-plus-js (npm)
Malicious code in workflow-postgres-setup (npm)
Malicious code in chalk-pro (npm)
Malicious code in jextic-eclib (npm)
Malicious code in vite-plugin-compress-js (npm)
Malicious code in vite-plugin-logo (npm)
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY
esbuild allows arbitrary file read when running the development server on Windows
Malicious code in uprobe (PyPI)
Malicious code in trongapy (PyPI)
Malicious code in tao-subnet-metrics (PyPI)
Malicious code in synago (PyPI)
Malicious code in silly-logger (PyPI)
Malicious code in saas-common-lib-473815 (PyPI)
Malicious code in pywingui (PyPI)
Malicious code in pylogxo (PyPI)
Malicious code in okite (PyPI)
Malicious code in pantheon-toolsets (PyPI)
Malicious code in pantheon-agents (PyPI)
Malicious code in nvidia-nat-semantic-kernel (PyPI)
Malicious code in nagios-xi (PyPI)
Malicious code in mrbios (PyPI)
Malicious code in instructor-mcp (PyPI)
Malicious code in executor-http (PyPI)
Malicious code in crw (PyPI)
Malicious code in goodoltoulas (PyPI)
Malicious code in funcdesc (PyPI)
Malicious code in cubifyanything (PyPI)
Malicious code in executor-engine (PyPI)
Malicious code in coolbox (PyPI)
Malicious code in cmd2func (PyPI)
Malicious code in bt-burn-watch (PyPI)
Malicious code in cch-agent (PyPI)
Malicious code in bittensor-burn-message (PyPI)
Malicious code in aurapro-ui (PyPI)
Malicious code in bramin (PyPI)
Malicious code in bibip-bip (PyPI)
Malicious code in worker-build (npm)
Malicious code in vqlxjmpr (npm)
Malicious code in vite-tsconfig (npm)
Malicious code in vite-svgr (npm)
Malicious code in vite-react-toolkit (npm)
Malicious code in veteran (npm)
Malicious code in typeorm-encrypt (npm)
Malicious code in tw-fluid-type (npm)
Malicious code in ui-weave (npm)
Malicious code in ttspc-server-sample (npm)
Malicious code in ts-build-optimize (npm)
Malicious code in theta-connector (npm)
Malicious code in theta-kit (npm)
Malicious code in tango-app-api-trax (npm)
Malicious code in tailwindcss-merge (npm)
Malicious code in tailwindcss-animotion (npm)
Malicious code in swagger-express-routes (npm)
Malicious code in sea-bound-siren (npm)
Malicious code in sass-formats (npm)
Malicious code in regexp-ts (npm)
Malicious code in react-photo-views (npm)
Malicious code in react-json-chalk (npm)