public
42 known vulnerabilities · 2 critical · 2 high
Flowise: Sensitive Data Leak in public-chatbotConfig
Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow in Flowise
Budibase: Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected Endpoints
Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS
ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions
Astro's server source code is exposed to the public if sourcemaps are enabled
OpenClaw's Chrome extension relay binds publicly due to wildcard treated as loopback
NPM IP package incorrectly identifies some private IP addresses as public
Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled
Flowise Cross-site Scripting in /api/v1/public-chatflows/id
sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey
When `ui.isAccessAllowed` is `undefined`, the `adminMeta` GraphQL query is publicly accessible
Malicious code in ua-publication-manager (npm)
Malicious code in @visiology-public-utilities/language-utils (npm)
Making all attributes on a content-type public without noticing it
Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs
Vite middleware may serve files starting with the same name with the public directory
Malicious code in octavius-public (npm)
Malicious code in public-method-library (npm)
Malicious code in publicrepoui (npm)
Malicious code in aws-public (npm)
fast-jwt: Incomplete fix for CVE-2023-48223: JWT Algorithm Confusion via Whitespace-Prefixed RSA Public Key
Malicious code in @emilgroup/public-api-sdk (npm)
Malicious code in public-tools-and-demos (npm)
ApostropheCMS: publicApiProjection Bypass via project Query Builder in Piece-Type REST API
jsrsasign: DSA signatures or X.509 certificates can be forged via DSA domain-parameter validation in KJUR.crypto.DSA.setPublic
Malicious code in wix-public (npm)
Malicious code in @ginger-team/public-ui (npm)
Malicious code in public-portal-ui (npm)
Malicious code in @emilgroup/public-api-sdk-node (npm)
Malicious code in network_security_private_communication_in_a_public_world_solution_manual_pdfzip_best__0sm (npm)
Malicious code in docs-public-api (npm)
Malicious code in public-site-boostmoney-ui (npm)
Malicious code in public-site-cms-ui (npm)
Malicious code in autoshipment-public-front (npm)
Malicious code in @metaplex-foundations/umi-public-keys (npm)