public
53 known vulnerabilities · 2 critical · 2 high
Flowise: Sensitive Data Leak in public-chatbotConfig
Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 Hour
Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow in Flowise
Budibase: Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected Endpoints
ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions
Astro's server source code is exposed to the public if sourcemaps are enabled
OpenClaw's Chrome extension relay binds publicly due to wildcard treated as loopback
NPM IP package incorrectly identifies some private IP addresses as public
Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled
Flowise Cross-site Scripting in /api/v1/public-chatflows/id
When `ui.isAccessAllowed` is `undefined`, the `adminMeta` GraphQL query is publicly accessible
Malicious code in ua-publication-manager (npm)
Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS
Malicious code in @visiology-public-utilities/language-utils (npm)
Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs
Making all attributes on a content-type public without noticing it
Vite middleware may serve files starting with the same name with the public directory
Malicious code in octavius-public (npm)
Malicious code in public-method-library (npm)
Malicious code in publicrepoui (npm)
Malicious code in aws-public (npm)
fast-jwt: Incomplete fix for CVE-2023-48223: JWT Algorithm Confusion via Whitespace-Prefixed RSA Public Key
n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure
Malicious code in public-tools-and-demos (npm)
ApostropheCMS: publicApiProjection Bypass via project Query Builder in Piece-Type REST API
jsrsasign: DSA signatures or X.509 certificates can be forged via DSA domain-parameter validation in KJUR.crypto.DSA.setPublic
Malicious code in wix-public (npm)
Malicious code in @ginger-team/public-ui (npm)
Malicious code in @stockrepublic/republic-components (npm)
Malicious code in @emilgroup/public-api-sdk-node (npm)
Malicious code in network_security_private_communication_in_a_public_world_solution_manual_pdfzip_best__0sm (npm)
Malicious code in docs-public-api (npm)
Malicious code in public-site-boostmoney-ui (npm)
Malicious code in public-site-cms-ui (npm)
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
NocoDB: Hidden Column Exposure in Public Shared View Endpoints
NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints
Malicious code in autoshipment-public-front (npm)
n8n: Public API Execution Retry Authorization Bypass
Malicious code in @emilgroup/public-api-sdk (npm)
sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey
Malicious code in @metaplex-foundations/umi-public-keys (npm)
Malicious code in @public-for-cdao/hooks (npm)
Malicious code in @antv/gi-public-data (npm)
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
Malicious code in public-portal-ui (npm)