dellalibera - Overview (original) (raw)

123

GHSA-g7r4-m6w7-qqqr

Path Traversal

esbuild

Javascript

122

GHSA-wfhj-v5g7-vr7g

Unsafe Deserialization

org.deeplearning4j:deeplearning4j (ML Library)

Java

121

CVE-2025-69256
GHSA-rwc2-f344-q6w6

Command Injection / RCE

serverless (MCP Server)

JavaScript

120

GHSA-4fmr-m2w5-f73j

Command Injection / RCE

port-kill-mcp

JavaScript

119

CVE-2025-61785
GHSA-vg2r-rmgp-cgqj

Permission Model Bypass

deno

Rust

118

CVE-2025-61786
GHSA-qq26-84mh-26j9

Permission Model Bypass

deno

Rust

117

CVE-2025-53967
GHSA-gxw4-4fc5-9gr5

Command Injection / RCE

figma-developer-mcp

JavaScript

116

CVE-2025-55152
GHSA-r3v7-pc4g-7xp9

Regular Expression Denial of Service (ReDoS)

@oakserver/oak

JavaScript

115

CVE-2025-54798
GHSA-52f5-9888-hmc6

Arbitrary temporary file / directory write

tmp

JavaScript

114

CVE-2025-54387
GHSA-mm3p-j368-7jcr

Path Traversal

ipx

JavaScript

113

CVE-2025-53832
GHSA-xj5p-8h7g-76m7

Command Injection / RCE

@translated/lara-mcp

JavaScript

112

CVE-2025-54073
GHSA-vf9j-h32g-2764

Command Injection / RCE

mcp-package-docs

JavaScript

111

CVE-2025-53355
GHSA-gjv4-ghm7-q58q

Command Injection / RCE

mcp-server-kubernetes

JavaScript

110

CVE-2025-53372
GHSA-5w57-2ccq-8w95

Command Injection / RCE

node-code-sandbox-mcp

JavaScript

109

CVE-2025-53107
GHSA-3q26-f695-pp76

Command Injection / RCE

@cyanheads/git-mcp-server

JavaScript

108

GHSA-m5qc-5hw7-8vg7

Denial of Service (DoS)

image-size

JavaScript

107

GHSA-pf56-h9qf-rxq4

Stored Cross-Site Scripting (XSS)

@saltcorn/server

JavaScript

106

CVE-2024-47818
GHSA-43f3-h63w-p6f6

Path Traversal

@saltcorn/server

JavaScript

105

GHSA-78p3-fwcq-62c2

RCE/SQLi via Prototype Pollution

@saltcorn/server

JavaScript

104

GHSA-fm76-w8jw-xf8m

Remote Code Execution (RCE)

@saltcorn/plugins-loader

JavaScript

103

GHSA-277h-px4m-62q8

Path Traversal

@saltcorn/server

JavaScript

102

GHSA-cfqx-f43m-vfh7

Exposure of Information Through Directory Listing

@saltcorn/server

JavaScript

101

CVE-2024-21526

Denial of Service (DoS)

speaker

JavaScript

100

CVE-2024-21525

Buffer Overflow

node-twain

JavaScript

99

CVE-2024-21524

Out-of-bounds Read

node-stringbuilder

JavaScript

98

CVE-2024-21523

Denial of Service (DoS)

images

JavaScript

97

CVE-2024-21522

Improper Validation of Array Index

audify

JavaScript

96

CVE-2024-21521

Denial of Service (DoS)

@discordjs/opus

JavaScript

95

CVE-2024-3817

Command Injection

hashicorp/go-getter

Go

94

CVE-2023-26148

CRLF Injection

libhv

C/C++

93

CVE-2023-26147

HTTP Response Splitting

libhv

C/C++

92

CVE-2023-26146

Cross-Site Scripting (XSS)

libhv

C/C++

91

CVE-2023-26142

HTTP Response Splitting

Crow

C/C++

90

CVE-2023-26138

CRLF Injection

drogon

C/C++

89

CVE-2023-26137

HTTP Response Splitting

drogon

C/C++

88

CVE-2022-25883

Regular Expression Denial of Service (ReDoS)

semver

JavaScript

87

CVE-2023-26131

Cross-Site Scripting (XSS)

xyproto/algernon

Go

86

CVE-2023-26130

CRLF Injection

cpp-httplib

C/C++

85

Link

Cross-Site Scripting (XSS)

grafana/grafana-json-datasource

JavaScript

84

CVE-2023-26103

Regular Expression Denial of Service (ReDoS)

deno

Rust

83

CVE-2023-0040

CRLF Injection

async-http-client

Swift

82

CVE-2022-3918

CRLF Injection

apple/swift-corelibs-foundation

Swift

81

CVE-2022-3215

HTTP Response Splitting

apple/swift-nio

Swift

80

CVE-2022-24065

Command Injection

cookiecutter

Python

79

CVE-2022-26945

Command Injection

hashicorp/go-getter

Go

78

CVE-2022-25878

Prototype Pollution

protobufjs

JavaScript

77

CVE-2022-25865

Command Injection

workspace-tools

JavaScript

76

CVE-2022-21190

Prototype Pollution

convict

JavaScript

75

CVE-2022-29184

Remote Code Execution (RCE)

gocd

Java

74

CVE-2022-21189

Prototype Pollution

dexie

JavaScript

73

CVE-2022-25303

Cross-Site Scripting (XSS)

whoogle-search

Python

72

CVE-2022-25866

Command Injection

czproject/git-php

PHP

71

CVE-2022-25648

Command Injection

git

Ruby

70

CVE-2022-25766

Remote Code Execution (RCE)

ungit

JavaScript

69

CVE-2022-24440

Command Injection

cocoapods-downloader

Ruby

68

CVE-2022-24433

Command Injection

simple-git

JavaScript

67

CVE-2022-23915

Remote Code Execution (RCE)

Weblate

Python

66

CVE-2022-21803

Prototype Pollution

nconf

JavaScript

65

CVE-2022-21235

Command Injection

Masterminds/vcs

Go

64

CVE-2022-21223

Command Injection

cocoapods-downloader

Ruby

63

CVE-2022-21187

Command Injection

libvcs

Python

62

Link

Remote Code Execution (RCE)

mozilla/pontoon

Python

61

CVE-2021-23820

Prototype Pollution

json-pointer

JavaScript

60

CVE-2021-23807

Prototype Pollution

jsonpointer

JavaScript

59

CVE-2021-23784

Cross-Site Scripting (XSS)

tempura

JavaScript

58

CVE-2021-23682

Prototype Pollution

litespeed.js

JavaScript

58

CVE-2021-23682

Prototype Pollution

appwrite/server-ce

JavaScript

57

CVE-2021-23624

Prototype Pollution

dotty

JavaScript

56

CVE-2021-23597

Denial of Service (DoS)

fastify-multipart

JavaScript

55

CVE-2021-23509

Prototype Pollution

json-ptr

JavaScript

54

CVE-2021-23472

Cross-Site Scripting (XSS)

bootstrap-table

JavaScript

53

CVE-2021-23447

Cross-Site Scripting (XSS)

teddy

JavaScript

52

CVE-2021-23445

Cross-Site Scripting (XSS)

datatables.net

JavaScript

51

CVE-2021-23444

Prototype Pollution

jointjs

JavaScript

50

CVE-2021-23443

Cross-Site Scripting (XSS)

edge.js

JavaScript

49

CVE-2021-23440

Prototype Pollution

set-value

JavaScript

48

CVE-2021-23438

Prototype Pollution

mpath

JavaScript

47

CVE-2021-23436

Prototype Pollution

immer

JavaScript

46

CVE-2021-23434

Prototype Pollution

object-path

JavaScript

45

CVE-2021-23390

Arbitrary Code Execution

total4

JavaScript

44

CVE-2021-23389

Arbitrary Code Execution

total.js

JavaScript

43

CVE-2021-23358

Arbitrary Code Execution

underscore

JavaScript

42

CVE-2021-23352

Command Injection

madge

JavaScript

41

CVE-2021-23335

LDAP Injection

is-user-valid

JavaScript

40

CVE-2020-8186

Command Injection

devcert

JavaScript

39

CVE-2020-7792

Prototype Pollution

mout

JavaScript

38

CVE-2020-7789

Command Injection

node-notifier

JavaScript

37

CVE-2020-7777

Arbitrary Code Execution

jsen

JavaScript

36

CVE-2020-7772

Prototype Pollution

doc-path

JavaScript

35

CVE-2020-7770

Prototype Pollution

json8

JavaScript

34

CVE-2020-7766

Prototype Pollution

json-ptr

JavaScript

33

CVE-2020-7746

Prototype Pollution

chart.js

JavaScript

32

CVE-2020-7743

Prototype Pollution

mathjs

JavaScript

31

CVE-2020-7742

Prototype Pollution

simpl-schema

JavaScript

30

CVE-2020-28499

Prototype Pollution

merge

JavaScript

29

CVE-2020-28495

Prototype Pollution

total.js

JavaScript

28

CVE-2020-28494

Command Injection

total.js

JavaScript

27

CVE-2020-28480

Prototype Pollution

jointjs

JavaScript

26

CVE-2020-28478

Prototype Pollution

gsap

JavaScript

25

CVE-2020-28477

Prototype Pollution

immer

JavaScript

24

CVE-2020-28464

Arbitrary Code Execution

djv

JavaScript

23

CVE-2020-28458

Prototype Pollution

datatables.net

JavaScript

22

CVE-2020-28442

Prototype Pollution

js-data

JavaScript

21

Snyk Advisory

Prototype Pollution

style-dictionary

JavaScript

20

Snyk Advisory

Prototype Pollution

highcharts

JavaScript

19

Snyk Advisory

Prototype Pollution

jiff

JavaScript

18

Snyk Advisory

Prototype Pollution

i18next

JavaScript

17

Snyk Advisory

Unsafe Deserialization

props

JavaScript

16

HackerOne Report

Prototype Pollution

@firebase/util

JavaScript

15

HackerOne Report

LDAP Injection

meemo-app

JavaScript

14

HackerOne Report

LDAP Injection

cloudron-surfer

JavaScript

13

HackerOne Report

Command Injection

wireguard-wrapper

JavaScript

12

HackerOne Report

Prototype Pollution

plain-object-merge

JavaScript

11

HackerOne Report

Prototype Pollution

extend-merge

JavaScript

10

HackerOne Report

Command Injection

gfc

JavaScript

9

HackerOne Report

Command Injection

diskstats

JavaScript

8

HackerOne Report

Prototype Pollution

objtools

JavaScript

7

HackerOne Report

Prototype Pollution

keyd

JavaScript

6

HackerOne Report

Cross-Site Scripting (XSS)

flsaba

JavaScript

5

HackerOne Report

Command Injection

extra-asciinema

JavaScript

4

HackerOne Report

Command Injection

vboxmanage.js

JavaScript

3

HackerOne Report

Command Injection

extra-ffmpeg

JavaScript

2

HackerOne Report

Prototype Pollution

object-path-set

JavaScript

1

HackerOne Report

Command Injection

xps

JavaScript