Hi 👋
| N° | CVE | Severity | Description |
|---|---|---|---|
| 1 | CVE-2022-1993 | High | Path Traversal vulnerability on the endpoint '/info/refs' in gogs/gogs |
| 2 | CVE-2022-3607 | Medium | ZipSlip Symlink variant allows to read any file within OctoPrint Box in octoprint/octoprint |
| 3 | CVE-2022-23530 | Medium | GuardDog vulnerable to arbitrary file write when scanning a specially-crafted remote PyPI package |
| 4 | CVE-2023-25804 | Medium | Limited Path Traversal in name parameter hap-wi/roxy-wi |
| 5 | CVE-2023-25803 CVE-2023-25802 | High | Directory Traversal vulnerability in hap-wi/roxy-wi |
| 6 | CVE-2022-23522 | High | Arbitrary File Write when Extracting Tarballs retrieved from a remote location using shutil.unpack_archive() |
| 7 | CVE-2023-30620 | High | Arbitrary File Write when Extracting a Remotely retrieved Tarball using Tarfile.extractall() in mindsdb/mindsdb |
| 8 | CVE-2023-31131 | Medium | Arbitrary File Write when Extracting Tarballs retrieved from a remote location using shutil.unpack_archive() in greenplum-db/gpdb |
| 9 | CVE-2023-35932 | High | Configuration Injection in tanghaibao/jcvi due to unsanitized user input |
| 10 | GHSA-373w-rj84-pv6x | Low | Hostname blocklist does not block FQDNs in IncludeSecurity/safeurl-python |
| 11 | CVE-2023-39911 | Medium | --- |
| 12 | CVE-2023-42183 | Low | A Post-Unicode Normalization Vulnerability in lockss/lockss-daemon |
| 13 | CVE-2023-41889 | Medium | Late-Unicode normalization vulnerability in shirasagi/shirasagi |
| 14 | CVE-2023-52081 | Low | Late-Unicode normalization vulnerability in ewen-lbh/ffcss |
| 15 | CVE-2024-21623 | Critical | Arbitrary Expression Injection in github workflow leads to Command execution & leaking secrets |
| 16 | CVE-2024-23343 | Medium | |
| 17 | CVE-2024-23826 | High | Uploading an image with a specific filename causes a server-side DoS |
| 18 | CVE-2024-24759 | Critical | -- |
✨ Feel free to subscribe to my little newsletter sim4n6.beehiiv.com.
💬 By the way, I'm looking for a remote opportunity ...
⚡sim4n6 AT gmail.com ⚡




