
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Command Injection
@syncfusion/ej2-base is an A common package of Essential JS 2 base libraries, methods and class definitions
Affected versions of this package are vulnerable to Command Injection via the use of child_process.exec function which uses the package name from package.json without escaping before being concatenated into the command string. An attacker can execute arbitrary operating system commands by providing crafted input locally.
Arbitrary Argument Injection
ansible-core is an a radically simple IT automation system. It handles configuration management, application deployment, cloud provisioning, ad-hoc task execution, network automation, and multi-node orchestration. Ansible makes complex changes like zero-downtime rolling updates with load balancers easy.
Affected versions of this package are vulnerable to Arbitrary Argument Injection via the collection install process when handling git sources without proper argument separation. An attacker can execute arbitrary commands by supplying a crafted git source URI containing malicious arguments. This is only exploitable if collections are installed from untrusted or non-HTTPS git sources.
Missing Authorization
org.graylog2:graylog2-server is a log management platform.
Affected versions of this package are vulnerable to Missing Authorization via the duplicate handler in EventDefinitionsResource for the POST /events/definitions/{definitionId}/duplicate endpoint. An attacker can clone any event definition by sending a duplicate request for a target definitionId while holding only the general eventdefinitions:create permission. This lets an authenticated low-privilege user read private event definitions they are not allowed to access, exposing detection queries, aggregation thresholds, grouping fields, schedules, and notification bindings through the cloned definition.
Recent vulnerabilities disclosed by Snyk
- M
Prototype Pollution in mongo-object (npm)- M
Regular Expression Denial of Service (ReDoS) in angular-resource (npm)- C
Code Execution in expr-eval (npm)- M
Uncaught Exception in ts-deepmerge (npm)- H
Command Injection in degit (npm)
Snyk security
researchers
have disclosed
3501
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.





