🛡️Comprehensive Vulnerability Research

Vulnerability Database

Discover, analyze, and understand security vulnerabilities with our comprehensive research database

246
Total CVEs
54
Critical
146
High
46
Medium
0
Low
🔍
Filter by severity:
246 of 246 vulnerabilities

CVE-2021-44228

CRITICAL

Remote Code Execution (Log4Shell) in log4j (VIBE-MAV-LOG4J-7242330)

CVSS 3.1: 10/10
Published: August 21, 2025

A critical severity vulnerability has been identified in Apache Log4j. The Log4Shell (CVE-2021-44228) vulnerability allows remote code execution through malicious JNDI lookups, posing unprecedented...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2021-44228

CRITICAL

Remote Code Execution (Log4Shell) in log4j (VIBE-MAV-LOG4J-78348228)

CVSS 3.1: 10/10
Published: August 21, 2025

A critical severity vulnerability has been identified in log4j (maven ecosystem). Remote Code Execution (Log4Shell) poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2021-44228

CRITICAL

Remote Code Execution (Log4Shell) in log4j (VIBE-MAV-LOG4J-46549088)

CVSS 3.1: 10/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in log4j (maven ecosystem). Remote Code Execution (Log4Shell) poses significant security risks requiring immediate attention and represen...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-24771

CRITICAL

Prototype Pollution in node-forge (VIBE-NPM-NODEFORGE-983163)

CVSS 3.1: 9.8/10
Published: March 18, 2022

Prototype Pollution in node-forge (VIBE-NPM-NODEFORGE-983163) vulnerability affecting node-forge package, versions < latest. Classification: CWE: CWE-347. This critical security issue was introduce...

Affected Systems:
< latest
Discovered: March 18, 2022
Last Modified: August 21, 2025View Details →

CVE-2022-43441

CRITICAL

Remote Code Execution in sqlite3 (VIBE-NPM-SQLITE3-71937405)

CVSS 3.1: 9.8/10
Published: March 16, 2023

Remote Code Execution in sqlite3 (VIBE-NPM-SQLITE3-71937405) vulnerability affecting sqlite3 package, versions < latest. Classification: CWE: CWE-915. This critical security issue was introduced on...

Affected Systems:
< latest
Discovered: March 16, 2023
Last Modified: August 21, 2025View Details →

CVE-2022-23812

CRITICAL

Malicious Code Injection in node-ipc (VIBE-NPM-NODEIPC-15094218)

CVSS 3.1: 9.8/10
Published: March 16, 2022

Malicious Code Injection in node-ipc (VIBE-NPM-NODEIPC-15094218) vulnerability affecting node-ipc package, versions < latest. Classification: CWE: NVD-CWE-Other. This critical security issue was in...

Affected Systems:
< latest
Discovered: March 16, 2022
Last Modified: August 21, 2025View Details →

CVE-2022-34265

CRITICAL

SQL Injection in django (VIBE-PIP-DJANGO-10679177)

CVSS 3.1: 9.8/10
Published: July 4, 2022

SQL Injection in django (VIBE-PIP-DJANGO-10679177) vulnerability affecting django package, versions < latest. Classification: CWE: CWE-89. This critical security issue was introduced on 2022-07-04 ...

Affected Systems:
< latest
Discovered: July 4, 2022
Last Modified: August 21, 2025View Details →

CVE-2023-43654

CRITICAL

Deserialization of Untrusted Data in pytorch (VIBE-PIP-PYTORCH-9793521)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Deserialization of Untrusted Data in pytorch (VIBE-PIP-PYTORCH-9793521) vulnerability affecting pytorch package, versions < latest. This critical security issue was introduced on 2025-08-21T06:02:...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-38898

CRITICAL

Arbitrary Code Execution in pyyaml (VIBE-PIP-PYYAML-72856627)

CVSS 3.1: 9.8/10
Published: August 15, 2023

Arbitrary Code Execution in pyyaml (VIBE-PIP-PYYAML-72856627) vulnerability affecting pyyaml package, versions < latest. Classification: CWE: NVD-CWE-Other. This critical security issue was introdu...

Affected Systems:
< latest
Discovered: August 15, 2023
Last Modified: August 21, 2025View Details →

CVE-2023-35116

CRITICAL

Deserialization in jackson-databind (VIBE-MAV-JACKSONDATABIND-98914489)

CVSS 3.1: 9.8/10
Published: June 14, 2023

Deserialization in jackson-databind (VIBE-MAV-JACKSONDATABIND-98914489) vulnerability affecting jackson-databind package, versions < latest. Classification: CWE: CWE-770. This critical security iss...

Affected Systems:
< latest
Discovered: June 14, 2023
Last Modified: August 21, 2025View Details →

CVE-2023-42794

CRITICAL

Remote Code Execution in apache-commons (VIBE-MAV-APACHECOMMONS-51713308)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Remote Code Execution in apache-commons (VIBE-MAV-APACHECOMMONS-51713308) vulnerability affecting apache-commons package, versions < latest. This critical security issue was introduced on 2025-08-...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-50164

CRITICAL

Remote Code Execution in struts (VIBE-MAV-STRUTS-44469496)

CVSS 3.1: 9.8/10
Published: December 7, 2023

Remote Code Execution in struts (VIBE-MAV-STRUTS-44469496) vulnerability affecting struts package, versions < latest. Classification: CWE: CWE-552. This critical security issue was introduced on 20...

Affected Systems:
< latest
Discovered: December 7, 2023
Last Modified: August 21, 2025View Details →

CVE-2023-25809

CRITICAL

Container Escape in github.com/containerd/containerd (VIBE-GOL-GITHUBCOMCONTAI-37411740)

CVSS 3.1: 9.8/10
Published: August 21, 2025

A critical severity vulnerability has been identified in github.com/containerd/containerd. Security Vulnerability poses significant security risks requiring immediate attention and coordinated orga...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-39326

CRITICAL

Authentication Bypass in github.com/etcd-io/etcd (VIBE-GOL-GITHUBCOMETCDIO-64393677)

CVSS 3.1: 9.8/10
Published: August 21, 2025

A critical severity vulnerability has been identified in github.com/etcd-io/etcd. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizationa...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-37466

CRITICAL

Sandbox Escape in vm2 (VIBE-NPM-VM2-72048872)

CVSS 3.1: 9.8/10
Published: August 21, 2025

A critical severity vulnerability has been identified in vm2. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-43441

CRITICAL

Remote Code Execution in sqlite3 (VIBE-NPM-SQLITE3-70831083)

CVSS 3.1: 9.8/10
Published: August 21, 2025

A critical severity vulnerability has been identified in sqlite3. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-47248

CRITICAL

Arbitrary Code Execution in pandas (VIBE-PIP-PANDAS-75196995)

CVSS 3.1: 9.8/10
Published: August 21, 2025

A critical severity vulnerability has been identified in pandas. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-22965

CRITICAL

Remote Code Execution in spring-boot (VIBE-MAV-SPRINGBOOT-26779738)

CVSS 3.1: 9.8/10
Published: August 21, 2025

A critical severity vulnerability has been identified in spring-boot. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-35116

CRITICAL

Deserialization in jackson-databind (VIBE-MAV-JACKSONDATABIND-40497271)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in jackson-databind (maven ecosystem). Deserialization poses significant security risks requiring immediate attention and represents a cr...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-50164

CRITICAL

Remote Code Execution in struts (VIBE-MAV-STRUTS-41957965)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in struts (maven ecosystem). Remote Code Execution poses significant security risks requiring immediate attention and represents a critic...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-25809

CRITICAL

Container Escape in github.com/containerd/containerd (VIBE-GOL-GITHUBCOMCONTAI-5998123)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in github.com/containerd/containerd (golang ecosystem). Container Escape poses significant security risks requiring immediate attention a...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-24771

CRITICAL

Prototype Pollution in node-forge (VIBE-NPM-NODEFORGE-45802467)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in node-forge (npm ecosystem). Prototype Pollution poses significant security risks requiring immediate attention and represents a critic...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-34265

CRITICAL

SQL Injection in django (VIBE-PIP-DJANGO-74788044)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in django (pip ecosystem). SQL Injection poses significant security risks requiring immediate attention and represents a critical attack ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-43654

CRITICAL

Deserialization of Untrusted Data in pytorch (VIBE-PIP-PYTORCH-26618798)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in pytorch (pip ecosystem). Deserialization of Untrusted Data poses significant security risks requiring immediate attention and represen...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-35116

CRITICAL

Deserialization in jackson-databind (VIBE-MAV-JACKSONDATABIND-99169130)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in jackson-databind (maven ecosystem). Deserialization poses significant security risks requiring immediate attention and represents a cr...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26464

CRITICAL

Remote Code Execution in log4js (VIBE-NPM-LOG4JS-26154079)

CVSS 3.1: 9.8/10
Published: August 21, 2025

A critical severity vulnerability has been identified in log4js (npm ecosystem). Remote Code Execution poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-37466

CRITICAL

Sandbox Escape in vm2 (VIBE-NPM-VM2-31298268)

CVSS 3.1: 9.8/10
Published: August 21, 2025

A critical severity vulnerability has been identified in vm2 (npm ecosystem). Sandbox Escape poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-22965

CRITICAL

Remote Code Execution in spring-boot (VIBE-MAV-SPRINGBOOT-96030837)

CVSS 3.1: 9.8/10
Published: August 21, 2025

A critical severity vulnerability has been identified in spring-boot (maven ecosystem). Remote Code Execution poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26143

CRITICAL

Command Injection in git-interface (VIBE-NPM-GITINTERFACE-87563435)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Threat intelligence assessment identifies a critical severity vulnerability in git-interface that represents an active and emerging threat vector. This security exposure provides multiple exploitat...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26143

CRITICAL

Command Injection in git-interface (VIBE-NPM-GITINTERFACE-77355267)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Threat intelligence assessment identifies a critical severity vulnerability in git-interface that represents an active and emerging threat vector. This security exposure provides multiple exploitat...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26464

CRITICAL

Remote Code Execution in log4js (VIBE-NPM-LOG4JS-81859765)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in log4js (npm ecosystem). Remote Code Execution poses significant security risks requiring immediate attention and represents a critical...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-22794

CRITICAL

SQL Injection in rails (VIBE-RUB-RAILS-62382868)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in rails (rubygems ecosystem). SQL Injection poses significant security risks requiring immediate attention and represents a critical att...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-37466

CRITICAL

Sandbox Escape in vm2 (VIBE-NPM-VM2-19443775)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in vm2 (npm ecosystem). Sandbox Escape poses significant security risks requiring immediate attention and represents a critical attack ve...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-47248

CRITICAL

Arbitrary Code Execution in pandas (VIBE-PIP-PANDAS-221676)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in pandas (pip ecosystem). Arbitrary Code Execution poses significant security risks requiring immediate attention and represents a criti...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-42794

CRITICAL

Remote Code Execution in apache-commons (VIBE-MAV-APACHECOMMONS-20749614)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in apache-commons (maven ecosystem). Remote Code Execution poses significant security risks requiring immediate attention and represents ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-25809

CRITICAL

Container Escape in github.com/containerd/containerd (VIBE-GOL-GITHUBCOMCONTAI-70787596)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in github.com/containerd/containerd (golang ecosystem). Container Escape poses significant security risks requiring immediate attention a...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-39326

CRITICAL

Authentication Bypass in github.com/etcd-io/etcd (VIBE-GOL-GITHUBCOMETCDIO-41341783)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in github.com/etcd-io/etcd (golang ecosystem). Authentication Bypass poses significant security risks requiring immediate attention and r...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-22794

CRITICAL

SQL Injection in rails (VIBE-RUB-RAILS-81875551)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in rails (rubygems ecosystem). SQL Injection poses significant security risks requiring immediate attention and represents a critical att...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26143

CRITICAL

Command Injection in git-interface (VIBE-NPM-GITINTERFACE-54677189)

CVSS 3.1: 9.8/10
Published: August 21, 2025

In the shadowy world of cybersecurity, a new threat emerges from git-interface. This critical severity vulnerability opens doors that sophisticated attackers have been waiting to exploit.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-47248

CRITICAL

Arbitrary Code Execution in pandas (VIBE-PIP-PANDAS-39524326)

CVSS 3.1: 9.8/10
Published: August 21, 2025

A critical severity vulnerability has been identified in pandas (pip ecosystem). Arbitrary Code Execution poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26143

CRITICAL

Command Injection in git-interface (VIBE-NPM-GITINTERFACE-27610517)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Threat intelligence assessment identifies a critical severity vulnerability in git-interface that represents an active and emerging threat vector. This security exposure provides multiple exploitat...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-24771

CRITICAL

Prototype Pollution in node-forge (VIBE-NPM-NODEFORGE-91476164)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in node-forge (npm ecosystem). Prototype Pollution poses significant security risks requiring immediate attention and represents a critic...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-23812

CRITICAL

Malicious Code Injection in node-ipc (VIBE-NPM-NODEIPC-44140213)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in node-ipc (npm ecosystem). Malicious Code Injection poses significant security risks requiring immediate attention and represents a cri...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-34265

CRITICAL

SQL Injection in django (VIBE-PIP-DJANGO-68458543)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in django (pip ecosystem). SQL Injection poses significant security risks requiring immediate attention and represents a critical attack ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-43654

CRITICAL

Deserialization of Untrusted Data in pytorch (VIBE-PIP-PYTORCH-81104620)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in pytorch (pip ecosystem). Deserialization of Untrusted Data poses significant security risks requiring immediate attention and represen...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-38898

CRITICAL

Arbitrary Code Execution in pyyaml (VIBE-PIP-PYYAML-16281369)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in pyyaml (pip ecosystem). Arbitrary Code Execution poses significant security risks requiring immediate attention and represents a criti...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-42794

CRITICAL

Remote Code Execution in apache-commons (VIBE-MAV-APACHECOMMONS-22118188)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in apache-commons (maven ecosystem). Remote Code Execution poses significant security risks requiring immediate attention and represents ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-39326

CRITICAL

Authentication Bypass in github.com/etcd-io/etcd (VIBE-GOL-GITHUBCOMETCDIO-9252909)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in github.com/etcd-io/etcd (golang ecosystem). Authentication Bypass poses significant security risks requiring immediate attention and r...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26464

CRITICAL

Remote Code Execution in log4js (VIBE-NPM-LOG4JS-37181651)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in log4js (npm ecosystem). Remote Code Execution poses significant security risks requiring immediate attention and represents a critical...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-43441

CRITICAL

Remote Code Execution in sqlite3 (VIBE-NPM-SQLITE3-63967858)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in sqlite3 (npm ecosystem). Remote Code Execution poses significant security risks requiring immediate attention and represents a critica...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-23812

CRITICAL

Malicious Code Injection in node-ipc (VIBE-NPM-NODEIPC-38984727)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in node-ipc (npm ecosystem). Malicious Code Injection poses significant security risks requiring immediate attention and represents a cri...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-38898

CRITICAL

Arbitrary Code Execution in pyyaml (VIBE-PIP-PYYAML-40455104)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in pyyaml (pip ecosystem). Arbitrary Code Execution poses significant security risks requiring immediate attention and represents a criti...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-22965

CRITICAL

Remote Code Execution in spring-boot (VIBE-MAV-SPRINGBOOT-43968764)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in spring-boot (maven ecosystem). Remote Code Execution poses significant security risks requiring immediate attention and represents a c...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-50164

CRITICAL

Remote Code Execution in struts (VIBE-MAV-STRUTS-74416314)

CVSS 3.1: 9.8/10
Published: August 21, 2025

Security analysis reveals a critical severity vulnerability in struts (maven ecosystem). Remote Code Execution poses significant security risks requiring immediate attention and represents a critic...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-22578

HIGH

SQL Injection in sequelize (VIBE-NPM-SEQUELIZE-41229457)

CVSS 3.1: 8.8/10
Published: February 16, 2023

SQL Injection in sequelize (VIBE-NPM-SEQUELIZE-41229457) vulnerability affecting sequelize package, versions < latest. Classification: CWE: CWE-790. This critical security issue was introduced on 2...

Affected Systems:
< latest
Discovered: February 16, 2023
Last Modified: August 21, 2025View Details →

CVE-2023-44271

HIGH

Buffer Overflow in pillow (VIBE-PIP-PILLOW-14390497)

CVSS 3.1: 8.8/10
Published: November 3, 2023

Buffer Overflow in pillow (VIBE-PIP-PILLOW-14390497) vulnerability affecting pillow package, versions < latest. Classification: CWE: CWE-770. This critical security issue was introduced on 2023-11-...

Affected Systems:
< latest
Discovered: November 3, 2023
Last Modified: August 21, 2025View Details →

CVE-2023-42789

HIGH

SQL Injection in hibernate (VIBE-MAV-HIBERNATE-74805155)

CVSS 3.1: 8.8/10
Published: March 12, 2024

SQL Injection in hibernate (VIBE-MAV-HIBERNATE-74805155) vulnerability affecting hibernate package, versions < latest. Classification: CWE: CWE-787. This critical security issue was introduced on 2...

Affected Systems:
< latest
Discovered: March 12, 2024
Last Modified: August 21, 2025View Details →

CVE-2023-3955

HIGH

Privilege Escalation in k8s.io/kubernetes (VIBE-GOL-K8SIOKUBERNETES-24932123)

CVSS 3.1: 8.8/10
Published: August 21, 2025

A high severity vulnerability has been identified in k8s.io/kubernetes. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-22794

HIGH

SQL Injection in Rails ActiveRecord

CVSS 3.1: 8.8/10
Published: February 10, 2023

SQL Injection vulnerability affecting Rails package, versions < 6.1.7.3.

Affected Systems:
< 6.0.6.1< 6.1.7.1< 7.0.4.1
Discovered: February 10, 2023
Last Modified: August 21, 2025View Details →

CVE-2023-22792

HIGH

SQL Injection in activerecord (VIBE-RUB-ACTIVERECORD-31163533)

CVSS 3.1: 8.8/10
Published: August 21, 2025

A high severity vulnerability has been identified in activerecord. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-22578

HIGH

SQL Injection in sequelize (VIBE-NPM-SEQUELIZE-77101482)

CVSS 3.1: 8.8/10
Published: August 21, 2025

A high severity vulnerability has been identified in sequelize. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-25399

HIGH

Buffer Overflow in numpy (VIBE-PIP-NUMPY-1313505)

CVSS 3.1: 8.8/10
Published: August 21, 2025

A high severity vulnerability has been identified in numpy. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-30608

HIGH

SQL Injection in sqlalchemy (VIBE-PIP-SQLALCHEMY-30430542)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in sqlalchemy (pip ecosystem). SQL Injection poses significant security risks requiring immediate attention and represents a critical attack ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-42789

HIGH

SQL Injection in hibernate (VIBE-MAV-HIBERNATE-88955431)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in hibernate (maven ecosystem). SQL Injection poses significant security risks requiring immediate attention and represents a critical attack...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-31419

HIGH

Privilege Escalation in elasticsearch (VIBE-MAV-ELASTICSEARCH-15277242)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in elasticsearch (maven ecosystem). Privilege Escalation poses significant security risks requiring immediate attention and represents a crit...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36899

HIGH

SQL Injection in Entity.Framework (VIBE-NUG-ENTITYFRAMEWORK-35883785)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in Entity.Framework (nuget ecosystem). SQL Injection poses significant security risks requiring immediate attention and represents a critical...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-41879

HIGH

SQL Injection in Dapper (VIBE-NUG-DAPPER-18386589)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in Dapper (nuget ecosystem). SQL Injection poses significant security risks requiring immediate attention and represents a critical attack ve...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-22792

HIGH

SQL Injection in activerecord (VIBE-RUB-ACTIVERECORD-95739229)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in activerecord (rubygems ecosystem). SQL Injection poses significant security risks requiring immediate attention and represents a critical ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-22578

HIGH

SQL Injection in sequelize (VIBE-NPM-SEQUELIZE-65480879)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in sequelize (npm ecosystem). SQL Injection poses significant security risks requiring immediate attention and represents a critical attack v...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-4863

HIGH

Heap Buffer Overflow in sharp (VIBE-NPM-SHARP-34769178)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in sharp (npm ecosystem). Heap Buffer Overflow poses significant security risks requiring immediate attention and represents a critical attac...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-25399

HIGH

Buffer Overflow in numpy (VIBE-PIP-NUMPY-64911910)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in numpy (pip ecosystem). Buffer Overflow poses significant security risks requiring immediate attention and represents a critical attack vec...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-42789

HIGH

SQL Injection in hibernate (VIBE-MAV-HIBERNATE-52735131)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in hibernate (maven ecosystem). SQL Injection poses significant security risks requiring immediate attention and represents a critical attack...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-4863

HIGH

Heap Buffer Overflow in sharp (VIBE-NPM-SHARP-89902769)

CVSS 3.1: 8.8/10
Published: August 21, 2025

A high severity vulnerability has been identified in sharp (npm ecosystem). Heap Buffer Overflow poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-25399

HIGH

Buffer Overflow in numpy (VIBE-PIP-NUMPY-2175714)

CVSS 3.1: 8.8/10
Published: August 21, 2025

A high severity vulnerability has been identified in numpy (pip ecosystem). Buffer Overflow poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-25801

HIGH

Heap Buffer Overflow in tensorflow (VIBE-PIP-TENSORFLOW-40390134)

CVSS 3.1: 8.8/10
Published: August 21, 2025

A high severity vulnerability has been identified in tensorflow (pip ecosystem). Heap Buffer Overflow poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-31419

HIGH

Privilege Escalation in elasticsearch (VIBE-MAV-ELASTICSEARCH-50009765)

CVSS 3.1: 8.8/10
Published: August 21, 2025

A high severity vulnerability has been identified in elasticsearch (maven ecosystem). Privilege Escalation poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-44487

HIGH

Elevation of Privilege in Microsoft.AspNetCore (VIBE-NUG-MICROSOFTASPNET-29412955)

CVSS 3.1: 8.8/10
Published: August 21, 2025

A high severity vulnerability has been identified in Microsoft. AspNetCore (nuget ecosystem). Elevation of Privilege poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36899

HIGH

SQL Injection in Entity.Framework (VIBE-NUG-ENTITYFRAMEWORK-97125838)

CVSS 3.1: 8.8/10
Published: August 21, 2025

A high severity vulnerability has been identified in Entity.Framework (nuget ecosystem). SQL Injection poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-25801

HIGH

Heap Buffer Overflow in tensorflow (VIBE-PIP-TENSORFLOW-74812537)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in tensorflow (pip ecosystem). Heap Buffer Overflow poses significant security risks requiring immediate attention and represents a critical ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-44271

HIGH

Buffer Overflow in pillow (VIBE-PIP-PILLOW-80263238)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in pillow (pip ecosystem). Buffer Overflow poses significant security risks requiring immediate attention and represents a critical attack ve...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-44487

HIGH

Elevation of Privilege in Microsoft.AspNetCore (VIBE-NUG-MICROSOFTASPNET-84640334)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in Microsoft.AspNetCore (nuget ecosystem). Elevation of Privilege poses significant security risks requiring immediate attention and represen...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-41879

HIGH

SQL Injection in Dapper (VIBE-NUG-DAPPER-96178558)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in Dapper (nuget ecosystem). SQL Injection poses significant security risks requiring immediate attention and represents a critical attack ve...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-3955

HIGH

Privilege Escalation in k8s.io/kubernetes (VIBE-GOL-K8SIOKUBERNETES-22707099)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in k8s.io/kubernetes (golang ecosystem). Privilege Escalation poses significant security risks requiring immediate attention and represents a...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-30608

HIGH

SQL Injection in sqlalchemy (VIBE-PIP-SQLALCHEMY-27886302)

CVSS 3.1: 8.8/10
Published: August 21, 2025

A high severity vulnerability has been identified in sqlalchemy (pip ecosystem). SQL Injection poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-41879

HIGH

SQL Injection in Dapper (VIBE-NUG-DAPPER-9546718)

CVSS 3.1: 8.8/10
Published: August 21, 2025

A high severity vulnerability has been identified in Dapper (nuget ecosystem). SQL Injection poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-4863

HIGH

Heap Buffer Overflow in sharp (VIBE-NPM-SHARP-95286909)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in sharp (npm ecosystem). Heap Buffer Overflow poses significant security risks requiring immediate attention and represents a critical attac...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-3955

HIGH

Privilege Escalation in k8s.io/kubernetes (VIBE-GOL-K8SIOKUBERNETES-32788663)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in k8s.io/kubernetes (golang ecosystem). Privilege Escalation poses significant security risks requiring immediate attention and represents a...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-25801

HIGH

Heap Buffer Overflow in tensorflow (VIBE-PIP-TENSORFLOW-90534296)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in tensorflow (pip ecosystem). Heap Buffer Overflow poses significant security risks requiring immediate attention and represents a critical ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-44271

HIGH

Buffer Overflow in pillow (VIBE-PIP-PILLOW-36879446)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in pillow (pip ecosystem). Buffer Overflow poses significant security risks requiring immediate attention and represents a critical attack ve...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-30608

HIGH

SQL Injection in sqlalchemy (VIBE-PIP-SQLALCHEMY-27452121)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in sqlalchemy (pip ecosystem). SQL Injection poses significant security risks requiring immediate attention and represents a critical attack ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-31419

HIGH

Privilege Escalation in elasticsearch (VIBE-MAV-ELASTICSEARCH-25467753)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in elasticsearch (maven ecosystem). Privilege Escalation poses significant security risks requiring immediate attention and represents a crit...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-44487

HIGH

Elevation of Privilege in Microsoft.AspNetCore (VIBE-NUG-MICROSOFTASPNET-24439843)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in Microsoft.AspNetCore (nuget ecosystem). Elevation of Privilege poses significant security risks requiring immediate attention and represen...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36899

HIGH

SQL Injection in Entity.Framework (VIBE-NUG-ENTITYFRAMEWORK-97509401)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in Entity.Framework (nuget ecosystem). SQL Injection poses significant security risks requiring immediate attention and represents a critical...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-22792

HIGH

SQL Injection in activerecord (VIBE-RUB-ACTIVERECORD-14887594)

CVSS 3.1: 8.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in activerecord (rubygems ecosystem). SQL Injection poses significant security risks requiring immediate attention and represents a critical ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-47641

HIGH

Template Injection in jinja2 (VIBE-PIP-JINJA2-37219662)

CVSS 3.1: 8.6/10
Published: August 21, 2025

Template Injection in jinja2 (VIBE-PIP-JINJA2-37219662) vulnerability affecting jinja2 package, versions < latest. This critical security issue was introduced on 2025-08-21T06:02:52.229Z and requi...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-47641

HIGH

Template Injection in jinja2 (VIBE-PIP-JINJA2-50176907)

CVSS 3.1: 8.6/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in jinja2 (pip ecosystem). Template Injection poses significant security risks requiring immediate attention and represents a critical attack...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-47641

HIGH

Template Injection in jinja2 (VIBE-PIP-JINJA2-97965687)

CVSS 3.1: 8.6/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in jinja2 (pip ecosystem). Template Injection poses significant security risks requiring immediate attention and represents a critical attack...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-3696

HIGH

Prototype Pollution in mongoose (VIBE-NPM-MONGOOSE-88512935)

CVSS 3.1: 8.1/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in mongoose (npm ecosystem). Prototype Pollution poses significant security risks requiring immediate attention and represents a critical att...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26159

HIGH

CSRF Vulnerability in axios (VIBE-NPM-AXIOS-62155721)

CVSS 3.1: 8.1/10
Published: August 21, 2025

A high severity vulnerability has been identified in axios (npm ecosystem). CSRF Vulnerability poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-46298

HIGH

Path Traversal in next (VIBE-NPM-NEXT-3740003)

CVSS 3.1: 8.1/10
Published: August 21, 2025

This high severity vulnerability in next creates a significant security exposure that requires immediate organizational attention and coordinated response. The vulnerability represents a critical s...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-46298

HIGH

Path Traversal in next (VIBE-NPM-NEXT-72467975)

CVSS 3.1: 8.1/10
Published: August 21, 2025

This high severity vulnerability in next creates a significant security exposure that requires immediate organizational attention and coordinated response. The vulnerability represents a critical s...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26159

HIGH

CSRF Vulnerability in axios (VIBE-NPM-AXIOS-89433819)

CVSS 3.1: 8.1/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in axios (npm ecosystem). CSRF Vulnerability poses significant security risks requiring immediate attention and represents a critical attack ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26159

HIGH

CSRF Vulnerability in axios (VIBE-NPM-AXIOS-47011612)

CVSS 3.1: 8.1/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in axios (npm ecosystem). CSRF Vulnerability poses significant security risks requiring immediate attention and represents a critical attack ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-46298

HIGH

Path Traversal in next (VIBE-NPM-NEXT-89897208)

CVSS 3.1: 8.1/10
Published: August 21, 2025

Let's break down what this high severity vulnerability in next means for your security. Think of it as a hidden backdoor that needs immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-3696

HIGH

Prototype Pollution in mongoose (VIBE-NPM-MONGOOSE-43476014)

CVSS 3.1: 8.1/10
Published: August 21, 2025

A high severity vulnerability has been identified in mongoose (npm ecosystem). Prototype Pollution poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-46298

HIGH

Path Traversal in next (VIBE-NPM-NEXT-37451593)

CVSS 3.1: 8.1/10
Published: August 21, 2025

This high severity vulnerability in next creates a significant security exposure that requires immediate organizational attention and coordinated response. The vulnerability represents a critical s...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-3696

HIGH

Prototype Pollution in mongoose (VIBE-NPM-MONGOOSE-40292249)

CVSS 3.1: 8.1/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in mongoose (npm ecosystem). Prototype Pollution poses significant security risks requiring immediate attention and represents a critical att...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-43775

HIGH

Command Injection in node-sass (VIBE-NPM-NODESASS-66303171)

CVSS 3.1: 7.8/10
Published: October 26, 2022

Command Injection in node-sass (VIBE-NPM-NODESASS-66303171) vulnerability affecting node-sass package, versions < latest. Classification: CWE: CWE-89. This critical security issue was introduced on...

Affected Systems:
< latest
Discovered: October 26, 2022
Last Modified: August 21, 2025View Details →

CVE-2022-43775

HIGH

Command Injection in node-sass (VIBE-NPM-NODESASS-91750334)

CVSS 3.1: 7.8/10
Published: August 21, 2025

A high severity vulnerability has been identified in node-sass. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-47108

HIGH

Build Cache Poisoning in github.com/docker/docker (VIBE-GOL-GITHUBCOMDOCKER-60029754)

CVSS 3.1: 7.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in github.com/docker/docker (golang ecosystem). Build Cache Poisoning poses significant security risks requiring immediate attention and repr...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-43775

HIGH

Command Injection in node-sass (VIBE-NPM-NODESASS-76761594)

CVSS 3.1: 7.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in node-sass (npm ecosystem). Command Injection poses significant security risks requiring immediate attention and represents a critical atta...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-43666

HIGH

Code Injection in scikit-learn (VIBE-PIP-SCIKITLEARN-19501120)

CVSS 3.1: 7.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in scikit-learn (pip ecosystem). Code Injection poses significant security risks requiring immediate attention and represents a critical atta...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-37908

HIGH

Command Injection in celery (VIBE-PIP-CELERY-5731869)

CVSS 3.1: 7.8/10
Published: August 21, 2025

A high severity vulnerability has been identified in celery (pip ecosystem). Command Injection poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-47108

HIGH

Build Cache Poisoning in github.com/docker/docker (VIBE-GOL-GITHUBCOMDOCKER-79309411)

CVSS 3.1: 7.8/10
Published: August 21, 2025

A high severity vulnerability has been identified in github. com/docker/docker (golang ecosystem). Build Cache Poisoning poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-43666

HIGH

Code Injection in scikit-learn (VIBE-PIP-SCIKITLEARN-47524512)

CVSS 3.1: 7.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in scikit-learn (pip ecosystem). Code Injection poses significant security risks requiring immediate attention and represents a critical atta...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-37908

HIGH

Command Injection in celery (VIBE-PIP-CELERY-66220729)

CVSS 3.1: 7.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in celery (pip ecosystem). Command Injection poses significant security risks requiring immediate attention and represents a critical attack ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-43666

HIGH

Code Injection in scikit-learn (VIBE-PIP-SCIKITLEARN-31693568)

CVSS 3.1: 7.8/10
Published: August 21, 2025

A high severity vulnerability has been identified in scikit-learn (pip ecosystem). Code Injection poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-37908

HIGH

Command Injection in celery (VIBE-PIP-CELERY-89629260)

CVSS 3.1: 7.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in celery (pip ecosystem). Command Injection poses significant security risks requiring immediate attention and represents a critical attack ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-47108

HIGH

Build Cache Poisoning in github.com/docker/docker (VIBE-GOL-GITHUBCOMDOCKER-58198500)

CVSS 3.1: 7.8/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in github.com/docker/docker (golang ecosystem). Build Cache Poisoning poses significant security risks requiring immediate attention and repr...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-3517

HIGH

Regular Expression Denial of Service in minimatch (VIBE-NPM-MINIMATCH-62318618)

CVSS 3.1: 7.5/10
Published: October 17, 2022

Regular Expression Denial of Service in minimatch (VIBE-NPM-MINIMATCH-62318618) vulnerability affecting minimatch package, versions < latest. Classification: CWE: CWE-400. This critical security is...

Affected Systems:
< latest
Discovered: October 17, 2022
Last Modified: August 21, 2025View Details →

CVE-2023-31125

HIGH

Denial of Service in socket.io (VIBE-NPM-SOCKETIO-55472611)

CVSS 3.1: 7.5/10
Published: May 8, 2023

Denial of Service in socket.io (VIBE-NPM-SOCKETIO-55472611) vulnerability affecting socket.io package, versions < latest. Classification: CWE: CWE-248. This critical security issue was introduced o...

Affected Systems:
< latest
Discovered: May 8, 2023
Last Modified: August 21, 2025View Details →

CVE-2023-26144

HIGH

Information Disclosure in graphql (VIBE-NPM-GRAPHQL-54195785)

CVSS 3.1: 7.5/10
Published: September 20, 2023

Information Disclosure in graphql (VIBE-NPM-GRAPHQL-54195785) vulnerability affecting graphql package, versions < latest. Classification: CWE: CWE-400. This critical security issue was introduced o...

Affected Systems:
< latest
Discovered: September 20, 2023
Last Modified: August 21, 2025View Details →

CVE-2023-36665

HIGH

Timing Attack in bcrypt (VIBE-NPM-BCRYPT-2691141)

CVSS 3.1: 7.5/10
Published: July 5, 2023

Timing Attack in bcrypt (VIBE-NPM-BCRYPT-2691141) vulnerability affecting bcrypt package, versions < latest. Classification: CWE: CWE-1321. This critical security issue was introduced on 2023-07-05...

Affected Systems:
< latest
Discovered: July 5, 2023
Last Modified: August 21, 2025View Details →

CVE-2023-30861

HIGH

Session Fixation in flask (VIBE-PIP-FLASK-56363969)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Session Fixation in flask (VIBE-PIP-FLASK-56363969) vulnerability affecting flask package, versions < latest. This critical security issue was introduced on 2025-08-21T06:02:37.056Z and requires i...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-32681

HIGH

Information Disclosure in requests (VIBE-PIP-REQUESTS-70302083)

CVSS 3.1: 7.5/10
Published: May 26, 2023

Information Disclosure in requests (VIBE-PIP-REQUESTS-70302083) vulnerability affecting requests package, versions < latest. Classification: CWE: CWE-200. This critical security issue was introduce...

Affected Systems:
< latest
Discovered: May 26, 2023
Last Modified: August 21, 2025View Details →

CVE-2023-46589

HIGH

Request Smuggling in tomcat (VIBE-MAV-TOMCAT-2451544)

CVSS 3.1: 7.5/10
Published: November 28, 2023

Request Smuggling in tomcat (VIBE-MAV-TOMCAT-2451544) vulnerability affecting tomcat package, versions < latest. Classification: CWE: CWE-444. This critical security issue was introduced on 2023-11...

Affected Systems:
< latest
Discovered: November 28, 2023
Last Modified: August 21, 2025View Details →

CVE-2023-36792

HIGH

Denial of Service in System.Text.Json (VIBE-NUG-SYSTEMTEXTJSON-33564872)

CVSS 3.1: 7.5/10
Published: September 12, 2023

Denial of Service in System.Text.Json (VIBE-NUG-SYSTEMTEXTJSON-33564872) vulnerability affecting System.Text.Json package, versions < latest. Classification: CWE: CWE-190. This critical security is...

Affected Systems:
< latest
Discovered: September 12, 2023
Last Modified: August 21, 2025View Details →

CVE-2023-34034

HIGH

SSRF Vulnerability in RestSharp (VIBE-NUG-RESTSHARP-95387112)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in RestSharp. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-44487

HIGH

HTTP/2 Rapid Reset in golang.org/x/net (VIBE-GOL-GOLANGORGXNET-82800057)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in golang.org/x/net. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-29401

HIGH

Path Traversal in github.com/gin-gonic/gin (VIBE-GOL-GITHUBCOMGINGON-71161610)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in github.com/gin-gonic/gin. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational r...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-45286

HIGH

Key Confusion in github.com/dgrijalva/jwt-go (VIBE-GOL-GITHUBCOMDGRIJA-46222399)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in github.com/dgrijalva/jwt-go. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizationa...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-39325

HIGH

Access Control Bypass in github.com/hashicorp/consul (VIBE-GOL-GITHUBCOMHASHIC-61397945)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in github.com/hashicorp/consul. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizationa...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-29017

HIGH

XML External Entity in nokogiri (VIBE-RUB-NOKOGIRI-82720256)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in nokogiri. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-40175

HIGH

HTTP Request Smuggling in puma (VIBE-RUB-PUMA-56893603)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in puma. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36464

HIGH

Directory Traversal in sinatra (VIBE-RUB-SINATRA-78996575)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in sinatra. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-24999

HIGH

Open Redirect in express (VIBE-NPM-EXPRESS-7714555)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in express. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-30861

HIGH

Session Fixation in flask (VIBE-PIP-FLASK-12518892)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in flask. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-32681

HIGH

Information Disclosure in requests (VIBE-PIP-REQUESTS-94464379)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in requests. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-45286

HIGH

Key Confusion in github.com/dgrijalva/jwt-go (VIBE-GOL-GITHUBCOMDGRIJA-12531480)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in github.com/dgrijalva/jwt-go (golang ecosystem). Key Confusion poses significant security risks requiring immediate attention and represent...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-39325

HIGH

Access Control Bypass in github.com/hashicorp/consul (VIBE-GOL-GITHUBCOMHASHIC-81144842)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in github.com/hashicorp/consul (golang ecosystem). Access Control Bypass poses significant security risks requiring immediate attention and r...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-27539

HIGH

Denial of Service in rack (VIBE-RUB-RACK-72413768)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in rack (rubygems ecosystem). Denial of Service poses significant security risks requiring immediate attention and represents a critical atta...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-49090

HIGH

Path Traversal in carrierwave (VIBE-RUB-CARRIERWAVE-1977404)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in carrierwave (rubygems ecosystem). Path Traversal poses significant security risks requiring immediate attention and represents a critical ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36464

HIGH

Directory Traversal in sinatra (VIBE-RUB-SINATRA-86607267)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in sinatra (rubygems ecosystem). Directory Traversal poses significant security risks requiring immediate attention and represents a critical...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-24999

HIGH

Open Redirect in express (VIBE-NPM-EXPRESS-99058940)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in express (npm ecosystem). Open Redirect poses significant security risks requiring immediate attention and represents a critical attack vec...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-28154

HIGH

Cross-site Scripting in webpack (VIBE-NPM-WEBPACK-8537978)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in webpack (npm ecosystem). Cross-site Scripting poses significant security risks requiring immediate attention and represents a critical att...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-30861

HIGH

Session Fixation in flask (VIBE-PIP-FLASK-24661032)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in flask (pip ecosystem). Session Fixation poses significant security risks requiring immediate attention and represents a critical attack ve...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-46589

HIGH

Request Smuggling in tomcat (VIBE-MAV-TOMCAT-78386211)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in tomcat (maven ecosystem). Request Smuggling poses significant security risks requiring immediate attention and represents a critical attac...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-29336

HIGH

Insecure Deserialization in Newtonsoft.Json (VIBE-NUG-NEWTONSOFTJSON-19096509)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in Newtonsoft.Json (nuget ecosystem). Insecure Deserialization poses significant security risks requiring immediate attention and represents ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-35390

HIGH

Token Bypass in IdentityModel (VIBE-NUG-IDENTITYMODEL-52760688)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in IdentityModel (nuget ecosystem). Token Bypass poses significant security risks requiring immediate attention and represents a critical att...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2024-TEST

HIGH

Test VIBE Vulnerability - Prototype Pollution

CVSS 3.1: 7.5/10
Published: August 21, 2025

This is a test VIBE vulnerability created by the migration system.

Affected Systems:
< 1.0.0
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-28154

HIGH

Cross-site Scripting in webpack (VIBE-NPM-WEBPACK-95074332)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in webpack (npm ecosystem). Cross-site Scripting poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36478

HIGH

Information Disclosure in jetty (VIBE-MAV-JETTY-83770598)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in jetty (maven ecosystem). Information Disclosure poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-35390

HIGH

Token Bypass in IdentityModel (VIBE-NUG-IDENTITYMODEL-83572163)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in IdentityModel (nuget ecosystem). Token Bypass poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-27539

HIGH

Denial of Service in rack (VIBE-RUB-RACK-12752252)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in rack (rubygems ecosystem). Denial of Service poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-3517

HIGH

Regular Expression Denial of Service in minimatch (VIBE-NPM-MINIMATCH-73962714)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Enterprise organizations utilizing minimatch face critical operational risk from this high severity vulnerability that threatens business continuity, regulatory compliance, and organizational reput...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-28154

HIGH

Cross-site Scripting in webpack (VIBE-NPM-WEBPACK-68370203)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in webpack (npm ecosystem). Cross-site Scripting poses significant security risks requiring immediate attention and represents a critical att...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-46589

HIGH

Request Smuggling in tomcat (VIBE-MAV-TOMCAT-70392023)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in tomcat (maven ecosystem). Request Smuggling poses significant security risks requiring immediate attention and represents a critical attac...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36478

HIGH

Information Disclosure in jetty (VIBE-MAV-JETTY-70573964)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in jetty (maven ecosystem). Information Disclosure poses significant security risks requiring immediate attention and represents a critical a...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-35390

HIGH

Token Bypass in IdentityModel (VIBE-NUG-IDENTITYMODEL-87538250)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in IdentityModel (nuget ecosystem). Token Bypass poses significant security risks requiring immediate attention and represents a critical att...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-34034

HIGH

SSRF Vulnerability in RestSharp (VIBE-NUG-RESTSHARP-10884042)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in RestSharp (nuget ecosystem). SSRF Vulnerability poses significant security risks requiring immediate attention and represents a critical a...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-44487

HIGH

HTTP/2 Rapid Reset in golang.org/x/net (VIBE-GOL-GOLANGORGXNET-213649)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in golang.org/x/net (golang ecosystem). HTTP/2 Rapid Reset poses significant security risks requiring immediate attention and represents a cr...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26146

HIGH

Session Fixation in devise (VIBE-RUB-DEVISE-26546252)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in devise (rubygems ecosystem). Session Fixation poses significant security risks requiring immediate attention and represents a critical att...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-31125

HIGH

Denial of Service in socket.io (VIBE-NPM-SOCKETIO-84667774)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in socket.io (npm ecosystem). Denial of Service poses significant security risks requiring immediate attention and represents a critical atta...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36665

HIGH

Timing Attack in bcrypt (VIBE-NPM-BCRYPT-18833836)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in bcrypt (npm ecosystem). Timing Attack poses significant security risks requiring immediate attention and represents a critical attack vect...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-34034

HIGH

SSRF Vulnerability in RestSharp (VIBE-NUG-RESTSHARP-67757343)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in RestSharp (nuget ecosystem). SSRF Vulnerability poses significant security risks requiring immediate attention and represents a critical a...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-29401

HIGH

Path Traversal in github.com/gin-gonic/gin (VIBE-GOL-GITHUBCOMGINGON-94523114)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in github.com/gin-gonic/gin (golang ecosystem). Path Traversal poses significant security risks requiring immediate attention and represents ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-45286

HIGH

Key Confusion in github.com/dgrijalva/jwt-go (VIBE-GOL-GITHUBCOMDGRIJA-10104021)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in github.com/dgrijalva/jwt-go (golang ecosystem). Key Confusion poses significant security risks requiring immediate attention and represent...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-39325

HIGH

Access Control Bypass in github.com/hashicorp/consul (VIBE-GOL-GITHUBCOMHASHIC-68753926)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in github.com/hashicorp/consul (golang ecosystem). Access Control Bypass poses significant security risks requiring immediate attention and r...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-27539

HIGH

Denial of Service in rack (VIBE-RUB-RACK-36019586)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in rack (rubygems ecosystem). Denial of Service poses significant security risks requiring immediate attention and represents a critical atta...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-29017

HIGH

XML External Entity in nokogiri (VIBE-RUB-NOKOGIRI-62589099)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in nokogiri (rubygems ecosystem). XML External Entity poses significant security risks requiring immediate attention and represents a critica...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-40175

HIGH

HTTP Request Smuggling in puma (VIBE-RUB-PUMA-53063279)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in puma (rubygems ecosystem). HTTP Request Smuggling poses significant security risks requiring immediate attention and represents a critical...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26146

HIGH

Session Fixation in devise (VIBE-RUB-DEVISE-60232701)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in devise (rubygems ecosystem). Session Fixation poses significant security risks requiring immediate attention and represents a critical att...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-24999

HIGH

Open Redirect in express (VIBE-NPM-EXPRESS-46286212)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in express (npm ecosystem). Open Redirect poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-34455

HIGH

Denial of Service in kafka (VIBE-MAV-KAFKA-28701986)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in kafka (maven ecosystem). Denial of Service poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-29336

HIGH

Insecure Deserialization in Newtonsoft.Json (VIBE-NUG-NEWTONSOFTJSON-55875483)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in Newtonsoft. Json (nuget ecosystem). Insecure Deserialization poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26146

HIGH

Session Fixation in devise (VIBE-RUB-DEVISE-15294276)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in devise (rubygems ecosystem). Session Fixation poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-49090

HIGH

Path Traversal in carrierwave (VIBE-RUB-CARRIERWAVE-77854880)

CVSS 3.1: 7.5/10
Published: August 21, 2025

A high severity vulnerability has been identified in carrierwave (rubygems ecosystem). Path Traversal poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-3517

HIGH

Regular Expression Denial of Service in minimatch (VIBE-NPM-MINIMATCH-5535371)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Enterprise organizations utilizing minimatch face critical operational risk from this high severity vulnerability that threatens business continuity, regulatory compliance, and organizational reput...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-3517

HIGH

Regular Expression Denial of Service in minimatch (VIBE-NPM-MINIMATCH-32829668)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Enterprise organizations utilizing minimatch face critical operational risk from this high severity vulnerability that threatens business continuity, regulatory compliance, and organizational reput...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-31125

HIGH

Denial of Service in socket.io (VIBE-NPM-SOCKETIO-6222084)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in socket.io (npm ecosystem). Denial of Service poses significant security risks requiring immediate attention and represents a critical atta...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26144

HIGH

Information Disclosure in graphql (VIBE-NPM-GRAPHQL-74242760)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in graphql (npm ecosystem). Information Disclosure poses significant security risks requiring immediate attention and represents a critical a...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36665

HIGH

Timing Attack in bcrypt (VIBE-NPM-BCRYPT-80445621)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in bcrypt (npm ecosystem). Timing Attack poses significant security risks requiring immediate attention and represents a critical attack vect...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-34455

HIGH

Denial of Service in kafka (VIBE-MAV-KAFKA-90786701)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in kafka (maven ecosystem). Denial of Service poses significant security risks requiring immediate attention and represents a critical attack...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-29336

HIGH

Insecure Deserialization in Newtonsoft.Json (VIBE-NUG-NEWTONSOFTJSON-56471411)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in Newtonsoft.Json (nuget ecosystem). Insecure Deserialization poses significant security risks requiring immediate attention and represents ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36792

HIGH

Denial of Service in System.Text.Json (VIBE-NUG-SYSTEMTEXTJSON-58684682)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in System.Text.Json (nuget ecosystem). Denial of Service poses significant security risks requiring immediate attention and represents a crit...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-29401

HIGH

Path Traversal in github.com/gin-gonic/gin (VIBE-GOL-GITHUBCOMGINGON-87213835)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in github.com/gin-gonic/gin (golang ecosystem). Path Traversal poses significant security risks requiring immediate attention and represents ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-29017

HIGH

XML External Entity in nokogiri (VIBE-RUB-NOKOGIRI-73192973)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in nokogiri (rubygems ecosystem). XML External Entity poses significant security risks requiring immediate attention and represents a critica...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-40175

HIGH

HTTP Request Smuggling in puma (VIBE-RUB-PUMA-64622600)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in puma (rubygems ecosystem). HTTP Request Smuggling poses significant security risks requiring immediate attention and represents a critical...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26144

HIGH

Information Disclosure in graphql (VIBE-NPM-GRAPHQL-3761944)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in graphql (npm ecosystem). Information Disclosure poses significant security risks requiring immediate attention and represents a critical a...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-32681

HIGH

Information Disclosure in requests (VIBE-PIP-REQUESTS-15980668)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in requests (pip ecosystem). Information Disclosure poses significant security risks requiring immediate attention and represents a critical ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36478

HIGH

Information Disclosure in jetty (VIBE-MAV-JETTY-98748955)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in jetty (maven ecosystem). Information Disclosure poses significant security risks requiring immediate attention and represents a critical a...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-34455

HIGH

Denial of Service in kafka (VIBE-MAV-KAFKA-15410287)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in kafka (maven ecosystem). Denial of Service poses significant security risks requiring immediate attention and represents a critical attack...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36792

HIGH

Denial of Service in System.Text.Json (VIBE-NUG-SYSTEMTEXTJSON-66429564)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in System.Text.Json (nuget ecosystem). Denial of Service poses significant security risks requiring immediate attention and represents a crit...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-44487

HIGH

HTTP/2 Rapid Reset in golang.org/x/net (VIBE-GOL-GOLANGORGXNET-82453126)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in golang.org/x/net (golang ecosystem). HTTP/2 Rapid Reset poses significant security risks requiring immediate attention and represents a cr...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-49090

HIGH

Path Traversal in carrierwave (VIBE-RUB-CARRIERWAVE-26909792)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in carrierwave (rubygems ecosystem). Path Traversal poses significant security risks requiring immediate attention and represents a critical ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36464

HIGH

Directory Traversal in sinatra (VIBE-RUB-SINATRA-62469235)

CVSS 3.1: 7.5/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in sinatra (rubygems ecosystem). Directory Traversal poses significant security risks requiring immediate attention and represents a critical...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2021-23337

HIGH

Prototype Pollution in lodash (VIBE-NPM-LODASH-70706319)

CVSS 3.1: 7.4/10
Published: February 15, 2021

Prototype Pollution in lodash (VIBE-NPM-LODASH-70706319) vulnerability affecting lodash package, versions < latest. Classification: CWE: CWE-94. This critical security issue was introduced on 2021-...

Affected Systems:
< latest
Discovered: February 15, 2021
Last Modified: August 21, 2025View Details →

CVE-2021-23337

HIGH

Prototype Pollution in lodash (VIBE-NPM-LODASH-81266232)

CVSS 3.1: 7.4/10
Published: August 21, 2025

A high severity vulnerability has been identified in lodash. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2021-23337

HIGH

Prototype Pollution in lodash (VIBE-NPM-LODASH-43324602)

CVSS 3.1: 7.4/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in lodash that demands immediate organizational response. This Prototype Pollution in lodash represents a critical security exposure requirin...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2021-23337

HIGH

Prototype Pollution in lodash (VIBE-NPM-LODASH-65829290)

CVSS 3.1: 7.4/10
Published: August 21, 2025

Security analysis reveals a high severity vulnerability in lodash that demands immediate organizational response. This Prototype Pollution in lodash represents a critical security exposure requirin...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-34091

MEDIUM

Prototype Pollution in vue (VIBE-NPM-VUE-97979194)

CVSS 3.1: 6.5/10
Published: June 1, 2023

Prototype Pollution in vue (VIBE-NPM-VUE-97979194) vulnerability affecting vue package, versions < latest. Classification: CWE: CWE-285. This critical security issue was introduced on 2023-06-01 an...

Affected Systems:
< latest
Discovered: June 1, 2023
Last Modified: August 21, 2025View Details →

CVE-2023-26116

MEDIUM

Regular Expression DoS in angular (VIBE-NPM-ANGULAR-41889226)

CVSS 3.1: 6.5/10
Published: August 21, 2025

Regular Expression DoS in angular (VIBE-NPM-ANGULAR-41889226) vulnerability affecting angular package, versions < latest. This critical security issue was introduced on 2025-08-21T06:02:30.975Z an...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-46298

MEDIUM

Server-Side Request Forgery in next (VIBE-NPM-NEXT-62927844)

CVSS 3.1: 6.5/10
Published: October 22, 2023

Server-Side Request Forgery in next (VIBE-NPM-NEXT-62927844) vulnerability affecting next package, versions < latest. Classification: CWE: NVD-CWE-noinfo. This critical security issue was introduce...

Affected Systems:
< latest
Discovered: October 22, 2023
Last Modified: August 21, 2025View Details →

CVE-2023-36041

MEDIUM

Information Disclosure in Azure.Storage (VIBE-NUG-AZURESTORAGE-1395245)

CVSS 3.1: 6.5/10
Published: November 14, 2023

Information Disclosure in Azure.Storage (VIBE-NUG-AZURESTORAGE-1395245) vulnerability affecting Azure.Storage package, versions < latest. Classification: CWE: CWE-416. This critical security issue ...

Affected Systems:
< latest
Discovered: November 14, 2023
Last Modified: August 21, 2025View Details →

CVE-2023-47109

MEDIUM

Information Disclosure in github.com/prometheus/prometheus (VIBE-GOL-GITHUBCOMPROMET-72255483)

CVSS 3.1: 6.5/10
Published: August 21, 2025

A medium severity vulnerability has been identified in github.com/prometheus/prometheus. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organi...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-46298

MEDIUM

Server-Side Request Forgery in next (VIBE-NPM-NEXT-18080847)

CVSS 3.1: 6.5/10
Published: August 21, 2025

A medium severity vulnerability has been identified in next. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-47109

MEDIUM

Information Disclosure in github.com/prometheus/prometheus (VIBE-GOL-GITHUBCOMPROMET-92842676)

CVSS 3.1: 6.5/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in github.com/prometheus/prometheus (golang ecosystem). Information Disclosure poses significant security risks requiring immediate attenti...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-34091

MEDIUM

Prototype Pollution in vue (VIBE-NPM-VUE-98563549)

CVSS 3.1: 6.5/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in vue (npm ecosystem). Prototype Pollution poses significant security risks requiring immediate attention and represents a critical attack...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26116

MEDIUM

Regular Expression DoS in angular (VIBE-NPM-ANGULAR-74760016)

CVSS 3.1: 6.5/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in angular (npm ecosystem). Regular Expression DoS poses significant security risks requiring immediate attention and represents a critical...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36799

MEDIUM

Type Confusion in AutoMapper (VIBE-NUG-AUTOMAPPER-61184551)

CVSS 3.1: 6.5/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in AutoMapper (nuget ecosystem). Type Confusion poses significant security risks requiring immediate attention and represents a critical at...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-28846

MEDIUM

Dependency Confusion in bundler (VIBE-RUB-BUNDLER-1542651)

CVSS 3.1: 6.5/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in bundler (rubygems ecosystem). Dependency Confusion poses significant security risks requiring immediate attention and represents a criti...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26116

MEDIUM

Regular Expression DoS in angular (VIBE-NPM-ANGULAR-931936)

CVSS 3.1: 6.5/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in angular (npm ecosystem). Regular Expression DoS poses significant security risks requiring immediate attention and represents a critical...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-46298

MEDIUM

Server-Side Request Forgery in next (VIBE-NPM-NEXT-59757153)

CVSS 3.1: 6.5/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in next (npm ecosystem). Server-Side Request Forgery poses significant security risks requiring immediate attention and represents a critic...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36041

MEDIUM

Information Disclosure in Azure.Storage (VIBE-NUG-AZURESTORAGE-17756878)

CVSS 3.1: 6.5/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in Azure.Storage (nuget ecosystem). Information Disclosure poses significant security risks requiring immediate attention and represents a ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-47109

MEDIUM

Information Disclosure in github.com/prometheus/prometheus (VIBE-GOL-GITHUBCOMPROMET-48564312)

CVSS 3.1: 6.5/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in github.com/prometheus/prometheus (golang ecosystem). Information Disclosure poses significant security risks requiring immediate attenti...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-28846

MEDIUM

Dependency Confusion in bundler (VIBE-RUB-BUNDLER-97701675)

CVSS 3.1: 6.5/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in bundler (rubygems ecosystem). Dependency Confusion poses significant security risks requiring immediate attention and represents a criti...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36799

MEDIUM

Type Confusion in AutoMapper (VIBE-NUG-AUTOMAPPER-6874954)

CVSS 3.1: 6.5/10
Published: August 21, 2025

A medium severity vulnerability has been identified in AutoMapper (nuget ecosystem). Type Confusion poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-28846

MEDIUM

Dependency Confusion in bundler (VIBE-RUB-BUNDLER-53971266)

CVSS 3.1: 6.5/10
Published: August 21, 2025

A medium severity vulnerability has been identified in bundler (rubygems ecosystem). Dependency Confusion poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36041

MEDIUM

Information Disclosure in Azure.Storage (VIBE-NUG-AZURESTORAGE-4112309)

CVSS 3.1: 6.5/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in Azure.Storage (nuget ecosystem). Information Disclosure poses significant security risks requiring immediate attention and represents a ...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-34091

MEDIUM

Prototype Pollution in vue (VIBE-NPM-VUE-79600807)

CVSS 3.1: 6.5/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in vue (npm ecosystem). Prototype Pollution poses significant security risks requiring immediate attention and represents a critical attack...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-36799

MEDIUM

Type Confusion in AutoMapper (VIBE-NUG-AUTOMAPPER-69933835)

CVSS 3.1: 6.5/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in AutoMapper (nuget ecosystem). Type Confusion poses significant security risks requiring immediate attention and represents a critical at...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-23529

MEDIUM

Insufficient Verification of Data in jsonwebtoken (VIBE-NPM-JSONWEBTOKEN-9172117)

CVSS 3.1: 6.4/10
Published: December 21, 2022

Insufficient Verification of Data in jsonwebtoken (VIBE-NPM-JSONWEBTOKEN-9172117) vulnerability affecting jsonwebtoken package, versions < latest. This critical security issue was introduced on 20...

Affected Systems:
< latest
Discovered: December 21, 2022
Last Modified: August 21, 2025View Details →

CVE-2022-23529

MEDIUM

Insufficient Verification of Data in jsonwebtoken (VIBE-NPM-JSONWEBTOKEN-51107393)

CVSS 3.1: 6.4/10
Published: August 21, 2025

A medium severity vulnerability has been identified in jsonwebtoken. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-23529

MEDIUM

Insufficient Verification of Data in jsonwebtoken (VIBE-NPM-JSONWEBTOKEN-51702726)

CVSS 3.1: 6.4/10
Published: August 21, 2025

This jsonwebtoken vulnerability represents a fundamental shift in software supply chain threat dynamics that demands strategic organizational response. Industry stakeholders must reconsider their s...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2022-23529

MEDIUM

Insufficient Verification of Data in jsonwebtoken (VIBE-NPM-JSONWEBTOKEN-815359)

CVSS 3.1: 6.4/10
Published: August 21, 2025

This jsonwebtoken vulnerability represents a fundamental shift in software supply chain threat dynamics that demands strategic organizational response. Industry stakeholders must reconsider their s...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-30589

MEDIUM

Cross-site Scripting in react (VIBE-NPM-REACT-94942007)

CVSS 3.1: 6.1/10
Published: August 21, 2025

A medium severity vulnerability has been identified in react. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26141

MEDIUM

Cross-site Scripting in sidekiq (VIBE-RUB-SIDEKIQ-95048033)

CVSS 3.1: 6.1/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in sidekiq (rubygems ecosystem). Cross-site Scripting poses significant security risks requiring immediate attention and represents a criti...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-30589

MEDIUM

Cross-site Scripting in react (VIBE-NPM-REACT-29975875)

CVSS 3.1: 6.1/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in react (npm ecosystem). Cross-site Scripting poses significant security risks requiring immediate attention and represents a critical att...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-30589

MEDIUM

Cross-site Scripting in react (VIBE-NPM-REACT-41716096)

CVSS 3.1: 6.1/10
Published: August 21, 2025

A medium severity vulnerability has been identified in react (npm ecosystem). Cross-site Scripting poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-32409

MEDIUM

Cross-site Scripting in beautifulsoup4 (VIBE-PIP-BEAUTIFULSOUP4-50008342)

CVSS 3.1: 6.1/10
Published: August 21, 2025

A medium severity vulnerability has been identified in beautifulsoup4 (pip ecosystem). Cross-site Scripting poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26141

MEDIUM

Cross-site Scripting in sidekiq (VIBE-RUB-SIDEKIQ-36350025)

CVSS 3.1: 6.1/10
Published: August 21, 2025

A medium severity vulnerability has been identified in sidekiq (rubygems ecosystem). Cross-site Scripting poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-26141

MEDIUM

Cross-site Scripting in sidekiq (VIBE-RUB-SIDEKIQ-15319955)

CVSS 3.1: 6.1/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in sidekiq (rubygems ecosystem). Cross-site Scripting poses significant security risks requiring immediate attention and represents a criti...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-32409

MEDIUM

Cross-site Scripting in beautifulsoup4 (VIBE-PIP-BEAUTIFULSOUP4-65089932)

CVSS 3.1: 6.1/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in beautifulsoup4 (pip ecosystem). Cross-site Scripting poses significant security risks requiring immediate attention and represents a cri...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-32409

MEDIUM

Cross-site Scripting in beautifulsoup4 (VIBE-PIP-BEAUTIFULSOUP4-82874923)

CVSS 3.1: 6.1/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in beautifulsoup4 (pip ecosystem). Cross-site Scripting poses significant security risks requiring immediate attention and represents a cri...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-38709

MEDIUM

Log Injection in Serilog (VIBE-NUG-SERILOG-76961959)

CVSS 3.1: 5.3/10
Published: August 21, 2025

A medium severity vulnerability has been identified in Serilog. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-22491

MEDIUM

Path Traversal in gatsby (VIBE-NPM-GATSBY-37160883)

CVSS 3.1: 5.3/10
Published: August 21, 2025

A medium severity vulnerability has been identified in gatsby. Security Vulnerability poses significant security risks requiring immediate attention and coordinated organizational response.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-38709

MEDIUM

Log Injection in Serilog (VIBE-NUG-SERILOG-35661073)

CVSS 3.1: 5.3/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in Serilog (nuget ecosystem). Log Injection poses significant security risks requiring immediate attention and represents a critical attack...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-22491

MEDIUM

Path Traversal in gatsby (VIBE-NPM-GATSBY-95319798)

CVSS 3.1: 5.3/10
Published: August 21, 2025

A medium severity vulnerability has been identified in gatsby (npm ecosystem). Path Traversal poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-38325

MEDIUM

Timing Attack in cryptography (VIBE-PIP-CRYPTOGRAPHY-48445916)

CVSS 3.1: 5.3/10
Published: August 21, 2025

A medium severity vulnerability has been identified in cryptography (pip ecosystem). Timing Attack poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-22491

MEDIUM

Path Traversal in gatsby (VIBE-NPM-GATSBY-81111768)

CVSS 3.1: 5.3/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in gatsby (npm ecosystem). Path Traversal poses significant security risks requiring immediate attention and represents a critical attack v...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-43642

MEDIUM

Denial of Service in github.com/gorilla/websocket (VIBE-GOL-GITHUBCOMGORILL-12045949)

CVSS 3.1: 5.3/10
Published: August 21, 2025

A medium severity vulnerability has been identified in github. com/gorilla/websocket (golang ecosystem). Denial of Service poses significant security risks requiring immediate attention.

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-38325

MEDIUM

Timing Attack in cryptography (VIBE-PIP-CRYPTOGRAPHY-62823403)

CVSS 3.1: 5.3/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in cryptography (pip ecosystem). Timing Attack poses significant security risks requiring immediate attention and represents a critical att...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-43642

MEDIUM

Denial of Service in github.com/gorilla/websocket (VIBE-GOL-GITHUBCOMGORILL-22132753)

CVSS 3.1: 5.3/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in github.com/gorilla/websocket (golang ecosystem). Denial of Service poses significant security risks requiring immediate attention and re...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-38325

MEDIUM

Timing Attack in cryptography (VIBE-PIP-CRYPTOGRAPHY-11665826)

CVSS 3.1: 5.3/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in cryptography (pip ecosystem). Timing Attack poses significant security risks requiring immediate attention and represents a critical att...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-38709

MEDIUM

Log Injection in Serilog (VIBE-NUG-SERILOG-46912215)

CVSS 3.1: 5.3/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in Serilog (nuget ecosystem). Log Injection poses significant security risks requiring immediate attention and represents a critical attack...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

CVE-2023-43642

MEDIUM

Denial of Service in github.com/gorilla/websocket (VIBE-GOL-GITHUBCOMGORILL-32942825)

CVSS 3.1: 5.3/10
Published: August 21, 2025

Security analysis reveals a medium severity vulnerability in github.com/gorilla/websocket (golang ecosystem). Denial of Service poses significant security risks requiring immediate attention and re...

Affected Systems:
< latest
Discovered: August 21, 2025
Last Modified: August 21, 2025View Details →

🔗 API Access

Integrate vulnerability data into your security tools and workflows

GETAPI Endpoint
https://api.vibeguard.co/v1/vulnerabilities

🎯 Query Parameters

  • severity - Filter by severity (critical, high, medium, low)
  • search - Search by CVE ID or title
  • limit - Number of results per page
  • offset - Pagination offset

📊 Rate Limits

  • Free: 100 requests/hour
  • Pro: 1,000 requests/hour
  • Enterprise: 10,000 requests/hour