
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Incorrect Authorization
@better-auth/oauth-provider is an An oauth provider plugin for Better Auth
Affected versions of this package are vulnerable to Incorrect Authorization via the createOAuthClientEndpoint endpoint. An attacker can gain unauthorized access to register OAuth clients by bypassing the intended clientPrivileges authorization checks, allowing the creation of clients with attacker-controlled redirect URIs and metadata. This may lead to increased risk of phishing, social engineering, and abuse of trust in OAuth/OIDC flows.
SQL Injection
openchatbi is an OpenChatBI - Natural language business intelligence powered by LLMs for intuitive data analysis and SQL generation
Affected versions of this package are vulnerable to SQL Injection via the Multi-stage Text2SQL Workflow component when processing the keywords argument. An attacker can execute unauthorized SQL commands by manipulating input remotely.
Directory Traversal
com.github.junrar:junrar is a rar decompression library in plain java.
Affected versions of this package are vulnerable to Directory Traversal via the createDirectory() and createFile() methods in LocalFolderExtractor module. An attacker can write arbitrary files to sibling directories by crafting a RAR archive with filenames containing directory traversal sequences.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in github.com/yuin/goldmark/renderer/html (golang)- M
Division by zero in jsrsasign (npm)- H
Incorrect Conversion between Numeric Types in jsrsasign (npm)- C
Missing Cryptographic Step in jsrsasign (npm)- C
Improper Verification of Cryptographic Signature in jsrsasign (npm)
Snyk security
researchers
have disclosed
3483
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




