VYPR

rpm package

opensuse/govulncheck-vulndb&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0

Vulnerabilities (1,722)

  • CVE-2026-31863LowMar 11, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API can be bypassed, allowing an attacker to gain access without the 4-digit code. This vulnerability is fixed in anytype-heart 0.48.4, anytype-cli 0.1.11, and Anytyp

  • CVE-2026-31892HigMar 11, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.11, A user who can submit Workflows can completely bypass all security settings defined in a WorkflowTemplate by including a podSpec

  • CVE-2026-29777MedMar 11, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.10, A tenant with write access to an HTTPRoute resource can inject backtick-delimited rule tokens into Traefik's router rule language via unsanitized header or query parameter match values. In shared gateway deploym

  • CVE-2026-28229CriMar 11, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a Authorization

  • CVE-2026-31817HigMar 10, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature is enabled, OliveTin persists execution log entries to disk. The filename used for these log files is constructed in part from the user-supplied UniqueTrackingId

  • CVE-2026-31809MedMar 10, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) checks href attributes for the javascript: prefix using strings.HasPrefix(). However, inserting ASCII tab ( ), newline ( ), or carriage return ( ) characters inside

  • CVE-2026-31807MedMar 10, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) blocks dangerous elements (, , ) and removes on* event handlers and javascript: in href attributes. However, it does NOT block SVG animation elem

  • CVE-2026-31801HigMar 10, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. From 1.3.0 to 2.1.14, zot’s dist-spec authorization middleware infers the required action for PUT /v2/{name}/manifests/{reference} as create by default, and only switches

  • CVE-2026-30934HigMar 10, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., title, description) that are rendered into HTML for /public/share/ without context-aware escaping. The server us

  • CVE-2026-30933HigMar 10, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. This vulnerability is fixed in 1.

  • CVE-2026-30869CriMar 10, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read arbitrary files from the server filesystem. By exploiting double‑encoded traversal sequences, an attacker can access sensitive file

  • CVE-2026-29773MedMar 10, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    Kubewarden is a policy engine for Kubernetes. Kubewarden cluster operators can grant permissions to users to deploy namespaced AdmissionPolicies and AdmissionPolicyGroups in their Namespaces. One of Kubewarden promises is that configured users can deploy namespaced policies in a

  • CVE-2026-28513HigMar 10, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, the OIDC token endpoint rejects an authorization code only when both the client ID is wrong and the code is expired. This allows cross-client code exchange and ex

  • CVE-2026-28512HigMar 10, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to before 2.4.0, a flaw in callback URL validation allowed crafted redirect_uri values containing URL userinfo (@) to bypass legitimate callback pattern checks. If an

  • CVE-2026-30926HigMar 10, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the publish service of SiYuan Note that allows low-privilege publish accounts (RoleReader) to modify notebook content via the /api/block/appendHeadingChildren API end

  • CVE-2026-30861CriMar 7, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an unauthenticated remote code execution (RCE) vulnerability exists in the MCP stdio configuration validation. The application allows

  • CVE-2026-30860CriMar 7, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vulnerability exists in the application's database query functionality. The validation system fails to recursively inspect c

  • CVE-2026-30859MedMar 7, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a broken access control vulnerability in the database query tool allows any authenticated tenant to read sensitive data belonging to other tenants, includ

  • CVE-2026-30858MedMar 7, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a DNS rebinding vulnerability in the web_fetch tool allows an unauthenticated attacker to bypass URL validation and access internal resources on the server

  • CVE-2026-30857MedMar 7, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a cross-tenant authorization bypass in the knowledge base copy endpoint allows any authenticated user to clone (duplicate) another tenant’s knowledge base

Page 54 of 87