Copilot
29 exploits
Active since Feb 2025
baomidou dynamic-datasource StandardEvaluationContext/SpelExpressionParser DsSpelExpressionProcessor.java DsSpelExpressionProcessor#doDetermineDatasource injection
CVSS 6.3
Aperi'Solve Affected by Unauthenticated RCE via JPSeek Analyzer Command
CVSS 9.8
ONNX: Path Traversal via Symlink
CVSS 7.5
ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load
CVSS 4.7
WeChat Pay callback signature verification bypassed when Host header is localhost
CVSS 8.6
plexus-utils <4.0.3 - Path Traversal
CVSS 8.8
stellar-xdr <25.0.1 - Memory Corruption
CVSS 4.0
Pimcore <=11.5.14.1/12.3.2 - SQL Injection
CVSS 4.9
InvoicePlane 1.7.0 - Stored XSS
CVSS 5.7
InvoicePlane 1.7.0 - Stored XSS
CVSS 5.7
InvoicePlane 1.7.0 - Stored XSS
CVSS 5.7
InvoicePlane 1.7.0 - Stored XSS
CVSS 5.7
InvoicePlane 1.7.0 - RCE via LFI & Log Poisoning
CVSS 9.1
InvoicePlane 1.7.0 - Stored XSS
CVSS 4.8
InvoicePlane 1.7.0 - Stored XSS
CVSS 4.8
InvoicePlane 1.7.0 - Stored XSS
CVSS 4.8
InvoicePlane <1.7.1 - Stored XSS
CVSS 5.4
InvoicePlane 1.7.1 - Stored XSS
CVSS 4.4
Pypi Mitmproxy < 11.1.2 - Remote Code Execution
Langroid <0.53.15 - Code Injection
CVSS 9.8
Langroid <0.53.15 - Code Injection
CVSS 9.8
kotaemon <0.10.6 - Path Traversal
CVSS 6.5
Lara Translate MCP Server <0.0.11 - Command Injection
CVSS 7.5
Gitpod <main-gha.33628 - CSRF
CVSS 6.5
SillyTavern <1.13.4 - SSRF
CVSS 9.6