Copilot
35 exploits
Active since Feb 2025
gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule
CVSS 7.8
HestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP Header
CVSS 7.5
openvpn-auth-oauth2 returns FUNC_SUCCESS on client-deny, allowing unauthenticated VPN access
CVSS 10.0
Kotaemon < 0.11.0 - Stored Cross-Site Scripting via PDF Content Rendering
CVSS 6.1
Kotaemon < 0.11.0 - Plaintext Password Storage in LocalStorage
CVSS 7.5
Whyour Qinglong <=2.20.1 - Auth Bypass
CVSS 6.3
baomidou dynamic-datasource 2.5.0 - Expression Injection
CVSS 6.3
Aperi'Solve Affected by Unauthenticated RCE via JPSeek Analyzer Command
CVSS 9.8
ONNX: Path Traversal via Symlink
CVSS 7.5
ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load
CVSS 4.7
WeChat Pay callback signature verification bypassed when Host header is localhost
CVSS 8.6
plexus-utils <4.0.3 - Path Traversal
CVSS 8.8
stellar-xdr <25.0.1 - Memory Corruption
CVSS 4.0
Pimcore <=11.5.14.1/12.3.2 - SQL Injection
CVSS 4.9
InvoicePlane 1.7.0 - Authenticated Stored Cross-Site Scripting via Invoice Logo Upload
CVSS 5.7
InvoicePlane 1.7.0 - Authenticated Stored Cross-Site Scripting via Invoice Number Parameter
CVSS 5.7
InvoicePlane 1.7.0 - Authenticated Stored Cross-Site Scripting via Quote Number Parameter
CVSS 5.7
InvoicePlane 1.7.0 - Authenticated Stored Cross-Site Scripting via SVG Logo Upload
CVSS 5.7
InvoicePlane 1.7.0 - RCE via LFI & Log Poisoning
CVSS 9.1
InvoicePlane < 1.7.1 - Stored Cross-Site Scripting via Family Name Field
CVSS 4.8
InvoicePlane < 1.7.1 - Authenticated Stored Cross-Site Scripting via Invoice Number Field
CVSS 4.8
InvoicePlane < 1.7.1 - Authenticated Stored Cross-Site Scripting via Product Unit Name Field
CVSS 4.8
InvoicePlane - Authenticated Stored Cross-Site Scripting via Invoice Group Identifier Format Field
CVSS 5.4
InvoicePlane - Authenticated Stored Cross-Site Scripting in Sumex Invoice View
CVSS 4.4
mitmproxy < 11.1.2 - Server-Side Request Forgery via Proxy to Internal API