Incomplete in the CWE catalog · 11 CVEs mapped
The product includes web functionality (such as a web widget) from another domain, which causes it to operate within the domain of the product, potentially granting total access and control of the product to the untrusted source.
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN packets.
Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and Minder Go versions from 0.0.72 to 0.0.83, Minder users may fetch content in the context of the Minder server, which may include URLs which the user would not normally have access to. This issue has been patched in Minder Helm version 0.20250203.3849+ref.fdc94f0 and Minder Go version 0.0.84.
⚡ A cunning code injection vulnerability hides in the Direct Connections feature of Open WebUI, allowing attackers to execute arbitrary JavaScript in victim browsers. 🔥 Think of it like a sneaky waiter who brings a dish to your table that’s laced with an ingredient you didn’t order — if a malicious external model server is added, it gets the chance to spice things up in your browser without any checks! This is no picnic! An attacker could easily steal authentication tokens and take full control of user accounts. If they chain this with the Functions API, they could even execute remote code on the backend server, putting your entire system at risk!