Open Source Vulnerabilities
mongodb, mongodb, mongodb, mongodb
rclone, rclone, rclone, rclone, rclone
rclone, rclone, rclone, rclone, rclone
rclone, rclone, rclone, rclone, rclone
tesseract, tesseract, tesseract, tesseract, tesseract, tesseract, tesseract
tesseract/ tesseract/ tesseract/ tesseract/ tesseract/ tesseract/ tesseract
tesseract, tesseract, tesseract, tesseract, tesseract, tesseract, tesseract
tesseract/ tesseract/ tesseract/ tesseract/ tesseract/ tesseract/ tesseract
tesseract, tesseract, tesseract, tesseract, tesseract, tesseract, tesseract
tesseract/ tesseract/ tesseract/ tesseract/ tesseract/ tesseract/ tesseract
tesseract, tesseract, tesseract, tesseract, tesseract, tesseract, tesseract
tesseract/ tesseract/ tesseract/ tesseract/ tesseract/ tesseract/ tesseract
tesseract, tesseract, tesseract, tesseract, tesseract, tesseract, tesseract
tesseract/ tesseract/ tesseract/ tesseract/ tesseract/ tesseract/ tesseract
tesseract, tesseract, tesseract, tesseract, tesseract, tesseract, tesseract
tesseract/ tesseract/ tesseract/ tesseract/ tesseract/ tesseract/ tesseract
tesseract, tesseract, tesseract, tesseract, tesseract, tesseract, tesseract
tesseract/ tesseract/ tesseract/ tesseract/ tesseract/ tesseract/ tesseract
tesseract, tesseract, tesseract, tesseract, tesseract, tesseract, tesseract
tesseract/ tesseract/ tesseract/ tesseract/ tesseract/ tesseract/ tesseract
angular.js, angular.js, angular.js, angular.js, angular.js, angular.js
angular.js/ angular.js/ angular.js/ angular.js/ angular.js/ angular.js
angular.js, angular.js, angular.js, angular.js, angular.js, angular.js
angular.js/ angular.js/ angular.js/ angular.js/ angular.js/ angular.js
angular.js, angular.js, angular.js, angular.js, angular.js, angular.js
angular.js/ angular.js/ angular.js/ angular.js/ angular.js/ angular.js
angular.js, angular.js, angular.js, angular.js, angular.js, angular.js
angular.js/ angular.js/ angular.js/ angular.js/ angular.js/ angular.js
angular.js, angular.js, angular.js, angular.js, angular.js, angular.js
angular.js/ angular.js/ angular.js/ angular.js/ angular.js/ angular.js
evolution, evolution, evolution, evolution, evolution, evolution
evolution/ evolution/ evolution/ evolution/ evolution/ evolution
gvfs, gvfs, gvfs, gvfs, gvfs, gvfs
netty, netty, netty, netty, netty, netty, netty
gpac, gpac, gpac, gpac, gpac, gpac
gpac, gpac, gpac, gpac, gpac, gpac
gpac, gpac, gpac, gpac, gpac, gpac
sssd, sssd, sssd, sssd, sssd, sssd
[UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks
[UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks
Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another.
Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another.
Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calendar block's frontend event dialog (/ccm/calendar/view_event/{bID}/{occurrence_id}).
Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calendar block's frontend event dialog (/ccm/calendar/view_event/{bID}/{occurrence_id}).
open-webui
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
open-webui
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
github.com/traefik/traefik/v3/ github.com/traefik/traefik/v2
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
github.com/traefik/traefik/v3
Traefik entrypoint header-name sanitization bypassed via request trailers
github.com/traefik/traefik/v3
Traefik entrypoint header-name sanitization bypassed via request trailers
github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
Traefik HTTP/3 Backend NTLM Connection Reuse
github.com/traefik/traefik/v3/ github.com/traefik/traefik/v2
Traefik HTTP/3 Backend NTLM Connection Reuse
github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
github.com/traefik/traefik/v3/ github.com/traefik/traefik/v2
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
github.com/rclone/rclone
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
github.com/rclone/rclone
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
github.com/rclone/rclone
rclone: http backend forwards custom/auth headers to a different host on redirect
github.com/rclone/rclone
rclone: http backend forwards custom/auth headers to a different host on redirect
github.com/rclone/rclone
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
github.com/rclone/rclone
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
github.com/rclone/rclone
rclone local: crafted Range request against a translated symlink panics (DoS)
github.com/rclone/rclone
rclone local: crafted Range request against a translated symlink panics (DoS)
github.com/rclone/rclone
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
github.com/rclone/rclone
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
github.com/rclone/rclone
rclone: RC per-server auth-proxy bypass
github.com/rclone/rclone
rclone: RC per-server auth-proxy bypass
github.com/rclone/rclone
rclone: FTP cross-session auth-proxy backend confusion
github.com/rclone/rclone
rclone: FTP cross-session auth-proxy backend confusion
github.com/rclone/rclone
rclone: source object names can escape the configured root on upload
github.com/rclone/rclone
rclone: source object names can escape the configured root on upload
github.com/rclone/rclone
rclone: S3 multipart declared-length memory exhaustion
github.com/rclone/rclone
rclone: S3 multipart declared-length memory exhaustion
open-webui
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
open-webui
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
