Open Source Vulnerabilities
Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization
Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization
ash,
Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization
ash/
Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization
alt-design/alt-redirect
Alt Redirect: Potential Authentication Bypass by Spoofing through query-string stripping logic flaw
alt-design/alt-redirect
Alt Redirect: Potential Authentication Bypass by Spoofing through query-string stripping logic flaw
com.liferay.commerce:com.liferay.commerce.order.web
Liferay Portal Commerce is vulnerable to XSS through account "name" field
com.liferay.commerce:com.liferay.commerce.order.web
Liferay Portal Commerce is vulnerable to XSS through account "name" field
com.liferay:com.liferay.portal.workflow.kaleo.designer.web
Liferay Portal is vulnerable to XSS through its workflow process builder
com.liferay:com.liferay.portal.workflow.kaleo.designer.web
Liferay Portal is vulnerable to XSS through its workflow process builder
com.liferay:com.liferay.account.admin.web
Liferay Portal's Membership page is vulnerable to XSS through “name“ text field
com.liferay:com.liferay.account.admin.web
Liferay Portal's Membership page is vulnerable to XSS through “name“ text field
expat, expat, expat, expat, expat, expat
Security update for expat
expat/ expat/ expat/ expat/ expat/ expat
Security update for expat
expat, expat
Security update for expat
open-vm-tools, open-vm-tools, open-vm-tools, open-vm-tools, open-vm-tools, open-vm-tools, open-vm-tools
Security update for open-vm-tools
open-vm-tools/ open-vm-tools/ open-vm-tools/ open-vm-tools/ open-vm-tools/ open-vm-tools/ open-vm-tools
Security update for open-vm-tools
podman, podman, podman, podman, podman, podman
Security update for podman
podman/ podman/ podman/ podman/ podman/ podman
Security update for podman
podofo
Security update for podofo
CURL_jll, LibCURL_jll
libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized...
CURL_jll/ LibCURL_jll
libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized...
LibCURL_jll
libcurl's URL API function [`curl_url_get()`](https://curl.se/libcurl/c/curl_url_get.html) offers...
LibCURL_jll
libcurl's URL API function [`curl_url_get()`](https://curl.se/libcurl/c/curl_url_get.html) offers...
CURL_jll, LibCURL_jll
libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string
CURL_jll/ LibCURL_jll
libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string
CURL_jll, LibCURL_jll
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a...
CURL_jll/ LibCURL_jll
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a...
LibCURL_jll
A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate...
LibCURL_jll
A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate...
CURL_jll, LibCURL_jll
An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature...
CURL_jll/ LibCURL_jll
An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature...
CURL_jll, LibCURL_jll
An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which...
CURL_jll/ LibCURL_jll
An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which...
LibCURL_jll
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances...
LibCURL_jll
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances...
LibCURL_jll
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if...
LibCURL_jll
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if...
LibCURL_jll
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to...
LibCURL_jll
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to...
LibCURL_jll
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to...
LibCURL_jll
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to...
LibCURL_jll
Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when...
LibCURL_jll
Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when...
LibCURL_jll
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow...
LibCURL_jll
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow...
LibCURL_jll
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to...
LibCURL_jll
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to...
CURL_jll, LibCURL_jll
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake.
CURL_jll/ LibCURL_jll
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake.
CURL_jll, LibCURL_jll
This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the...
CURL_jll/ LibCURL_jll
This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the...
python-3.9, python-3.9-base, python-3.9-base-dev, python-3.9-dev, python-3.9-doc
python-3.9/ python-3.9-base/ python-3.9-base-dev/ python-3.9-dev/ python-3.9-doc
redis, redis-devel, redis-doc
redis: Fix of CVE-2025-49844
redis/ redis-devel/ redis-doc
redis: Fix of CVE-2025-49844
exiv2, exiv2-devel, exiv2-doc, exiv2-libs
exiv2: Fix of CVE-2025-55304
exiv2/ exiv2-devel/ exiv2-doc/ exiv2-libs
exiv2: Fix of CVE-2025-55304
linux
Kernel vulnerabilities are irrelevant in container environments.
linux
Kernel vulnerabilities are irrelevant in container environments.
linux
Kernel vulnerabilities are irrelevant in container environments.
linux
Kernel vulnerabilities are irrelevant in container environments.
linux
Kernel vulnerabilities are irrelevant in container environments.
linux
Kernel vulnerabilities are irrelevant in container environments.
linux
Kernel vulnerabilities are irrelevant in container environments.
linux
Kernel vulnerabilities are irrelevant in container environments.
Dbus_jll
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon
Dbus_jll
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon
Dbus_jll
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before...
Dbus_jll
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before...
Dbus_jll
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before...
Dbus_jll
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before...
Dbus_jll
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before...
Dbus_jll
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before...
Dbus_jll
An issue was discovered in dbus >= 1.3.0 before 1.12.18
Dbus_jll
An issue was discovered in dbus >= 1.3.0 before 1.12.18
nss, nss-devel, nss-pkcs11-devel, nss-sysinit, nss-tools
nss: Fix of CVE-2020-25648
nss/ nss-devel/ nss-pkcs11-devel/ nss-sysinit/ nss-tools
nss: Fix of CVE-2020-25648
binutils, binutils-devel
binutils: Fix of CVE-2017-9042
Cairo_jll
An issue was discovered in cairo 1.16.0
Cairo_jll
An issue was discovered in cairo 1.16.0
Cairo_jll
cairo 1.16.0, in `cairo_ft_apply_variations()` in cairo-ft-font.c, would free memory using a free...
Cairo_jll
cairo 1.16.0, in `cairo_ft_apply_variations()` in cairo-ft-font.c, would free memory using a free...
Cairo_jll
cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted...
Cairo_jll
cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted...
