Open Source Vulnerabilities
apache
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
apache
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
discourse
Discourse DoS via remote theme assets
dotnet-sdk
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
dotnet-sdk
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
jupyter-notebook
Insertion of Sensitive Information into Log File affects Jupyter Notebook
jupyter-notebook
Insertion of Sensitive Information into Log File affects Jupyter Notebook
gitlab
Improper Certificate Validation in GitLab
jupyterlab
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
jupyterlab
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
jupyter-base-notebook
Insertion of Sensitive Information into Log File affects Jupyter Notebook
jupyter-base-notebook
Insertion of Sensitive Information into Log File affects Jupyter Notebook
envoy
Envoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received.
envoy
Envoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received.
dotnet
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
dotnet
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
golang
Arbitrary code execution via go.mod toolchain directive in cmd/go
golang
Arbitrary code execution via go.mod toolchain directive in cmd/go
drupal
Cross-site Scripting in CKEditor4
airflow
Apache Airflow: ReDoS via dags function
kafka
Unauthenticated clients may cause OutOfMemoryError on Apache Kafka Brokers
kafka
Unauthenticated clients may cause OutOfMemoryError on Apache Kafka Brokers
apache
Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier
apache
Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier
helm
Repository credentials passed to alternate domain
discourse
Discourse DoS via SvgSprite cache
ghost
Privilege escalation: all users can access Admin-level API keys
ghost
Privilege escalation: all users can access Admin-level API keys
gitlab
Inefficient Regular Expression Complexity in GitLab
gitlab
Inefficient Regular Expression Complexity in GitLab
jupyter-notebook
Forced Browsing in Jupyter Notebook
jupyter-notebook
Forced Browsing in Jupyter Notebook
jupyterlab
Stored cross site scripting in Markdown Preview in JupyterLab
jupyterlab
Stored cross site scripting in Markdown Preview in JupyterLab
dotnet-sdk
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
dotnet-sdk
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
jupyter-base-notebook
Forced Browsing in Jupyter Notebook
jupyter-base-notebook
Forced Browsing in Jupyter Notebook
envoy
Envoy forwards invalid Http2/Http3 downstream headers
envoy
Envoy forwards invalid Http2/Http3 downstream headers
dotnet
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
dotnet
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
golang
Panic when processing post-handshake message on QUIC connections in crypto/tls
golang
Panic when processing post-handshake message on QUIC connections in crypto/tls
airflow
Apache Airflow: Exposure of sensitive connection information, DOS and SSRF on "test connection" feature
airflow
Apache Airflow: Exposure of sensitive connection information, DOS and SSRF on "test connection" feature
aspnet-core
Microsoft ASP.NET Core Security Feature Bypass Vulnerability
aspnet-core
Microsoft ASP.NET Core Security Feature Bypass Vulnerability
apache
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
apache
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
