Open Source Vulnerabilities
Moodle: stored xss and potential idor risk in wiki comments
Moodle: students can view other users in "only see own membership" groups
Moodle: students can view other users in "only see own membership" groups
Moodle: xss risk when using csv grade import method
Moodle: authenticated remote code execution risk in imscp
Moodle: authenticated remote code execution risk in lesson
github.com/sigstore/cosign, github.com/sigstore/cosign/v2
Denial of service attack from remote registry in github.com/sigstore/cosign
github.com/sigstore/cosign/ github.com/sigstore/cosign/v2
Denial of service attack from remote registry in github.com/sigstore/cosign
asyncssh
AsyncSSH Rogue Session Attack
esptool
esptool allows attackers to view sensitive information via weak cryptographic algorithm
esptool
esptool allows attackers to view sensitive information via weak cryptographic algorithm
openmct
NASA Open MCT Cross Site Request Forgery (CSRF) vulnerability
openmct
NASA Open MCT Cross Site Request Forgery (CSRF) vulnerability
openmct
NASA Open MCT Cross Site Scripting vulnerability
openmct
NASA Open MCT Cross Site Scripting vulnerability
asyncssh
AsyncSSH Rogue Extension Negotiation
WordPress Top 10 Plugin <= 3.3.2 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress Top 10 Plugin <= 3.3.2 is vulnerable to Cross Site Request Forgery (CSRF)
github.com/sigstore/cosign
Improper certificate validation in github.com/sigstore/cosign
github.com/sigstore/cosign
Improper certificate validation in github.com/sigstore/cosign
github.com/sigstore/cosign
Improper verification of signature attestations in github.com/sigstore/cosign
github.com/sigstore/cosign
Improper verification of signature attestations in github.com/sigstore/cosign
golang
CVE-2023-45284 affecting package golang 1.27.1-1
golang
CVE-2023-45283 affecting package golang 1.27.1-1
golang
CVE-2023-45283 affecting package golang 1.26.7-1
golang
CVE-2023-45284 affecting package golang 1.26.7-1
golang
CVE-2023-45284 affecting package golang for versions less than 1.21.6-1
golang
CVE-2023-45284 affecting package golang for versions less than 1.21.6-1
golang
CVE-2023-45283 affecting package golang for versions less than 1.21.6-1
golang
CVE-2023-45283 affecting package golang for versions less than 1.21.6-1
golang
CVE-2023-45284 affecting package golang for versions less than 1.21.6-1
golang
CVE-2023-45284 affecting package golang for versions less than 1.21.6-1
golang
CVE-2023-45283 affecting package golang for versions less than 1.21.6-1
golang
CVE-2023-45283 affecting package golang for versions less than 1.21.6-1
msft-golang
CVE-2023-45283 affecting package msft-golang for versions less than 1.20.11-1
msft-golang
CVE-2023-45283 affecting package msft-golang for versions less than 1.20.11-1
golang-1.10, golang-1.10, golang-1.6, golang-1.13, golang-1.18, golang-1.10, golang-1.13, golang-1.16, golang-1.18, golang-1.8, golang-1.9, golang-1.13, golang-1.14, golang-1.16, golang-1.18, golang-1.17, golang-1.18, golang-1.13
golang-1.10/ golang-1.10/ golang-1.6/ golang-1.13/ golang-1.18/ golang-1.10/ golang-1.13/ golang-1.16/ golang-1.18/ golang-1.8/ golang-1.9/ golang-1.13/ golang-1.14/ golang-1.16/ golang-1.18/ golang-1.17/ golang-1.18/ golang-1.13
golang-1.10, golang-1.10, golang-1.6, golang-1.13, golang-1.18, golang-1.10, golang-1.13, golang-1.16, golang-1.18, golang-1.8, golang-1.9, golang-1.13, golang-1.14, golang-1.16, golang-1.18, golang-1.17, golang-1.18, golang-1.13
golang-1.10/ golang-1.10/ golang-1.6/ golang-1.13/ golang-1.18/ golang-1.10/ golang-1.13/ golang-1.16/ golang-1.18/ golang-1.8/ golang-1.9/ golang-1.13/ golang-1.14/ golang-1.16/ golang-1.18/ golang-1.17/ golang-1.18/ golang-1.13
Incorrect detection of reserved device names on Windows in path/filepath
Incorrect detection of reserved device names on Windows in path/filepath
Insecure parsing of Windows paths with a \??\ prefix in path/filepath
Insecure parsing of Windows paths with a \??\ prefix in path/filepath
esptool, esptool, esptool, esptool, esptool, esptool, esptool
esptool/ esptool/ esptool/ esptool/ esptool/ esptool/ esptool
software.amazon.cryptography:aws-database-encryption-sdk-dynamodb
Signing DynamoDB Sets when using the AWS Database Encryption SDK.
software.amazon.cryptography:aws-database-encryption-sdk-dynamodb
Signing DynamoDB Sets when using the AWS Database Encryption SDK.
prestashop/blockreassurance
Any value can be changed in the configuration table by an employee having access to block reassurance module
prestashop/blockreassurance
Any value can be changed in the configuration table by an employee having access to block reassurance module
The same file cannot be opened with different rights
Any value can be changed in the configuration table by an employee having access to block reassurance module
Any value can be changed in the configuration table by an employee having access to block reassurance module
