Open Source Vulnerabilities
ruby-protocol-http1, ruby-protocol-http1, ruby-protocol-http1, ruby-protocol-http1
ruby-protocol-http1/ ruby-protocol-http1/ ruby-protocol-http1/ ruby-protocol-http1
Knowage Server vulnerable to path traversal via upload functionality
Knowage Server vulnerable to path traversal via upload functionality
matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms
matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms
amanda, amanda
Security update for amanda
amanda, amanda
Security update for amanda
MindsDB 'Call to requests with verify=False disabling SSL certificate checks, security issue.' issue
MindsDB 'Call to requests with verify=False disabling SSL certificate checks, security issue.' issue
.eth registrar controller can shorten the duration of registered names
.eth registrar controller can shorten the duration of registered names
protocol-http1 HTTP Request/Response Smuggling vulnerability
github.com/projectdiscovery/nuclei/v2, github.com/projectdiscovery/nuclei
Nuclei Path Traversal vulnerability
github.com/projectdiscovery/nuclei/v2/ github.com/projectdiscovery/nuclei
Nuclei Path Traversal vulnerability
matrix-appservice-irc
matrix-appservice-irc IRC command injection via admin commands containing newlines
matrix-appservice-irc
matrix-appservice-irc IRC command injection via admin commands containing newlines
matrix-appservice-bridge, matrix-appservice-bridge
matrix-appservice-bridge doesn't verify the sub parameter of an openId token exhange, allowing unauthorized access to provisioning APIs
matrix-appservice-bridge/ matrix-appservice-bridge
matrix-appservice-bridge doesn't verify the sub parameter of an openId token exhange, allowing unauthorized access to provisioning APIs
matrix-appservice-irc
matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms
matrix-appservice-irc
matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms
cypress-image-snapshot vulnerable to insecure snapshot file names
cypress-image-snapshot vulnerable to insecure snapshot file names
Command injection vulnerability in module management function in CloudExplorer Lite
Command injection vulnerability in module management function in CloudExplorer Lite
Unrestricted Upload of File with Dangerous Type in omeka/omeka-s
Unrestricted Upload of File with Dangerous Type in omeka/omeka-s
Cross-site Scripting (XSS) - Stored in omeka/omeka-s
Improper Neutralization of Special Elements in Output Used by a Downstream Component in omeka/omeka-s
Improper Neutralization of Special Elements in Output Used by a Downstream Component in omeka/omeka-s
matrix-appservice-bridge doesn't verify the sub parameter of an openId token exhange, allowing unauthorized access to provisioning APIs
matrix-appservice-bridge doesn't verify the sub parameter of an openId token exhange, allowing unauthorized access to provisioning APIs
matrix-appservice-irc IRC command injection via admin commands containing newlines
matrix-appservice-irc IRC command injection via admin commands containing newlines
Deserialization of Untrusted Data in network IO
twitch-tui's connection is not encrypted
cargo, rust-cargo, rust-cargo, rust-cargo
rust, rust, rust, rust, rust, rust
rust
CVE-2023-38497 affecting package rust for versions less than 1.72.0-2
rust
CVE-2023-38497 affecting package rust for versions less than 1.72.0-2
Sydent does not verify email server certificates
Cargo not respecting umask when extracting crate archives
The cloud version of the MeterSphere interface leaks some sensitive data without authentication
The cloud version of the MeterSphere interface leaks some sensitive data without authentication
HedgeDoc API allows to hide existing notes
pyrocms/pyrocms
PyroCMS remote code execution vulnerability
pyrocms/pyrocms
PyroCMS remote code execution vulnerability
Metabase vulnerable to remote code execution via POST /api/setup/validate API endpoint
Metabase vulnerable to remote code execution via POST /api/setup/validate API endpoint
Aerospike Java Client vulnerable to unsafe deserialization of server responses
Aerospike Java Client vulnerable to unsafe deserialization of server responses
jq
Segv on unknown address in decUnitCompare
