Open Source Vulnerabilities
products-cmfcore, products-cmfcore
Products.CMFCore unauthenticated denial of service and crash via unchecked use of input with Python's marshal module
products-cmfcore/ products-cmfcore
Products.CMFCore unauthenticated denial of service and crash via unchecked use of input with Python's marshal module
kiwitcms
Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
kiwitcms
Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
opensource-workshop/connect-cms, opensource-workshop/connect-cms
Connect-CMS Privilege Escalation Vulnerability
opensource-workshop/connect-cms/ opensource-workshop/connect-cms
Connect-CMS Privilege Escalation Vulnerability
github.com/1Panel-dev/1Panel
1Panel vulnerable to command injection when entering the container terminal
github.com/1Panel-dev/1Panel
1Panel vulnerable to command injection when entering the container terminal
github.com/1Panel-dev/1Panel
1Panel vulnerable to command injection when adding container repositories
github.com/1Panel-dev/1Panel
1Panel vulnerable to command injection when adding container repositories
@fastify/oauth2
@fastify/oauth2 vulnerable to Cross Site Request Forgery due to reused Oauth2 state
@fastify/oauth2
@fastify/oauth2 vulnerable to Cross Site Request Forgery due to reused Oauth2 state
mechanicalsoup
MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form
mechanicalsoup
MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form
github.com/cometbft/cometbft, github.com/cometbft/cometbft
CometBFT may duplicate transactions in the mempool's data structures
github.com/cometbft/cometbft/ github.com/cometbft/cometbft
CometBFT may duplicate transactions in the mempool's data structures
github.com/cometbft/cometbft, github.com/cometbft/cometbft
CometBFT PeerState JSON serialization deadlock
github.com/cometbft/cometbft/ github.com/cometbft/cometbft
CometBFT PeerState JSON serialization deadlock
Statamic's Antlers sanitizer cannot effectively sanitize malicious SVG
Statamic's Antlers sanitizer cannot effectively sanitize malicious SVG
Fides vulnerable to Path Traversal in Webserver API
Uptime Kuma authenticated path traversal via plugin repository name may lead to unavailability or data loss
Uptime Kuma authenticated path traversal via plugin repository name may lead to unavailability or data loss
haskell-pandoc, haskell-pandoc, pandoc, pandoc, pandoc
pandoc, pandoc, pandoc, pandoc, pandoc, pandoc, pandoc, pandoc
pandoc/ pandoc/ pandoc/ pandoc/ pandoc/ pandoc/ pandoc/ pandoc
kodi, kodi, kodi, kodi, kodi, kodi, kodi
Uptime Kuma vulnerable to authenticated remote code execution via malicious plugin installation
Uptime Kuma vulnerable to authenticated remote code execution via malicious plugin installation
Kanboard Authenticated SQL Injections vulnerability
Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
1Panel vulnerable to command injection when adding container repositories
1Panel vulnerable to command injection when adding container repositories
1Panel vulnerable to ommand injection when entering the container terminal
1Panel vulnerable to ommand injection when entering the container terminal
GLPI vulnerable to SQL injection through Computer Virtual Machine information
GLPI vulnerable to SQL injection through Computer Virtual Machine information
GLPI vulnerable to unauthenticated access to Dashboard data
GLPI vulnerable to unauthorized access to Dashboard data
Arbitrary file write is possible in Pandoc when using PDF output or --extract-media with untrusted input
Arbitrary file write is possible in Pandoc when using PDF output or --extract-media with untrusted input
python-mechanicalsoup, python-mechanicalsoup, python-mechanicalsoup
python-mechanicalsoup/ python-mechanicalsoup/ python-mechanicalsoup
python-mechanicalsoup, python-mechanicalsoup, python-mechanicalsoup, python-mechanicalsoup, python-mechanicalsoup, python-mechanicalsoup
python-mechanicalsoup/ python-mechanicalsoup/ python-mechanicalsoup/ python-mechanicalsoup/ python-mechanicalsoup/ python-mechanicalsoup
GLPI vulnerable to SQL injection via inventory agent request
MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form
MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form
GLPI vulnerable to reflected XSS in search pages
GLPI vulnerable to unauthorized access to KnowbaseItem data
