Open Source Vulnerabilities
Default `maxSignatureAttempts` in `notation verify` enables an endless data attack in notation
Default `maxSignatureAttempts` in `notation verify` enables an endless data attack in notation
Denial of service from high number of artifact signatures in notation
Denial of service from high number of artifact signatures in notation
Stored cross site scripting (XSS) via unrestricted file upload in Kiwi TCMS
Stored cross site scripting (XSS) via unrestricted file upload in Kiwi TCMS
Cross-site Scripting (XSS) in Web GUI in syncthing
kernel-livepatch-SLE15-SP4_Update_1
Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP4)
kernel-livepatch-SLE15-SP4_Update_1
Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP4)
fast-xml-parser
fast-xml-parser vulnerable to Regex Injection via Doctype Entities
fast-xml-parser
fast-xml-parser vulnerable to Regex Injection via Doctype Entities
ruby-redcloth, ruby-redcloth, ruby-redcloth
ruby-redcloth, ruby-redcloth, ruby-redcloth, ruby-redcloth
ruby-redcloth/ ruby-redcloth/ ruby-redcloth/ ruby-redcloth
kernel-livepatch-SLE15-SP3_Update_23
Security update for the Linux Kernel (Live Patch 23 for SLE 15 SP3)
kernel-livepatch-SLE15-SP3_Update_23
Security update for the Linux Kernel (Live Patch 23 for SLE 15 SP3)
avo, avo
avo possible unsafe reflection / partial DoS vulnerability
avo/ avo
avo possible unsafe reflection / partial DoS vulnerability
kiwitcms
kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload
kiwitcms
kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload
github.com/notaryproject/notation-go
notation-go's verification bypass can cause users to verify the wrong artifact
github.com/notaryproject/notation-go
notation-go's verification bypass can cause users to verify the wrong artifact
github.com/notaryproject/notation
Notation's default `maxSignatureAttempts` in `notation verify` enables an endless data attack
github.com/notaryproject/notation
Notation's default `maxSignatureAttempts` in `notation verify` enables an endless data attack
github.com/notaryproject/notation
Notation vulnerable to denial of service from high number of artifact signatures
github.com/notaryproject/notation
Notation vulnerable to denial of service from high number of artifact signatures
matrix-synapse
Synapse has URL deny list bypass via oEmbed and image URLs when generating previews
matrix-synapse
Synapse has URL deny list bypass via oEmbed and image URLs when generating previews
matrix-synapse
Synapse has improper checks for deactivated users during login
matrix-synapse
Synapse has improper checks for deactivated users during login
github.com/syncthing/syncthing
syncthing vulnerable to Cross-site Scripting (XSS) in Web GUI
github.com/syncthing/syncthing
syncthing vulnerable to Cross-site Scripting (XSS) in Web GUI
kgraft-patch-SLE12-SP4_Update_27
Security update for the Linux Kernel (Live Patch 27 for SLE 12 SP4)
kgraft-patch-SLE12-SP4_Update_27
Security update for the Linux Kernel (Live Patch 27 for SLE 12 SP4)
Command Injection Vulnerability in `Release PR Merged` Workflow in taosdata/grafanaplugin
Command Injection Vulnerability in `Release PR Merged` Workflow in taosdata/grafanaplugin
kgraft-patch-SLE12-SP4_Update_30
Security update for the Linux Kernel (Live Patch 30 for SLE 12 SP4)
kgraft-patch-SLE12-SP4_Update_30
Security update for the Linux Kernel (Live Patch 30 for SLE 12 SP4)
kernel-livepatch-SLE15-SP2_Update_35, kernel-livepatch-SLE15-SP3_Update_31
Security update for the Linux Kernel (Live Patch 31 for SLE 15 SP3)
kernel-livepatch-SLE15-SP2_Update_35/ kernel-livepatch-SLE15-SP3_Update_31
Security update for the Linux Kernel (Live Patch 31 for SLE 15 SP3)
kernel-livepatch-SLE15-SP3_Update_28
Security update for the Linux Kernel (Live Patch 28 for SLE 15 SP3)
kernel-livepatch-SLE15-SP3_Update_28
Security update for the Linux Kernel (Live Patch 28 for SLE 15 SP3)
kgraft-patch-SLE12-SP5_Update_39
Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP5)
kgraft-patch-SLE12-SP5_Update_39
Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP5)
kernel-livepatch-SLE15-SP2_Update_36
Security update for the Linux Kernel (Live Patch 36 for SLE 15 SP2)
kernel-livepatch-SLE15-SP2_Update_36
Security update for the Linux Kernel (Live Patch 36 for SLE 15 SP2)
avo, avo
avo vulnerable to Stored XSS (Cross Site Scripting) in html content based fields
avo/ avo
avo vulnerable to Stored XSS (Cross Site Scripting) in html content based fields
kernel-livepatch-SLE15-SP2_Update_29, kernel-livepatch-SLE15-SP3_Update_19
Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP3)
kernel-livepatch-SLE15-SP2_Update_29/ kernel-livepatch-SLE15-SP3_Update_19
Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP3)
mosquitto
Segv on unknown address in config__bridge_cleanup
