Open Source Vulnerabilities
v8n
v8n vulnerable to Inefficient Regular Expression Complexity
v8n
v8n vulnerable to Inefficient Regular Expression Complexity
twisted
Twisted vulnerable to HTTP Request Smuggling Attacks
twisted
Twisted vulnerable to HTTP Request Smuggling Attacks
flask-security
Flask-Security vulnerable to Open Redirect
flask-security
Flask-Security vulnerable to Open Redirect
github.com/supranational/blst
Blst vulnerable to incorrect results for some inputs in blst_fp_eucl_inverse function
github.com/supranational/blst
Blst vulnerable to incorrect results for some inputs in blst_fp_eucl_inverse function
github.com/tendermint/tendermint
Tendermint Core vulnerable to Uncontrolled Resource Consumption
github.com/tendermint/tendermint
Tendermint Core vulnerable to Uncontrolled Resource Consumption
tensorflow, tensorflow-cpu, tensorflow-gpu
TensorFlow vulnerable to heap out of bounds read in filesystem glob matching
tensorflow/ tensorflow-cpu/ tensorflow-gpu
TensorFlow vulnerable to heap out of bounds read in filesystem glob matching
atlassian/gajira-create
gajira-create GitHub action vulnerable to arbitrary code execution
atlassian/gajira-create
gajira-create GitHub action vulnerable to arbitrary code execution
github.com/antchfx/xmlquery
xmlquery lacks check for whether LoadURL response is in XML format, causing denial of service
github.com/antchfx/xmlquery
xmlquery lacks check for whether LoadURL response is in XML format, causing denial of service
github.com/russellhaering/goxmldsig, github.com/russellhaering/gosaml2
goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures
github.com/russellhaering/goxmldsig/ github.com/russellhaering/gosaml2
goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures
dhcp, dhcp, dhcp, dhcp, dhcp, dhcp, dhcp, dhcp
dhcp, dhcp, dhcp, dhcp, dhcp, dhcp, dhcp, dhcp
ndpi
Stack-buffer-overflow in check_content_type_and_change_protocol
ndpi
Stack-buffer-overflow in check_content_type_and_change_protocol
ghostscript
Stack-buffer-underflow in gs_type2_interpret
knot-resolver
knot-resolver - security update
Improper Privilege Management in tooljet/tooljet
Allocation of Resources Without Limits or Throttling in nocodb/nocodb
Allocation of Resources Without Limits or Throttling in nocodb/nocodb
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
Plaintext transmission of CSRF tokens in tiny-csrf
CSRF key bypass using HTTP methods in zoneminder
Denial of service through logs in zoneminder
Session still functional after user is deactivated
heimdal, heimdal, heimdal, heimdal, heimdal, heimdal, heimdal, heimdal
heimdal/ heimdal/ heimdal/ heimdal/ heimdal/ heimdal/ heimdal/ heimdal
go.etcd.io/etcd/client/v3, go.etcd.io/etcd/client/v3
etcd having a negative value for cluster node size results in an index out-of-bound panic during service discovery
go.etcd.io/etcd/client/v3/ go.etcd.io/etcd/client/v3
etcd having a negative value for cluster node size results in an index out-of-bound panic during service discovery
go.etcd.io/etcd/client/v3, go.etcd.io/etcd/client/v3
etcd user credentials are stored in WAL logs in plaintext
go.etcd.io/etcd/client/v3/ go.etcd.io/etcd/client/v3
etcd user credentials are stored in WAL logs in plaintext
go.etcd.io/etcd/client/v3, go.etcd.io/etcd/client/v3
etcd has no minimum password length
go.etcd.io/etcd/client/v3/ go.etcd.io/etcd/client/v3
etcd has no minimum password length
go.etcd.io/etcd/v3, go.etcd.io/etcd/v3
etcd vulnerable to TOCTOU of gateway endpoint authentication
go.etcd.io/etcd/v3/ go.etcd.io/etcd/v3
etcd vulnerable to TOCTOU of gateway endpoint authentication
go.etcd.io/etcd/v3, go.etcd.io/etcd/v3
etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic
go.etcd.io/etcd/v3/ go.etcd.io/etcd/v3
etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic
github.com/caddyserver/caddy
Caddy vulnerable to Authentication Bypass due to mishandling of TLS client authentication
github.com/caddyserver/caddy
Caddy vulnerable to Authentication Bypass due to mishandling of TLS client authentication
phpmailer/phpmailer
PHPMailer vulnerable to email header injection
phpmailer/phpmailer
PHPMailer vulnerable to email header injection
codeigniter4/framework
Codeigniter4's Secure or HttpOnly flag set in Config\Cookie is not reflected in Cookies issued
codeigniter4/framework
Codeigniter4's Secure or HttpOnly flag set in Config\Cookie is not reflected in Cookies issued
github.com/sylabs/sif/v2
SIF's Digital Signature Hash Algorithms Not Validated
github.com/sylabs/sif/v2
SIF's Digital Signature Hash Algorithms Not Validated
kamadak-exif
kamadak-exif vulnerable to Infinite loop when parsing PNG files
kamadak-exif
kamadak-exif vulnerable to Infinite loop when parsing PNG files
