Open Source Vulnerabilities
@next-auth/upstash-redis-adapter
Upstash Adapter missing token verification
@next-auth/upstash-redis-adapter
Upstash Adapter missing token verification
twig/twig, twig/twig, twig/twig
Twig may load a template outside a configured directory when using the filesystem loader
twig/twig/ twig/twig/ twig/twig
Twig may load a template outside a configured directory when using the filesystem loader
node-css-what, node-css-what, node-css-what
node-css-what, node-css-what, node-css-what, node-css-what, node-css-what, node-css-what
node-css-what/ node-css-what/ node-css-what/ node-css-what/ node-css-what/ node-css-what
kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive
kodi-inputstream-adaptive/ kodi-inputstream-adaptive/ kodi-inputstream-adaptive/ kodi-inputstream-adaptive
ipe, ipe, ipe, ipe, ipe, ipe, ipe
ipe, ipe, ipe, ipe, ipe, ipe, ipe
ipe, ipe, ipe, ipe, ipe, ipe, ipe
kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive
kodi-inputstream-adaptive/ kodi-inputstream-adaptive/ kodi-inputstream-adaptive/ kodi-inputstream-adaptive
kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive
kodi-inputstream-adaptive/ kodi-inputstream-adaptive/ kodi-inputstream-adaptive/ kodi-inputstream-adaptive
kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive
kodi-inputstream-adaptive/ kodi-inputstream-adaptive/ kodi-inputstream-adaptive/ kodi-inputstream-adaptive
Regular Expression Denial of Service (ReDoS)
Regular Expression Denial of Service (ReDoS)
CompositeC1.Core
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
CompositeC1.Core
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
com.wire:lithium, com.wire.bots:lithium
Lithium vulnerable to Cross Site Scripting in provided Swagger-UI
com.wire:lithium/ com.wire.bots:lithium
Lithium vulnerable to Cross Site Scripting in provided Swagger-UI
org.matrix.android:matrix-android-sdk2
matrix-android-sdk2 vulnerable to Olm/Megolm protocol confusion
org.matrix.android:matrix-android-sdk2
matrix-android-sdk2 vulnerable to Olm/Megolm protocol confusion
org.matrix.android:matrix-android-sdk2
matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions
org.matrix.android:matrix-android-sdk2
matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions
com.zaxxer:nuprocess
NuProcess vulnerable to command-line injection through insertion of NUL character(s)
com.zaxxer:nuprocess
NuProcess vulnerable to command-line injection through insertion of NUL character(s)
matrix-js-sdk
matrix-js-sdk subject to user spoofing via Olm/Megolm protocol confusion
matrix-js-sdk
matrix-js-sdk subject to user spoofing via Olm/Megolm protocol confusion
matrix-js-sdk
matrix-js-sdk subject to impersonated messages due to permissive key forwarding
matrix-js-sdk
matrix-js-sdk subject to impersonated messages due to permissive key forwarding
kimageformats
Index-out-of-bounds in LibRaw::ahd_interpolate_r_and_b_in_rgb_and_convert_to_cielab
kimageformats
Index-out-of-bounds in LibRaw::ahd_interpolate_r_and_b_in_rgb_and_convert_to_cielab
upb
Segv on unknown address in upb_MiniTable_SetSubEnum
skia
Heap-buffer-overflow in SkRect::setBoundsCheck
rdiffweb
rdiffweb vulnerable to password complexity bypass leading to weak passwords
rdiffweb
rdiffweb vulnerable to password complexity bypass leading to weak passwords
inventree
Inventree vulnerable to Stored Cross-site Scripting
inventree
Inventree vulnerable to Stored Cross-site Scripting
feehi/feehicms
FeehiCMS vulnerable to Cross-Site scripting via crafted payload
feehi/feehicms
FeehiCMS vulnerable to Cross-Site scripting via crafted payload
github.com/dutchcoders/transfer.sh
Dutchoders transfer.sh contains an XSS vulnerability via malicious file upload
github.com/dutchcoders/transfer.sh
Dutchoders transfer.sh contains an XSS vulnerability via malicious file upload
exiv2
Heap-buffer-overflow in std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<ch
exiv2
Heap-buffer-overflow in std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<ch
moodle/moodle, moodle/moodle, moodle/moodle
Moodle type juggling vulnerability
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle type juggling vulnerability
moodle/moodle, moodle/moodle, moodle/moodle
Moodle Improper Authentication
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle Improper Authentication
moodle/moodle, moodle/moodle, moodle/moodle
Moodle Incorrect Authorization
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle Incorrect Authorization
moodle/moodle, moodle/moodle, moodle/moodle
Moodle Exposure of Sensitive Information to an Unauthorized Actor
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle Exposure of Sensitive Information to an Unauthorized Actor
moodle/moodle, moodle/moodle, moodle/moodle
Moodle Improper Encoding or Escaping of Output
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle Improper Encoding or Escaping of Output
com.amazon.redshift:redshift-jdbc42
Duplicate Advisory: AWS Redshift JDBC Driver fails to validate class type during object instantiation
com.amazon.redshift:redshift-jdbc42
Duplicate Advisory: AWS Redshift JDBC Driver fails to validate class type during object instantiation
rdiffweb
rdiffweb's unlimited length Fullname field can lead to DoS
rdiffweb
rdiffweb's unlimited length Fullname field can lead to DoS
mariadb-10.3
mariadb-10.3 - regression update
libvncserver
libvncserver - security update
libhttp-daemon-perl
libhttp-daemon-perl - security update
Exchange Server
unknown in Exchange Server version Exchange Server 2019
Exchange Server
unknown in Exchange Server version Exchange Server 2019
Exchange Server
unknown in Exchange Server version Exchange Server 2019
Exchange Server
unknown in Exchange Server version Exchange Server 2019
