Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CVE-2022-38405
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-38404
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-38403
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-38402
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-38401
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-35713
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-35664
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-34218
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-30686
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-30685
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-30684
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-30683
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-30682
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-30681
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-30680
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-30678
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-30677
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-30676
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-30675
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-30674
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-30673
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-30672
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-30671
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-28857
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-28856
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-28855
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-28854
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-28853
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-28852
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2021-46836
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2021-40024
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2021-40023
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2021-40019
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2021-40017
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2020-36601
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2020-36600
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    CVE-2022-39063
    No fix available
    Packages

    Summary

    Published
    16 Sept 2022
    GHSA-r9x7-2xmr-v8fw
    Fix available
    Packages

    mangadex-downloader

    Summary

    mangadex-downloader vulnerable to unauthorized file reading

    Published
    16 Sept 2022
    GHSA-jv3g-j58f-9mq9
    Fix available
    Packages

    jose, jose-browser-runtime, jose-node-cjs-runtime, jose-node-esm-runtime, jose, jose, jose, jose-browser-runtime, jose-node-cjs-runtime, jose-node-esm-runtime

    Summary

    JOSE vulnerable to resource exhaustion via specifically crafted JWE

    Published
    16 Sept 2022
    GHSA-qm4w-4995-vg7f
    Fix available
    Packages

    cruddl, cruddl

    Summary

    cruddl vulnerable to ArangoDB Query Language (AQL) injection through flexSearch

    Published
    16 Sept 2022
    GHSA-f524-rf33-2jjr
    Fix available
    Packages

    github.com/open-policy-agent/opa

    Summary

    OPA Compiler: Bypass of WithUnsafeBuiltins using "with" keyword to mock functions

    Published
    16 Sept 2022
    GHSA-xg8p-34w2-j49j
    Fix available
    Packages

    linked_list_allocator

    Summary

    linked_list_allocator vulnerable to out-of-bound writes on `Heap` initialization and `Heap::extend`

    Published
    16 Sept 2022
    GHSA-jgc8-gvcx-9vfx
    Fix available
    Packages

    org.xwiki.platform:xwiki-platform-oldcore, org.xwiki.platform:xwiki-platform-oldcore

    Summary

    XWiki Platform Improper Authorization check for inactive users

    Published
    16 Sept 2022
    GHSA-599v-w48h-rjrm
    Fix available
    Packages

    org.xwiki.platform:xwiki-platform-web-templates, org.xwiki.platform:xwiki-platform-web

    Summary

    XWiki Platform Web Templates vulnerable to Missing Authorization, Exposure of Private Personal Information to Unauthorized Actor

    Published
    16 Sept 2022
    GHSA-gjmq-x5x7-wc36
    Fix available
    Packages

    org.xwiki.platform:xwiki-platform-index-ui, org.xwiki.platform:xwiki-platform-index-ui

    Summary

    XWiki Platform vulnerable to Cross-site Scripting in the deleted attachments list

    Published
    16 Sept 2022
    GHSA-9r9j-57rf-f6vj
    Fix available
    Packages

    org.xwiki.platform:xwiki-platform-attachment-ui

    Summary

    XWiki Platform Attachment UI vulnerable to cross-site scripting in the move attachment form

    Published
    16 Sept 2022
    GHSA-c5v8-2q4r-5w9v
    Fix available
    Packages

    org.xwiki.platform:xwiki-platform-mentions-ui, org.xwiki.platform:xwiki-platform-mentions-ui

    Summary

    XWiki Platform Mentions UI vulnerable to Cross-site Scripting

    Published
    16 Sept 2022
    GHSA-xr6m-2p4m-jvqf
    Fix available
    Packages

    org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki, org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki

    Summary

    XWiki Platform Wiki UI Main Wiki Eval Injection vulnerability

    Published
    16 Sept 2022
    GHSA-2g5c-228j-p52x
    Fix available
    Packages

    org.xwiki.platform:xwiki-platform-tag-ui, org.xwiki.platform.applications:xwiki-application-tag, org.xwiki.platform:xwiki-platform-tag-ui

    Summary

    XWiki Platform Applications Tag and XWiki Platform Tag UI vulnerable to Eval Injection

    Published
    16 Sept 2022
    GHSA-7hgc-php5-77qq
    Fix available
    Packages

    github.com/talos-systems/talos

    Summary

    Talos worker join token can be used to get elevated access level to the Talos API

    Published
    16 Sept 2022