Open Source Vulnerabilities
Cross-site Scripting (XSS) - Stored in pimcore/pimcore
libgit2, libgit2
Security update for libgit2
kernel-azure, kernel-source-azure, kernel-syms-azure, kernel-azure, kernel-source-azure, kernel-syms-azure
Security update for the Linux Kernel
kernel-azure/ kernel-source-azure/ kernel-syms-azure/ kernel-azure/ kernel-source-azure/ kernel-syms-azure
Security update for the Linux Kernel
MozillaThunderbird, MozillaThunderbird, MozillaThunderbird, MozillaThunderbird, MozillaThunderbird, MozillaThunderbird
Security update for MozillaThunderbird
MozillaThunderbird/ MozillaThunderbird/ MozillaThunderbird/ MozillaThunderbird/ MozillaThunderbird/ MozillaThunderbird
Security update for MozillaThunderbird
opera
Security update for opera
Misinterpretation of Input in ionicabizau/parse-url
gpac, gpac, gpac, gpac, gpac, gpac
Cross-Site Request Forgery (CSRF) in ikus060/rdiffweb
libzip, libzip, php, php-pear, php-pear, php-pecl-apcu, php-pecl-apcu, php-pecl-rrd, php-pecl-xdebug, php-pecl-zip, php-pecl-zip
Moderate: php:7.4 security update
libzip/ libzip/ php/ php-pear/ php-pear/ php-pecl-apcu/ php-pecl-apcu/ php-pecl-rrd/ php-pecl-xdebug/ php-pecl-zip/ php-pecl-zip
Moderate: php:7.4 security update
webkit2gtk3
Moderate: webkit2gtk3 security update
dotnet6.0
Moderate: .NET 6.0 security and bugfix update
kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive
kodi-inputstream-adaptive/ kodi-inputstream-adaptive/ kodi-inputstream-adaptive/ kodi-inputstream-adaptive
kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive
kodi-inputstream-adaptive/ kodi-inputstream-adaptive/ kodi-inputstream-adaptive/ kodi-inputstream-adaptive
kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive
kodi-inputstream-adaptive/ kodi-inputstream-adaptive/ kodi-inputstream-adaptive/ kodi-inputstream-adaptive
python-aiohttp, python-typing_extensions, python-aiohttp, python-typing_extensions, python-aiohttp, python-typing_extensions, python-aiohttp, python-typing_extensions, python-aiohttp, python-aiohttp, python-typing_extensions
Recommended update for python-aiohttp, python-typing_extensions
python-aiohttp/ python-typing_extensions/ python-aiohttp/ python-typing_extensions/ python-aiohttp/ python-typing_extensions/ python-aiohttp/ python-typing_extensions/ python-aiohttp/ python-aiohttp/ python-typing_extensions
Recommended update for python-aiohttp, python-typing_extensions
org.eclipse.milo:sdk-server
Eclipse Milo vulnerable to Resource Exhaustion (Denial of Service)
org.eclipse.milo:sdk-server
Eclipse Milo vulnerable to Resource Exhaustion (Denial of Service)
tuf
Python-TUF vulnerable to incorrect threshold signature computation for new root metadata
tuf
Python-TUF vulnerable to incorrect threshold signature computation for new root metadata
github.com/gravitl/netmaker
Netmaker vulnerable to Insufficient Granularity of Access Control
github.com/gravitl/netmaker
Netmaker vulnerable to Insufficient Granularity of Access Control
github.com/matrix-org/dendrite
Dendrite signature checks not applied to some retrieved missing events
github.com/matrix-org/dendrite
Dendrite signature checks not applied to some retrieved missing events
typo3/cms-core, typo3/cms-core, typo3/cms-core, typo3/cms-core, typo3/cms-core
TYPO3 HTML Sanitizer Bypasses Cross-Site Scripting Protection
typo3/cms-core/ typo3/cms-core/ typo3/cms-core/ typo3/cms-core/ typo3/cms-core
TYPO3 HTML Sanitizer Bypasses Cross-Site Scripting Protection
matrix-appservice-irc
matrix-appservice-irc vulnerable to IRC mode parameter confusion
matrix-appservice-irc
matrix-appservice-irc vulnerable to IRC mode parameter confusion
matrix-appservice-irc
Parsing issue in matrix-org/node-irc leading to room takeovers
matrix-appservice-irc
Parsing issue in matrix-org/node-irc leading to room takeovers
Microsoft.AspNetCore.App.Runtime.linux-arm, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-x64, Microsoft.AspNetCore.App.Runtime.linux-x64, Microsoft.AspNetCore.App.Runtime.osx-x64, Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.win-arm64, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-x86, Microsoft.AspNetCore.App.Runtime.linux-arm, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-arm, Microsoft.AspNetCore.App.Runtime.linux-musl-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-x64, Microsoft.AspNetCore.App.Runtime.linux-x64, Microsoft.AspNetCore.App.Runtime.osx-arm64, Microsoft.AspNetCore.App.Runtime.osx-x64, Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.win-arm64, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-x86
.NET Denial of Service Vulnerability
Microsoft.AspNetCore.App.Runtime.linux-arm/ Microsoft.AspNetCore.App.Runtime.linux-arm64/ Microsoft.AspNetCore.App.Runtime.linux-musl-arm64/ Microsoft.AspNetCore.App.Runtime.linux-musl-x64/ Microsoft.AspNetCore.App.Runtime.linux-x64/ Microsoft.AspNetCore.App.Runtime.osx-x64/ Microsoft.AspNetCore.App.Runtime.win-arm/ Microsoft.AspNetCore.App.Runtime.win-arm64/ Microsoft.AspNetCore.App.Runtime.win-x64/ Microsoft.AspNetCore.App.Runtime.win-x86/ Microsoft.AspNetCore.App.Runtime.linux-arm/ Microsoft.AspNetCore.App.Runtime.linux-arm64/ Microsoft.AspNetCore.App.Runtime.linux-musl-arm/ Microsoft.AspNetCore.App.Runtime.linux-musl-arm64/ Microsoft.AspNetCore.App.Runtime.linux-musl-x64/ Microsoft.AspNetCore.App.Runtime.linux-x64/ Microsoft.AspNetCore.App.Runtime.osx-arm64/ Microsoft.AspNetCore.App.Runtime.osx-x64/ Microsoft.AspNetCore.App.Runtime.win-arm/ Microsoft.AspNetCore.App.Runtime.win-arm64/ Microsoft.AspNetCore.App.Runtime.win-x64/ Microsoft.AspNetCore.App.Runtime.win-x86
.NET Denial of Service Vulnerability
axum-core, axum-core
axum-core has no default limit put on request bodies
axum-core/ axum-core
axum-core has no default limit put on request bodies
pageflow, pageflow
Pageflow vulnerable to insecure direct object reference in membership update endpoint
pageflow/ pageflow
Pageflow vulnerable to insecure direct object reference in membership update endpoint
pageflow, pageflow
Pageflow vulnerable to sensitive user data extraction via Ransack query injection
pageflow/ pageflow
Pageflow vulnerable to sensitive user data extraction via Ransack query injection
kubevirt.io/kubevirt
KubeVirt vulnerable to arbitrary file read on host
kubevirt.io/kubevirt
KubeVirt vulnerable to arbitrary file read on host
intel-microcode, intel-microcode, intel-microcode
intel-microcode vulnerability
intel-microcode/ intel-microcode/ intel-microcode
intel-microcode vulnerability
smarty3, smarty3, smarty3, smarty4, smarty4, smarty4
smarty3, smarty3, smarty3, smarty3, smarty3, smarty3, smarty3
smarty3/ smarty3/ smarty3/ smarty3/ smarty3/ smarty3/ smarty3
libsass
Segv on unknown address in Sass::unifyComplex
parse-url
Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url
parse-url
Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url
