Open Source Vulnerabilities
org.dspace:dspace-jspui, org.dspace:dspace-jspui
JSPUI vulnerable to path traversal in submission (resumable) upload
org.dspace:dspace-jspui/ org.dspace:dspace-jspui
JSPUI vulnerable to path traversal in submission (resumable) upload
org.dspace:dspace-jspui, org.dspace:dspace-jspui
JSPUI's controlled vocabulary feature vulnerable to Open Redirect before v6.4 and v5.11
org.dspace:dspace-jspui/ org.dspace:dspace-jspui
JSPUI's controlled vocabulary feature vulnerable to Open Redirect before v6.4 and v5.11
org.dspace:dspace-jspui, org.dspace:dspace-jspui
JSPUI Possible Cross Site Scripting in "Request a Copy" Feature
org.dspace:dspace-jspui/ org.dspace:dspace-jspui
JSPUI Possible Cross Site Scripting in "Request a Copy" Feature
org.dspace:dspace-jspui, org.dspace:dspace-jspui
JSPUI spellcheck and autocomplete tools vulnerable to Cross Site Scripting
org.dspace:dspace-jspui/ org.dspace:dspace-jspui
JSPUI spellcheck and autocomplete tools vulnerable to Cross Site Scripting
org.dspace:dspace-xmlui
XMLUI's metadata of withdrawn Items is exposed to anonymous users
org.dspace:dspace-xmlui
XMLUI's metadata of withdrawn Items is exposed to anonymous users
org.dspace:dspace-jspui
JSPUI's "Internal System Error" page prints exceptions and stack traces without sanitization
org.dspace:dspace-jspui
JSPUI's "Internal System Error" page prints exceptions and stack traces without sanitization
@solana/pay
Solana Pay Vulnerable to Weakness in Transfer Validation Logic
@solana/pay
Solana Pay Vulnerable to Weakness in Transfer Validation Logic
drupal/core, drupal/core, drupal/core
Drupal core Information Disclosure vulnerability
drupal/core/ drupal/core/ drupal/core
Drupal core Information Disclosure vulnerability
untangle
untangle vulnerable to XML Entity Expansion
untangle
untangle vulnerable to Improper Restriction of XML External Entity Reference
untangle
untangle vulnerable to Improper Restriction of XML External Entity Reference
next-auth, next-auth
next-auth before v4.10.2 and v3.29.9 leaks excessive information into log
next-auth/ next-auth
next-auth before v4.10.2 and v3.29.9 leaks excessive information into log
sanic, sanic, sanic
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
sanic/ sanic/ sanic
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
fof/byobu
Byobu user preference to prevent private discussions being started are not respected
fof/byobu
Byobu user preference to prevent private discussions being started are not respected
websocket
Rust-WebSocket memory allocation based on untrusted length
websocket
Rust-WebSocket memory allocation based on untrusted length
rdkit
Heap-buffer-overflow in void RDKit::ParseV3000AtomProps<std::__1::vector<std::__1::basic_string_view<cha
rdkit
Heap-buffer-overflow in void RDKit::ParseV3000AtomProps<std::__1::vector<std::__1::basic_string_view<cha
@acrontum/filesystem-template
@acrontum/filesystem-template vulnerable to Command Injection due to fetchRepo API missing sanitization
@acrontum/filesystem-template
@acrontum/filesystem-template vulnerable to Command Injection due to fetchRepo API missing sanitization
administrate
administrate vulnerable to Cross-Site Request Forgery
administrate
administrate vulnerable to Cross-Site Request Forgery
moodle/moodle
Moodle XSS Vulnerability
io.undertow:undertow-core, io.undertow:undertow-core
Undertow vulnerable to Dos via Large AJP request
io.undertow:undertow-core/ io.undertow:undertow-core
Undertow vulnerable to Dos via Large AJP request
org.keycloak:keycloak-saml-core
Keycloak allows arbitrary Javascript to be uploaded for SAML protocol mapper even if UPLOAD_SCRIPTS feature disabled
org.keycloak:keycloak-saml-core
Keycloak allows arbitrary Javascript to be uploaded for SAML protocol mapper even if UPLOAD_SCRIPTS feature disabled
github.com/ethereum/go-ethereum
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
github.com/ethereum/go-ethereum
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
dav1d
Use-of-uninitialized-value in cdef_filter_block_c
