Open Source Vulnerabilities
shescape
Shescape prior to 1.5.8 vulnerable to insufficient escaping of line feeds for CMD
shescape
Shescape prior to 1.5.8 vulnerable to insufficient escaping of line feeds for CMD
wintercms/winter, wintercms/winter
Bypass of CMS Safe Mode Security Feature
wintercms/winter/ wintercms/winter
Bypass of CMS Safe Mode Security Feature
io.undertow:undertow-core
Undertow vulnerable to Denial of Service (DoS) attacks
io.undertow:undertow-core
Undertow vulnerable to Denial of Service (DoS) attacks
io.undertow:undertow-core, io.undertow:undertow-core
Undertow vulnerable to memory exhaustion due to buffer leak
io.undertow:undertow-core/ io.undertow:undertow-core
Undertow vulnerable to memory exhaustion due to buffer leak
packbackbooks/lti-1-3-php-library
LTI 1.3 Tool Library's Nonce Claim Value not validated against nonce value sent in Authentication Request before v5.0
packbackbooks/lti-1-3-php-library
LTI 1.3 Tool Library's Nonce Claim Value not validated against nonce value sent in Authentication Request before v5.0
packbackbooks/lti-1-3-php-library
LTI 1.3 Tool Library's function used to generate random nonces not sufficiently cryptographically complex before v5.0
packbackbooks/lti-1-3-php-library
LTI 1.3 Tool Library's function used to generate random nonces not sufficiently cryptographically complex before v5.0
org.togglz:togglz-console
Togglz console missing cross-site request forgery (CSRF) protection
org.togglz:togglz-console
Togglz console missing cross-site request forgery (CSRF) protection
com.amazonaws:aws-java-sdk-s3
Partial Path Traversal in com.amazonaws:aws-java-sdk-s3
com.amazonaws:aws-java-sdk-s3
Partial Path Traversal in com.amazonaws:aws-java-sdk-s3
node-terser, node-terser, node-terser
js-jquery
CVE-2022-25858 affecting package js-jquery 3.5.0-4
golang
CVE-2022-30634 affecting package golang 1.27.1-1
kured
CVE-2022-25891 affecting package kured for versions less than 1.13.2-1
kured
CVE-2022-25891 affecting package kured for versions less than 1.13.2-1
uglify-js
CVE-2022-25858 affecting package uglify-js for versions less than 3.19.3-11
uglify-js
CVE-2022-25858 affecting package uglify-js for versions less than 3.19.3-11
golang
CVE-2022-30634 affecting package golang 1.25.7-1
CVE-2022-30634 does not affect BellSoft software
angular.js, angular.js, angular.js, angular.js, angular.js, angular.js, angular.js
angular.js/ angular.js/ angular.js/ angular.js/ angular.js/ angular.js/ angular.js
node-terser, node-terser, qt6-webengine, node-terser, qt6-webengine, node-terser, qt6-webengine, node-terser, qt6-webengine
node-terser/ node-terser/ qt6-webengine/ node-terser/ qt6-webengine/ node-terser/ qt6-webengine/ node-terser/ qt6-webengine
Regular Expression Denial of Service (ReDoS)
com.fasterxml.jackson.core:jackson-databind
jackson-databind vulnerable to unsafe deserialization
com.fasterxml.jackson.core:jackson-databind
jackson-databind vulnerable to unsafe deserialization
Indefinite hang with large buffers on Windows in crypto/rand
oro/commerce
OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor
oro/commerce
OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor
fastify-bearer-auth, @fastify/bearer-auth, @fastify/bearer-auth
fastify-bearer-auth vulnerable to Timing Attack Vector
fastify-bearer-auth/ @fastify/bearer-auth/ @fastify/bearer-auth
fastify-bearer-auth vulnerable to Timing Attack Vector
openzeppelin-cairo-contracts
OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli
openzeppelin-cairo-contracts
OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli
org.jvnet.hudson.main:hudson-core
Hudson XML API susceptible to External Entity Injection Vunerability prior to v3.3.2
org.jvnet.hudson.main:hudson-core
Hudson XML API susceptible to External Entity Injection Vunerability prior to v3.3.2
github.com/flyteorg/flyteadmin
FlyteAdmin Insufficient AccessToken Expiration Check
github.com/flyteorg/flyteadmin
FlyteAdmin Insufficient AccessToken Expiration Check
OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli
OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli
Partial Path Traversal in com.amazonaws:aws-java-sdk-s3
Use of a Broken or Risky Cryptographic Algorithm in packbackbooks/lti-1-3-php-library
Use of a Broken or Risky Cryptographic Algorithm in packbackbooks/lti-1-3-php-library
Authentication Bypass by Capture-replay in packbackbooks/lti-1-3-php-library
Authentication Bypass by Capture-replay in packbackbooks/lti-1-3-php-library
