Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-jjc5-fp7p-6f8w
    Fix available
    Packages

    shescape

    Summary

    Shescape prior to 1.5.8 vulnerable to insufficient escaping of line feeds for CMD

    Published
    15 Jul 2022
    GHSA-q37h-jhf3-85cj
    Fix available
    Packages

    wintercms/winter, wintercms/winter

    Summary

    Bypass of CMS Safe Mode Security Feature

    Published
    15 Jul 2022
    GHSA-339q-62wm-c39w
    Fix available
    Packages

    io.undertow:undertow-core

    Summary

    Undertow vulnerable to Denial of Service (DoS) attacks

    Published
    15 Jul 2022
    CVE-2022-35890
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022
    CVE-2022-32434
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022
    GHSA-fj7c-vg2v-ccrm
    Fix available
    Packages

    io.undertow:undertow-core, io.undertow:undertow-core

    Summary

    Undertow vulnerable to memory exhaustion due to buffer leak

    Published
    15 Jul 2022
    GHSA-5p73-qg2v-383h
    Fix available
    Packages

    packbackbooks/lti-1-3-php-library

    Summary

    LTI 1.3 Tool Library's Nonce Claim Value not validated against nonce value sent in Authentication Request before v5.0

    Published
    15 Jul 2022
    GHSA-768m-5w34-2xf5
    Fix available
    Packages

    packbackbooks/lti-1-3-php-library

    Summary

    LTI 1.3 Tool Library's function used to generate random nonces not sufficiently cryptographically complex before v5.0

    Published
    15 Jul 2022
    GHSA-697v-pxg3-j262
    Fix available
    Packages

    org.togglz:togglz-console

    Summary

    Togglz console missing cross-site request forgery (CSRF) protection

    Published
    15 Jul 2022
    GHSA-c28r-hw5m-5gv3
    Fix available
    Packages

    com.amazonaws:aws-java-sdk-s3

    Summary

    Partial Path Traversal in com.amazonaws:aws-java-sdk-s3

    Published
    15 Jul 2022
    CVE-2022-25869
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022
    DEBIAN-CVE-2022-25869
    No fix available
    Packages

    angular.js, angular.js

    Summary

    Published
    15 Jul 2022
    Packages

    node-terser, node-terser, node-terser

    Summary

    Published
    15 Jul 2022
    AZL-44553
    No fix available
    Packages

    js-jquery

    Summary

    CVE-2022-25858 affecting package js-jquery 3.5.0-4

    Published
    15 Jul 2022
    AZL-98796
    No fix available
    Packages

    golang

    Summary

    CVE-2022-30634 affecting package golang 1.27.1-1

    Published
    15 Jul 2022
    AZL-31969
    Fix available
    Packages

    kured

    Summary

    CVE-2022-25891 affecting package kured for versions less than 1.13.2-1

    Published
    15 Jul 2022
    AZL-44460
    Fix available
    Packages

    uglify-js

    Summary

    CVE-2022-25858 affecting package uglify-js for versions less than 3.19.3-11

    Published
    15 Jul 2022
    AZL-78962
    No fix available
    Packages

    golang

    Summary

    CVE-2022-30634 affecting package golang 1.25.7-1

    Published
    15 Jul 2022
    BELL-CVE-2022-30634
    No fix available
    Packages

    Summary

    CVE-2022-30634 does not affect BellSoft software

    Published
    15 Jul 2022
    UBUNTU-CVE-2022-30634
    No fix available
    Packages

    golang-1.8, golang-1.17

    Summary

    Published
    15 Jul 2022
    UBUNTU-CVE-2022-25869
    No fix available
    Packages

    angular.js, angular.js, angular.js, angular.js, angular.js, angular.js, angular.js

    Summary

    Published
    15 Jul 2022
    UBUNTU-CVE-2022-25858
    No fix available
    Packages

    node-terser, node-terser, qt6-webengine, node-terser, qt6-webengine, node-terser, qt6-webengine, node-terser, qt6-webengine

    Summary

    Published
    15 Jul 2022
    CVE-2022-25891
    Fix available
    Packages

    Summary

    Denial of Service (DoS)

    Published
    15 Jul 2022
    CVE-2022-25858
    Fix available
    Packages

    Summary

    Regular Expression Denial of Service (ReDoS)

    Published
    15 Jul 2022
    GHSA-rpr3-cw39-3pxh
    Fix available
    Packages

    com.fasterxml.jackson.core:jackson-databind

    Summary

    jackson-databind vulnerable to unsafe deserialization

    Published
    15 Jul 2022
    CVE-2022-30634
    Fix available
    Packages

    Summary

    Indefinite hang with large buffers on Windows in crypto/rand

    Published
    15 Jul 2022
    GHSA-6f85-3f8q-qc94
    Fix available
    Packages

    oro/commerce

    Summary

    OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor

    Published
    15 Jul 2022
    CVE-2021-34987
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022
    CVE-2021-34986
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022
    GHSA-376v-xgjx-7mfr
    Fix available
    Packages

    fastify-bearer-auth, @fastify/bearer-auth, @fastify/bearer-auth

    Summary

    fastify-bearer-auth vulnerable to Timing Attack Vector

    Published
    15 Jul 2022
    GHSA-8mjr-jr5h-q2xr
    Fix available
    Packages

    openzeppelin-cairo-contracts

    Summary

    OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli

    Published
    15 Jul 2022
    PYSEC-2022-43143
    Fix available
    Packages

    openzeppelin-cairo-contracts-test

    Summary

    Published
    15 Jul 2022
    GHSA-j3h2-8mf8-j5r2
    Fix available
    Packages

    org.jvnet.hudson.main:hudson-core

    Summary

    Hudson XML API susceptible to External Entity Injection Vunerability prior to v3.3.2

    Published
    15 Jul 2022
    GHSA-qwrj-9hmp-gpxh
    Fix available
    Packages

    github.com/flyteorg/flyteadmin

    Summary

    FlyteAdmin Insufficient AccessToken Expiration Check

    Published
    15 Jul 2022
    CVE-2022-31153
    Fix available
    Packages

    Summary

    OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli

    Published
    15 Jul 2022
    CVE-2022-31159
    No fix available
    Packages

    Summary

    Partial Path Traversal in com.amazonaws:aws-java-sdk-s3

    Published
    15 Jul 2022
    CVE-2022-31157
    Fix available
    Packages

    Summary

    Use of a Broken or Risky Cryptographic Algorithm in packbackbooks/lti-1-3-php-library

    Published
    15 Jul 2022
    CVE-2022-31158
    Fix available
    Packages

    Summary

    Authentication Bypass by Capture-replay in packbackbooks/lti-1-3-php-library

    Published
    15 Jul 2022
    CVE-2022-34252
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022
    CVE-2022-34251
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022
    CVE-2022-34250
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022
    CVE-2022-34249
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022
    CVE-2022-34248
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022
    CVE-2022-34247
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022
    CVE-2022-34246
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022
    CVE-2022-34245
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022
    CVE-2022-34244
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022
    CVE-2022-34243
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022
    CVE-2022-34242
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022
    CVE-2022-34241
    No fix available
    Packages

    Summary

    Published
    15 Jul 2022