Open Source Vulnerabilities
motoradmin - host header Injection in the reset password functionality
motoradmin - host header Injection in the reset password functionality
salt, salt
Security update for salt
vim, vim-athena, vim-athena-py2, vim-common, vim-doc, vim-gnome, vim-gnome-py2, vim-gtk, vim-gtk-py2, vim-gtk3, vim-gtk3-py2, vim-gui-common, vim-nox, vim-nox-py2, vim-runtime, vim-tiny
Fix CVE(s): CVE-2022-2042
vim/ vim-athena/ vim-athena-py2/ vim-common/ vim-doc/ vim-gnome/ vim-gnome-py2/ vim-gtk/ vim-gtk-py2/ vim-gtk3/ vim-gtk3-py2/ vim-gui-common/ vim-nox/ vim-nox-py2/ vim-runtime/ vim-tiny
Fix CVE(s): CVE-2022-2042
vim-X11, vim-common, vim-enhanced, vim-filesystem, vim-minimal
Fixed CVE-2022-2042 in vim
vim-X11/ vim-common/ vim-enhanced/ vim-filesystem/ vim-minimal
Fixed CVE-2022-2042 in vim
vim-X11, vim-common, vim-enhanced, vim-filesystem, vim-minimal
Fixed CVE-2022-2042 in vim
vim-X11/ vim-common/ vim-enhanced/ vim-filesystem/ vim-minimal
Fixed CVE-2022-2042 in vim
Cross-site Scripting (XSS) - Reflected in microweber/microweber
Cross-site Scripting (XSS) - Reflected in microweber/microweber
Habitica - Open redirect in login page
httpd, mod_http2, mod_md, mod_md
Low: httpd:2.4 security update
httpd/ mod_http2/ mod_md/ mod_md
Low: httpd:2.4 security update
ERPNext - Stored XSS leads to account takover
fwupdate
Security update for fwupdate
fwupdate, fwupdate, fwupdate, fwupdate, fwupdate, fwupdate, fwupdate, fwupdate, fwupdate, fwupdate, fwupdate, fwupdate
Security update for fwupdate
fwupdate/ fwupdate/ fwupdate/ fwupdate/ fwupdate/ fwupdate/ fwupdate/ fwupdate/ fwupdate/ fwupdate/ fwupdate/ fwupdate
Security update for fwupdate
libucl
Heap-buffer-overflow in ucl_hash_search
nukeviet/nukeviet
Cross-site Scripting in NukeViet CMS
org.springframework.cloud:spring-cloud-function-parent
Denial of Service in Spring Cloud Function
org.springframework.cloud:spring-cloud-function-parent
Denial of Service in Spring Cloud Function
krayin/laravel-crm
Cross-site Scripting in krayin/laravel-crm
krayin/laravel-crm
Cross-site Scripting in krayin/laravel-crm
firejail, firejail
firejail - security update
github.com/argoproj/argo-cd, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd/v2
DoS through large manifest files in Argo CD
github.com/argoproj/argo-cd/ github.com/argoproj/argo-cd/v2/ github.com/argoproj/argo-cd/v2/ github.com/argoproj/argo-cd/v2/ github.com/argoproj/argo-cd/v2
DoS through large manifest files in Argo CD
log4j, log4j-javadoc, log4j-manual
Fixed CVE-2019-17571 in log4j
log4j/ log4j-javadoc/ log4j-manual
Fixed CVE-2019-17571 in log4j
log4j, log4j-javadoc, log4j-manual
Fixed CVE-2019-17571 in log4j
log4j/ log4j-javadoc/ log4j-manual
Fixed CVE-2019-17571 in log4j
rulex
Reachable Assertion in rulex
guzzlehttp/guzzle, guzzlehttp/guzzle
Change in port should be considered a change in origin
guzzlehttp/guzzle/ guzzlehttp/guzzle
Change in port should be considered a change in origin
next-auth, next-auth
Improper Handling of `callbackUrl` parameter in next-auth
next-auth/ next-auth
Improper Handling of `callbackUrl` parameter in next-auth
github.com/argoproj/argo-cd, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd/v2
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server
github.com/argoproj/argo-cd/ github.com/argoproj/argo-cd/v2/ github.com/argoproj/argo-cd/v2/ github.com/argoproj/argo-cd/v2/ github.com/argoproj/argo-cd/v2
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server
github.com/argoproj/argo-cd, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd/v2
Argo CD's external URLs for Deployments can include JavaScript
github.com/argoproj/argo-cd/ github.com/argoproj/argo-cd/v2/ github.com/argoproj/argo-cd/v2/ github.com/argoproj/argo-cd/v2/ github.com/argoproj/argo-cd/v2
Argo CD's external URLs for Deployments can include JavaScript
github.com/argoproj/argo-cd, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd/v2
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params
github.com/argoproj/argo-cd/ github.com/argoproj/argo-cd/v2/ github.com/argoproj/argo-cd/v2/ github.com/argoproj/argo-cd/v2/ github.com/argoproj/argo-cd/v2
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params
cups, cups-client, cups-devel, cups-filesystem, cups-ipptool, cups-libs, cups-lpd
Fixed CVE-2022-26691 in cups
cups/ cups-client/ cups-devel/ cups-filesystem/ cups-ipptool/ cups-libs/ cups-lpd
Fixed CVE-2022-26691 in cups
cups, cups-client, cups-devel, cups-filesystem, cups-ipptool, cups-libs, cups-lpd
Fixed CVE-2022-26691 in cups
cups/ cups-client/ cups-devel/ cups-filesystem/ cups-ipptool/ cups-libs/ cups-lpd
Fixed CVE-2022-26691 in cups
Exposure of Sensitive Information in discourse-chat
guzzlehttp/guzzle, guzzlehttp/guzzle
CURLOPT_HTTPAUTH option not cleared on change of origin
guzzlehttp/guzzle/ guzzlehttp/guzzle
CURLOPT_HTTPAUTH option not cleared on change of origin
