Open Source Vulnerabilities
ompl, ompl, ompl, ompl, ompl, ompl, ompl
python-bottle, python-bottle, python-bottle
python-bottle security update
python-bottle/ python-bottle/ python-bottle
python-bottle security update
grafana, grafana, grafana
grafana security update
python-jwt, python-jwt, python-jwt
python-jwt security update
libinput, libinput, libinput
libinput security update
Cross-site Scripting (XSS) - Stored in inventree/inventree
Improper Neutralization of Formula Elements in a CSV File in inventree/inventree
Improper Neutralization of Formula Elements in a CSV File in inventree/inventree
Unrestricted Upload of File with Dangerous Type in inventree/inventree
Unrestricted Upload of File with Dangerous Type in inventree/inventree
kernel-default, kernel-livepatch-SLE15-SP1_Update_31, kernel-default, kernel-default, kernel-docs, kernel-obs-build, kernel-source, kernel-syms, kernel-default, kernel-docs, kernel-obs-build, kernel-source, kernel-syms, kernel-default, kernel-docs, kernel-obs-build, kernel-source, kernel-syms, kernel-default, kernel-docs, kernel-obs-build, kernel-source, kernel-syms, kernel-zfcpdump, kernel-default, kernel-docs, kernel-obs-build, kernel-source, kernel-syms, kernel-default, kernel-docs, kernel-obs-build, kernel-source, kernel-syms, kernel-debug, kernel-default, kernel-kvmsmall, kernel-vanilla, kernel-zfcpdump, kernel-debug, kernel-default, kernel-kvmsmall, kernel-vanilla, kernel-zfcpdump
Security update for the Linux Kernel
kernel-default/ kernel-livepatch-SLE15-SP1_Update_31/ kernel-default/ kernel-default/ kernel-docs/ kernel-obs-build/ kernel-source/ kernel-syms/ kernel-default/ kernel-docs/ kernel-obs-build/ kernel-source/ kernel-syms/ kernel-default/ kernel-docs/ kernel-obs-build/ kernel-source/ kernel-syms/ kernel-default/ kernel-docs/ kernel-obs-build/ kernel-source/ kernel-syms/ kernel-zfcpdump/ kernel-default/ kernel-docs/ kernel-obs-build/ kernel-source/ kernel-syms/ kernel-default/ kernel-docs/ kernel-obs-build/ kernel-source/ kernel-syms/ kernel-debug/ kernel-default/ kernel-kvmsmall/ kernel-vanilla/ kernel-zfcpdump/ kernel-debug/ kernel-default/ kernel-kvmsmall/ kernel-vanilla/ kernel-zfcpdump
Security update for the Linux Kernel
linux-azure, linux-aws-hwe, linux-azure, linux-gcp, linux-hwe, linux-oracle, linux, linux-aws, linux-aws-5.4, linux-azure-4.15, linux-azure-5.4, linux-dell300x, linux-gcp-4.15, linux-gcp-5.4, linux-gke-5.4, linux-gkeop-5.4, linux-hwe-5.4, linux-ibm-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux, linux-aws, linux-aws-5.13, linux-azure, linux-azure-5.13, linux-azure-fde, linux-gcp, linux-gcp-5.13, linux-gke, linux-gkeop, linux-hwe-5.13, linux-ibm, linux-intel-5.13, linux-kvm, linux-oracle, linux-oracle-5.13, linux, linux-aws, linux-azure, linux-gcp, linux-gke, linux-ibm, linux-intel-iotg, linux-kvm, linux-lowlatency, linux-oracle
linux, linux-aws, linux-aws-hwe, linux-aws-5.13, linux-aws-5.4, linux-azure, linux-azure-4.15, linux-azure-5.13, linux-azure-5.4, linux-azure-fde, linux-dell300x, linux-gcp, linux-gcp-4.15, linux-gcp-5.13, linux-gcp-5.4, linux-gke, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe, linux-hwe-5.13, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-intel-5.13, linux-intel-iotg, linux-kvm, linux-lowlatency, linux-oracle, linux-oracle-5.13, linux-oracle-5.4 vulnerabilities
linux-azure/ linux-aws-hwe/ linux-azure/ linux-gcp/ linux-hwe/ linux-oracle/ linux/ linux-aws/ linux-aws-5.4/ linux-azure-4.15/ linux-azure-5.4/ linux-dell300x/ linux-gcp-4.15/ linux-gcp-5.4/ linux-gke-5.4/ linux-gkeop-5.4/ linux-hwe-5.4/ linux-ibm-5.4/ linux-kvm/ linux-oracle/ linux-oracle-5.4/ linux/ linux-aws/ linux-aws-5.13/ linux-azure/ linux-azure-5.13/ linux-azure-fde/ linux-gcp/ linux-gcp-5.13/ linux-gke/ linux-gkeop/ linux-hwe-5.13/ linux-ibm/ linux-intel-5.13/ linux-kvm/ linux-oracle/ linux-oracle-5.13/ linux/ linux-aws/ linux-azure/ linux-gcp/ linux-gke/ linux-ibm/ linux-intel-iotg/ linux-kvm/ linux-lowlatency/ linux-oracle
linux, linux-aws, linux-aws-hwe, linux-aws-5.13, linux-aws-5.4, linux-azure, linux-azure-4.15, linux-azure-5.13, linux-azure-5.4, linux-azure-fde, linux-dell300x, linux-gcp, linux-gcp-4.15, linux-gcp-5.13, linux-gcp-5.4, linux-gke, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe, linux-hwe-5.13, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-intel-5.13, linux-intel-iotg, linux-kvm, linux-lowlatency, linux-oracle, linux-oracle-5.13, linux-oracle-5.4 vulnerabilities
tss-esapi, tss-esapi
Use After Free in Context::start_auth_session
tss-esapi/ tss-esapi
Use After Free in Context::start_auth_session
inventree
Formula Injection in Exported Data
inventree
Unrestricted Attachment Upload
inventree
Insufficient HTML Sanitization
ghost, ghost
Ghost vulnerable to remote code execution in locale setting change
ghost/ ghost
Ghost vulnerable to remote code execution in locale setting change
github.com/edgexfoundry/device-sdk-go/v2, github.com/edgexfoundry/app-functions-sdk-go/v2
Configuration API in EdgeXFoundry 2.1.0 and earlier exposes message bus credentials to local unauthenticated users
github.com/edgexfoundry/device-sdk-go/v2/ github.com/edgexfoundry/app-functions-sdk-go/v2
Configuration API in EdgeXFoundry 2.1.0 and earlier exposes message bus credentials to local unauthenticated users
@backstage/plugin-techdocs-node, @backstage/techdocs-common
Path traversal for local publishers in TechDocs backend
@backstage/plugin-techdocs-node/ @backstage/techdocs-common
Path traversal for local publishers in TechDocs backend
github.com/argoproj/argo-events
Insecure path traversal in Git Trigger Source can lead to arbitrary file read
github.com/argoproj/argo-events
Insecure path traversal in Git Trigger Source can lead to arbitrary file read
github.com/argoproj/argo-events
Uses of deprecated API can be used to cause DoS in user-facing endpoints
github.com/argoproj/argo-events
Uses of deprecated API can be used to cause DoS in user-facing endpoints
undici
ProxyAgent vulnerable to MITM
biscuit-auth, github.com/biscuit-auth/biscuit-go, com.clever-cloud:biscuit-java
Signature forgery in Biscuit
biscuit-auth/ github.com/biscuit-auth/biscuit-go/ com.clever-cloud:biscuit-java
Signature forgery in Biscuit
zeroize_derive
Duplicate Advisory: `#[zeroize(drop)]` doesn't implement `Drop` for `enum`s
zeroize_derive
Duplicate Advisory: `#[zeroize(drop)]` doesn't implement `Drop` for `enum`s
windows
Delegate functions are missing `Send` bound
vec-const
vec-const attempts to construct a Vec from a pointer to a const slice
vec-const
vec-const attempts to construct a Vec from a pointer to a const slice
tremor-script
Memory Safety Issue when using `patch` or `merge` on `state` and assign the result back to `state`
tremor-script
Memory Safety Issue when using `patch` or `merge` on `state` and assign the result back to `state`
tower-http, tower-http
tower-http's improper validation of Windows paths could lead to directory traversal attack
tower-http/ tower-http
tower-http's improper validation of Windows paths could lead to directory traversal attack
thread_local
Data race in `Iter` and `IterMut`
tectonic_xdv
Duplicate Advisory: `Read` on uninitialized buffer may cause UB ('tectonic_xdv' crate)
tectonic_xdv
Duplicate Advisory: `Read` on uninitialized buffer may cause UB ('tectonic_xdv' crate)
simple_asn1
Panic on incorrect date input to `simple_asn1`
simple_asn1
Panic on incorrect date input to `simple_asn1`
sha2
Miscomputed sha2 results when using AVX2 backend
shamir
Threshold value is ignored (all shares are n=3)
rustc-serialize
Stack overflow in rustc_serialize when parsing deeply nested JSON
rustc-serialize
Stack overflow in rustc_serialize when parsing deeply nested JSON
rust-embed
RustEmbed generated `get` method allows for directory traversal when reading files from disk
rust-embed
RustEmbed generated `get` method allows for directory traversal when reading files from disk
rust-crypto
Miscomputation when performing AES encryption in rust-crypto
rust-crypto
Miscomputation when performing AES encryption in rust-crypto
