Open Source Vulnerabilities
tensorflow, tensorflow, tensorflow, tensorflow-cpu, tensorflow-cpu, tensorflow-cpu, tensorflow-gpu, tensorflow-gpu, tensorflow-gpu
Missing validation crashes `QuantizeAndDequantizeV4Grad`
tensorflow/ tensorflow/ tensorflow/ tensorflow-cpu/ tensorflow-cpu/ tensorflow-cpu/ tensorflow-gpu/ tensorflow-gpu/ tensorflow-gpu
Missing validation crashes `QuantizeAndDequantizeV4Grad`
tensorflow, tensorflow-cpu, tensorflow-gpu, tensorflow, tensorflow, tensorflow-cpu, tensorflow-cpu, tensorflow-gpu, tensorflow-gpu
Missing validation causes denial of service via `GetSessionTensor`
tensorflow/ tensorflow-cpu/ tensorflow-gpu/ tensorflow/ tensorflow/ tensorflow-cpu/ tensorflow-cpu/ tensorflow-gpu/ tensorflow-gpu
Missing validation causes denial of service via `GetSessionTensor`
github.com/pion/dtls, github.com/pion/dtls/v2
Pion DTLS Header reconstruction method can be thrown into an infinite loop
github.com/pion/dtls/ github.com/pion/dtls/v2
Pion DTLS Header reconstruction method can be thrown into an infinite loop
github.com/pion/dtls, github.com/pion/dtls/v2
Pion/DTLS contains buffer for inbound DTLS fragments with no limit
github.com/pion/dtls/ github.com/pion/dtls/v2
Pion/DTLS contains buffer for inbound DTLS fragments with no limit
github.com/stripe/smokescreen
Smokescreen SSRF via deny list bypass (square brackets)
github.com/stripe/smokescreen
Smokescreen SSRF via deny list bypass (square brackets)
next-auth, next-auth
URL Redirection to Untrusted Site ('Open Redirect') in next-auth
next-auth/ next-auth
URL Redirection to Untrusted Site ('Open Redirect') in next-auth
com.xebialabs.deployit.ci:deployit-plugin
Missing permission check in Jenkins XebiaLabs XL Deploy Plugin allows enumerating credentials IDs
com.xebialabs.deployit.ci:deployit-plugin
Missing permission check in Jenkins XebiaLabs XL Deploy Plugin allows enumerating credentials IDs
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the currentURL Parameter
com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the currentURL Parameter
mootools-more
mootools-more vulnerable to prototype pollution
mootools-more
mootools-more vulnerable to prototype pollution
github.com/liamg/gitjacker
gitjacker arbitrary code execution
github.com/liamg/gitjacker
gitjacker arbitrary code execution
github.com/openark/orchestrator
openark/orchestrator cross-site scripting vulnerability
github.com/openark/orchestrator
openark/orchestrator cross-site scripting vulnerability
golang.org/x/crypto
golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability
golang.org/x/crypto
golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability
github.com/hashicorp/vault
Token leases could outlive their TTL in HashiCorp Vault
github.com/hashicorp/vault
Token leases could outlive their TTL in HashiCorp Vault
org.jboss.resteasy:resteasy-client, org.jboss.resteasy:resteasy-client
Improper Input Validation in RESTEasy
org.jboss.resteasy:resteasy-client/ org.jboss.resteasy:resteasy-client
Improper Input Validation in RESTEasy
ansible
Ansible Code Injection Vulnerability
github.com/influxdata/influxdb
InfluxDB Reflected Cross-site Scripting
github.com/influxdata/influxdb
InfluxDB Reflected Cross-site Scripting
io.pebbletemplates:pebble-project
Pebble Templates Improper Input Validation vulnerability
io.pebbletemplates:pebble-project
Pebble Templates Improper Input Validation vulnerability
org.igniterealtime.openfire:parent
XSS in Ignite Realtime Openfire via isTrustStore
org.igniterealtime.openfire:parent
XSS in Ignite Realtime Openfire via isTrustStore
bson-objectid
bson-objectid contains Improper input validation
bson-objectid
bson-objectid contains Improper input validation
net-ldap
net-ldap has weak salt when generating passwords
helm.sh/helm
Helm Unsafe Link Following
istio.io/istio
Istio vulnerable to denial of service
org.hornetq.rest:hornetq-rest
HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference
org.hornetq.rest:hornetq-rest
HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference
matrix-synapse
Improper Verification of Cryptographic Signature in matrix-synapse
matrix-synapse
Improper Verification of Cryptographic Signature in matrix-synapse
com.typesafe.play:play-ws_2.12
Play Framework Inadequate Encryption Strength vulnerability
com.typesafe.play:play-ws_2.12
Play Framework Inadequate Encryption Strength vulnerability
magento/community-edition, magento/community-edition
Magento remote code execution vulnerability
magento/community-edition/ magento/community-edition
Magento remote code execution vulnerability
magento/community-edition, magento/community-edition
Magento Broken authentication and session managememt
magento/community-edition/ magento/community-edition
Magento Broken authentication and session managememt
pip
Improper Authentication in pip
phantomjs
PhantomJS Arbitrary File Read
reportlab
XML Injection in ReportLab
numpy
Numpy Deserialization of Untrusted Data
nilsteampassnet/teampass
TeamPass Cross-site Scripting (XSS) vulnerability
nilsteampassnet/teampass
TeamPass Cross-site Scripting (XSS) vulnerability
org.jenkins-ci.plugins:gitlab-logo
Jenkins GitLab Logo Plugin stores credentials unencrypted
org.jenkins-ci.plugins:gitlab-logo
Jenkins GitLab Logo Plugin stores credentials unencrypted
io.jenkins.plugins:neuvector-vulnerability-scanner
Jenkins NeuVector Vulnerability Scanner Plugin stored credentials in plain text
io.jenkins.plugins:neuvector-vulnerability-scanner
Jenkins NeuVector Vulnerability Scanner Plugin stored credentials in plain text
net.arangamani.jenkins:gem-publisher
Jenkins Gem Publisher Plugin stores credentials as plaintext
net.arangamani.jenkins:gem-publisher
Jenkins Gem Publisher Plugin stores credentials as plaintext
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Improper Neutralization of Input During Web Page Generation in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Improper Neutralization of Input During Web Page Generation in Jenkins
org.jenkins-ci.plugins:aqua-microscanner
Jenkins Aqua MicroScanner Plugin showed plain text credential in configuration form
org.jenkins-ci.plugins:aqua-microscanner
Jenkins Aqua MicroScanner Plugin showed plain text credential in configuration form
hudson.plugins:project-inheritance
Project Inheritance Plugin showed secret environment variables defined in Mask Passwords Plugin
hudson.plugins:project-inheritance
Project Inheritance Plugin showed secret environment variables defined in Mask Passwords Plugin
org.jenkins-ci.plugins:aqua-security-scanner
Jenkins Aqua Security Scanner Plugin showed plain text password in configuration form
org.jenkins-ci.plugins:aqua-security-scanner
Jenkins Aqua Security Scanner Plugin showed plain text password in configuration form
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Improper Neutralization of Input During Web Page Generation in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Improper Neutralization of Input During Web Page Generation in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Improper Neutralization of Input During Web Page Generation in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Improper Neutralization of Input During Web Page Generation in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Improper Neutralization of Input During Web Page Generation in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Improper Neutralization of Input During Web Page Generation in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Improper Neutralization of Input During Web Page Generation in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Improper Neutralization of Input During Web Page Generation in Jenkins
magento/community-edition, magento/community-edition, magento/community-edition
Magento 2 Community Edition SQLi Vulnerability
magento/community-edition/ magento/community-edition/ magento/community-edition
Magento 2 Community Edition SQLi Vulnerability
github.com/beego/beego, github.com/astaxie/beego
Incorrect Default Permissions in Beego
github.com/beego/beego/ github.com/astaxie/beego
Incorrect Default Permissions in Beego
org.apache.tapestry:tapestry-core
Deserialization of Untrusted Data in Apache Tapestry
org.apache.tapestry:tapestry-core
Deserialization of Untrusted Data in Apache Tapestry
phpmyadmin/phpmyadmin
phpMyAdmin Cross-Site Request Forgery (CSRF)
phpmyadmin/phpmyadmin
phpMyAdmin Cross-Site Request Forgery (CSRF)
Microsoft.AspNetCore.SpaServices, Microsoft.AspNetCore.SpaServices
Elevation of privilege in ASP.NET Core
Microsoft.AspNetCore.SpaServices/ Microsoft.AspNetCore.SpaServices
Elevation of privilege in ASP.NET Core
