Open Source Vulnerabilities
org.jenkins-ci.plugins:nomad
Password stored in plain text by Jenkins Nomad Plugin
org.jenkins-ci.plugins:nomad
Password stored in plain text by Jenkins Nomad Plugin
org.jenkins-ci.plugins:nested-view
XXE vulnerability in Jenkins Nested View Plugin
org.jenkins-ci.plugins:nested-view
XXE vulnerability in Jenkins Nested View Plugin
org.jenkins-ci.plugins:azure-ad
Jenkins Azure AD Plugin allows bypassing CSRF protection for any URL
org.jenkins-ci.plugins:azure-ad
Jenkins Azure AD Plugin allows bypassing CSRF protection for any URL
neutron, neutron, neutron
OpenStack Neutron vulnerable to authenticated attackers reconfiguring dnsmasq via crafted extra_dhcp_opts value
neutron/ neutron/ neutron
OpenStack Neutron vulnerable to authenticated attackers reconfiguring dnsmasq via crafted extra_dhcp_opts value
mezzanine
Mezzanine Cross Site Scripting (XSS) vulnerability
mezzanine
Mezzanine Cross Site Scripting (XSS) vulnerability
openssl-src
SM2 Decryption Buffer Overflow
openssl-src
Read buffer overruns processing ASN.1 strings
neutron, neutron, neutron
OpenStack Neutron vulnerable to hardware address impersonation
neutron/ neutron/ neutron
OpenStack Neutron vulnerable to hardware address impersonation
org.owasp:csrfguard
Cross-Site Request Forgery in OWASP CSRFGuard
org.owasp:csrfguard
Cross-Site Request Forgery in OWASP CSRFGuard
lin-cms
Lin-CMS-Flask vulnerable to Improper Authentication
lin-cms
Lin-CMS-Flask vulnerable to Improper Authentication
lin-cms
Lin-CMS-Flask Cross Site Scripting (XSS) vulnerability
lin-cms
Lin-CMS-Flask Cross Site Scripting (XSS) vulnerability
obsidian
Obsidian does not require user confirmation for non-http/https URLs.
obsidian
Obsidian does not require user confirmation for non-http/https URLs.
org.jeecgframework.boot:jeecg-boot-parent
Jeecg-Boot CMS arbitrary file upload vulnerability
org.jeecgframework.boot:jeecg-boot-parent
Jeecg-Boot CMS arbitrary file upload vulnerability
intelliants/subrion
Subrion Cross-Site Scripting (XSS) vulnerability
intelliants/subrion
Subrion Cross-Site Scripting (XSS) vulnerability
keystone, keystone, keystone, keystone
OpenStack Keystone allows information disclosure during account locking
keystone/ keystone/ keystone/ keystone
OpenStack Keystone allows information disclosure during account locking
org.wildfly.security:wildfly-elytron, org.wildfly.security:wildfly-elytron, org.wildfly.security:wildfly-elytron
Observable Discrepancy in Wildfly Elytron
org.wildfly.security:wildfly-elytron/ org.wildfly.security:wildfly-elytron/ org.wildfly.security:wildfly-elytron
Observable Discrepancy in Wildfly Elytron
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal Layout Module and Liferay DXP Exposes the Cross-Site Request Forgery (CSRF) Token in URLs
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal Layout Module and Liferay DXP Exposes the Cross-Site Request Forgery (CSRF) Token in URLs
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Liferay Portal Fragment Module and Liferay DXP Vulnerable to Cross-Site Scripting
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal Fragment Module and Liferay DXP Vulnerable to Cross-Site Scripting
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal Journal Module and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal Journal Module and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
com.liferay.portal:release.portal.bom, com.liferay:com.liferay.frontend.taglib.clay
Liferay Portal cross-site scripting (XSS) vulnerability in the Frontend Taglib module
com.liferay.portal:release.portal.bom/ com.liferay:com.liferay.frontend.taglib.clay
Liferay Portal cross-site scripting (XSS) vulnerability in the Frontend Taglib module
com.liferay:com.liferay.document.library.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Document Library module
com.liferay:com.liferay.document.library.web/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Document Library module
joplin
Joplin vulnerable to Cross-site Scripting in notes
nokogiri
Nokogiri has vulnerable dependencies on libxml2 and libxslt
nokogiri
Nokogiri has vulnerable dependencies on libxml2 and libxslt
com.liferay:com.liferay.portlet.configuration.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP does not properly check user permission
com.liferay:com.liferay.portlet.configuration.web/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP does not properly check user permission
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Don't Check Permissions of Pages
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Don't Check Permissions of Pages
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Stores User Passwords in Cleartext
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Stores User Passwords in Cleartext
com.liferay:com.liferay.dynamic.data.mapping.form.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP autosaves form data for other users to see
com.liferay:com.liferay.dynamic.data.mapping.form.web/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP autosaves form data for other users to see
com.liferay:com.liferay.frontend.js.aui.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Frontend JS module
com.liferay:com.liferay.frontend.js.aui.web/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Frontend JS module
com.liferay.portal:com.liferay.portal.impl, com.liferay.portal:release.portal.bom
Liferay Portal and Liferay DXP insecure default configuration
com.liferay.portal:com.liferay.portal.impl/ com.liferay.portal:release.portal.bom
Liferay Portal and Liferay DXP insecure default configuration
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Edit Vocabulary Page
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Edit Vocabulary Page
com.liferay:com.liferay.flags.taglib, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP vulnerable to email spam via lack of flagging rate
com.liferay:com.liferay.flags.taglib/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP vulnerable to email spam via lack of flagging rate
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Fails to Properly Check User Permissions
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Fails to Properly Check User Permissions
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Fails to Check User Permissions for Workflow Submissions
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Fails to Check User Permissions for Workflow Submissions
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Allows Arbitrary Redirect of Users to External URLs
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Allows Arbitrary Redirect of Users to External URLs
mongodb
Exposure of Sensitive Information to an Unauthorized Actor in MongoDB Rust Driver
mongodb
Exposure of Sensitive Information to an Unauthorized Actor in MongoDB Rust Driver
nukeviet/nukeviet
NukeViet Cross-site Scripting via the editor in the News module
nukeviet/nukeviet
NukeViet Cross-site Scripting via the editor in the News module
nukeviet/nukeviet
NukeViet SQL Injection vulnerability via topicsid parameter
nukeviet/nukeviet
NukeViet SQL Injection vulnerability via topicsid parameter
nukeviet/nukeviet, nukeviet/nukeviet, nukeviet/nukeviet, nukeviet/nukeviet
NukeViet SQL Injection vulnerability
nukeviet/nukeviet/ nukeviet/nukeviet/ nukeviet/nukeviet/ nukeviet/nukeviet
NukeViet SQL Injection vulnerability
org.neo4j:neo4j-kernel
Improper Privilege Management in Neo4j Graph Database
org.neo4j:neo4j-kernel
Improper Privilege Management in Neo4j Graph Database
org.elasticsearch.client:elasticsearch-rest-client
Generation of Error Message Containing Sensitive Information in Elasticsearch
org.elasticsearch.client:elasticsearch-rest-client
Generation of Error Message Containing Sensitive Information in Elasticsearch
thinkcmf/thinkcmf
ThinkCMF Cross Site Request Forgerly (CSRF) vulnerability
thinkcmf/thinkcmf
ThinkCMF Cross Site Request Forgerly (CSRF) vulnerability
xo-web, xo-server
Xen Orchestra Mishandles Authorization
xo-web/ xo-server
Xen Orchestra Mishandles Authorization
smashing
Smashing Cross-site Scripting vulnerability
lavalite/cms
LavaLite Stored Cross-site Scripting vulnerability
lavalite/cms
LavaLite Stored Cross-site Scripting vulnerability
lavalite/cms
Stored XSS in LavaLite 5.8.0
lavalite/cms
Stored XSS in LavaLite 5.8.0
plone
Plone has stored XSS in folder contents
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Session fixation vulnerability in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Session fixation vulnerability in Jenkins
