Open Source Vulnerabilities
org.jenkins-ci.plugins:requests
CSRF vulnerabilities in Jenkins requests-plugin Plugin
org.jenkins-ci.plugins:requests
CSRF vulnerabilities in Jenkins requests-plugin Plugin
org.jenkins-ci.plugins:requests
Missing permission check in Jenkins requests-plugin Plugin allows viewing pending requests
org.jenkins-ci.plugins:requests
Missing permission check in Jenkins requests-plugin Plugin allows viewing pending requests
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Improper permission checks allow canceling queue items and aborting builds in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Improper permission checks allow canceling queue items and aborting builds in Jenkins
org.jenkins-ci.plugins:cas-plugin
Open redirect vulnerability in Jenkins CAS Plugin
org.jenkins-ci.plugins:cas-plugin
Open redirect vulnerability in Jenkins CAS Plugin
org.jenkins-ci.plugins:requests
Missing permission check in Jenkins requests-plugin Plugin allows sending emails
org.jenkins-ci.plugins:requests
Missing permission check in Jenkins requests-plugin Plugin allows sending emails
ec-cube/ec-cube
EC-CUBE Cross-site scripting vulnerability
ec-cube/ec-cube
EC-CUBE Cross-site scripting vulnerability
ec-cube/ec-cube, ec-cube/ec-cube
EC-CUBE Cross-site scripting vulnerability
ec-cube/ec-cube/ ec-cube/ec-cube
EC-CUBE Cross-site scripting vulnerability
magento/community-edition, magento/community-edition, magento/project-community-edition
Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies
magento/community-edition/ magento/community-edition/ magento/project-community-edition
Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies
magento/community-edition, magento/community-edition, magento/project-community-edition
Magento Violation of Secure Design Principles vulnerability in RMA PDF filename formats
magento/community-edition/ magento/community-edition/ magento/project-community-edition
Magento Violation of Secure Design Principles vulnerability in RMA PDF filename formats
magento/community-edition, magento/community-edition
Magento Unauthorized access to restricted resources
magento/community-edition/ magento/community-edition
Magento Unauthorized access to restricted resources
magento/community-edition, magento/community-edition, magento/project-community-edition
Magento Path Traversal vulnerability
magento/community-edition/ magento/community-edition/ magento/project-community-edition
Magento Path Traversal vulnerability
magento/community-edition, magento/community-edition, magento/project-community-edition
Magento Improper input validation vulnerability
magento/community-edition/ magento/community-edition/ magento/project-community-edition
Magento Improper input validation vulnerability
com.jfinal:jfinal
JFinal Java Deserialization Vulnerability
com.jfinal:jfinal
JFinal Java Deserialization Vulnerability
moodle/moodle, moodle/moodle, moodle/moodle
Moodle command execution vulnerability exists in the default legacy spellchecker plugin
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle command execution vulnerability exists in the default legacy spellchecker plugin
automattic/jetpack
JetPack Exposure of Resource to Wrong Sphere
automattic/jetpack
JetPack Exposure of Resource to Wrong Sphere
org.jenkins-ci.plugins:generic-webhook-trigger
XXE vulnerability in Jenkins Generic Webhook Trigger Plugin
org.jenkins-ci.plugins:generic-webhook-trigger
XXE vulnerability in Jenkins Generic Webhook Trigger Plugin
mantisbt/mantisbt
MantisBT allows XSS in manage_custom_field_edit_page.php
mantisbt/mantisbt
MantisBT allows XSS in manage_custom_field_edit_page.php
hermes-engine
Use After Free in Hermes
moodle/moodle
Moodle Cross Site Scripting (XSS)
drupal/core, drupal/core, drupal/core
Drupal Core Cross-site scripting vulnerability
drupal/core/ drupal/core/ drupal/core
Drupal Core Cross-site scripting vulnerability
drupal/core, drupal/core, drupal/core, drupal/core, drupal/drupal, drupal/drupal, drupal/drupal, drupal/drupal
Drupal Core Cross-Site Request Forgery (CSRF) vulnerability
drupal/core/ drupal/core/ drupal/core/ drupal/core/ drupal/drupal/ drupal/drupal/ drupal/drupal/ drupal/drupal
Drupal Core Cross-Site Request Forgery (CSRF) vulnerability
com.xebialabs.deployit.ci:deployit-plugin
CSRF vulnerability in Jenkins XebiaLabs XL Deploy Plugin allows capturing credentials
com.xebialabs.deployit.ci:deployit-plugin
CSRF vulnerability in Jenkins XebiaLabs XL Deploy Plugin allows capturing credentials
com.xebialabs.deployit.ci:deployit-plugin
Missing permission check in Jenkins XebiaLabs XL Deploy Plugin allows capturing credentials
com.xebialabs.deployit.ci:deployit-plugin
Missing permission check in Jenkins XebiaLabs XL Deploy Plugin allows capturing credentials
com.xebialabs.deployit.ci:deployit-plugin
Incorrect permission check in XebiaLabs XL Deploy Plugin allows capturing credentials
com.xebialabs.deployit.ci:deployit-plugin
Incorrect permission check in XebiaLabs XL Deploy Plugin allows capturing credentials
silverstripe/framework
SilverStripe XXE Vulnerability in CSSContentParser
silverstripe/framework
SilverStripe XXE Vulnerability in CSSContentParser
github.com/nmstate/kubernetes-nmstate
Withdrawn Advisory: kubernetes-nmstate Insecure Privilege Management
github.com/nmstate/kubernetes-nmstate
Withdrawn Advisory: kubernetes-nmstate Insecure Privilege Management
neutron, neutron, neutron
Openstack Neutron has Insufficient Verification of IPv6 addresses
neutron/ neutron/ neutron
Openstack Neutron has Insufficient Verification of IPv6 addresses
istio.io/istio, istio.io/istio
Istio Authorization Bypass Vulnerability
istio.io/istio/ istio.io/istio
Istio Authorization Bypass Vulnerability
golang.org/x/net
golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion
golang.org/x/net
golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion
org.springframework:spring-web, org.springframework:spring-web
Improper Privilege Management in Spring Framework
org.springframework:spring-web/ org.springframework:spring-web
Improper Privilege Management in Spring Framework
golang.org/x/net
golang.org/x/net/html Infinite Loop vulnerability
golang.org/x/net
golang.org/x/net/html Infinite Loop vulnerability
org.jenkins-ci.plugins:urltrigger
XXE vulnerability in Jenkins URLTrigger Plugin
org.jenkins-ci.plugins:urltrigger
XXE vulnerability in Jenkins URLTrigger Plugin
org.jenkins-ci.plugins:fstrigger
XXE vulnerability in Jenkins Filesystem Trigger Plugin
org.jenkins-ci.plugins:fstrigger
XXE vulnerability in Jenkins Filesystem Trigger Plugin
org.apache.wicket:wicket-core, org.apache.wicket:wicket-core, org.apache.wicket:wicket-core
DNS based denial of service in Apache Wicket
org.apache.wicket:wicket-core/ org.apache.wicket:wicket-core/ org.apache.wicket:wicket-core
DNS based denial of service in Apache Wicket
org.jenkins-ci.plugins:nuget
XML external entity vulnerability in Jenkins Nuget Plugin
org.jenkins-ci.plugins:nuget
XML external entity vulnerability in Jenkins Nuget Plugin
io.jenkins.plugins:markdown-formatter
XSS vulnerability in Jenkins Markdown Formatter Plugin
io.jenkins.plugins:markdown-formatter
XSS vulnerability in Jenkins Markdown Formatter Plugin
org.opennms:opennms
OpenNMS Horizon vulnerable to XSS
deep-defaults
deep-defaults vulnerable to prototype pollution
deep-defaults
deep-defaults vulnerable to prototype pollution
plone
Plone XSS in User Fullname Property and File Upload
nokogiri
Nokogiri contains libxml Out-of-bounds Write vulnerability
nokogiri
Nokogiri contains libxml Out-of-bounds Write vulnerability
nokogiri
Nokogiri Implements libxml2 version vulnerable to use-after-free
nokogiri
Nokogiri Implements libxml2 version vulnerable to use-after-free
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in the Layout Admin Page
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in the Layout Admin Page
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Asset Module Parameter
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Asset Module Parameter
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Multiple SQL Injections
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Multiple SQL Injections
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the Redirect's Admin Page
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the Redirect's Admin Page
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Membership Request Admin Page
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Membership Request Admin Page
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Asset Publisher App
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Asset Publisher App
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Fails to Check Permissions
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Fails to Check Permissions
woocommerce/woocommerce
Woocommerce Cross-site Scripting via Additional tax classes field when taxes are enabled
woocommerce/woocommerce
Woocommerce Cross-site Scripting via Additional tax classes field when taxes are enabled
