Open Source Vulnerabilities
org.jenkins-ci.plugins:claim
XSS vulnerability in Jenkins Claim Plugin
org.jenkins-ci.plugins:claim
XSS vulnerability in Jenkins Claim Plugin
org.biouno:uno-choice
Stored XSS vulnerability in Jenkins Active Choices Plugin
org.biouno:uno-choice
Stored XSS vulnerability in Jenkins Active Choices Plugin
org.jenkins-ci.plugins:support-core
Support bundles can include user session IDs in Jenkins Support Core Plugin
org.jenkins-ci.plugins:support-core
Support bundles can include user session IDs in Jenkins Support Core Plugin
io.jenkins.plugins:artifact-repository-parameter
Stored XSS vulnerability in Jenkins Artifact Repository Parameter Plugin
io.jenkins.plugins:artifact-repository-parameter
Stored XSS vulnerability in Jenkins Artifact Repository Parameter Plugin
org.jenkins-ci.plugins:configurationslicing
CSRF vulnerability in Jenkins Configuration Slicing Plugin
org.jenkins-ci.plugins:configurationslicing
CSRF vulnerability in Jenkins Configuration Slicing Plugin
org.jenkins-ci.plugins:repository-connector
Stored XSS vulnerability in Jenkins Repository Connector Plugin
org.jenkins-ci.plugins:repository-connector
Stored XSS vulnerability in Jenkins Repository Connector Plugin
mantisbt/mantisbt
MantisBT XSS in manage_custom_field_update.php
mantisbt/mantisbt
MantisBT XSS in manage_custom_field_update.php
org.opennms:opennms, org.opennms.features:org.opennms.features.measurements, org.opennms:opennms-provision, org.opennms:opennms-util
OpenNMS Horizon RCE via JEXL2 expression
org.opennms:opennms/ org.opennms.features:org.opennms.features.measurements/ org.opennms:opennms-provision/ org.opennms:opennms-util
OpenNMS Horizon RCE via JEXL2 expression
gramaddict
GramAddict bot uses dependency with reverse tcp backdoor
gramaddict
GramAddict bot uses dependency with reverse tcp backdoor
jsdom
Withdrawn Advisory: Insufficient Granularity of Access Control in JSDom
jsdom
Withdrawn Advisory: Insufficient Granularity of Access Control in JSDom
nfstream
NFStream Local Denial of Service (DoS)
pyqlib
qlib Deserialization of Untrusted Data vulnerability
pyqlib
qlib Deserialization of Untrusted Data vulnerability
magento/community-edition, magento/community-edition, magento/project-community-edition
Magento Insufficient Session Expiration
magento/community-edition/ magento/community-edition/ magento/project-community-edition
Magento Insufficient Session Expiration
magento/community-edition, magento/community-edition
Magento Blind SQL Injection in the Search module
magento/community-edition/ magento/community-edition
Magento Blind SQL Injection in the Search module
magento/community-edition, magento/community-edition
Magento XML injection in the Widgets module
magento/community-edition/ magento/community-edition
Magento XML injection in the Widgets module
magento/community-edition, magento/community-edition
Magento Reflected Cross-site Scripting vulnerability via 'file' parameter
magento/community-edition/ magento/community-edition
Magento Reflected Cross-site Scripting vulnerability via 'file' parameter
magento/community-edition, magento/community-edition, magento/project-community-edition
Magento Insufficient Session Expiration
magento/community-edition/ magento/community-edition/ magento/project-community-edition
Magento Insufficient Session Expiration
magento/community-edition, magento/community-edition, magento/project-community-edition
Magento stored cross-site scripting (XSS) in the customer address upload feature
magento/community-edition/ magento/community-edition/ magento/project-community-edition
Magento stored cross-site scripting (XSS) in the customer address upload feature
magento/community-edition, magento/community-edition, magento/project-community-edition
Magento Insecure Direct Object Reference (IDOR) in the product module
magento/community-edition/ magento/community-edition/ magento/project-community-edition
Magento Insecure Direct Object Reference (IDOR) in the product module
magento/community-edition, magento/community-edition, magento/project-community-edition
Magento improper authorization vulnerability in the integrations module
magento/community-edition/ magento/community-edition/ magento/project-community-edition
Magento improper authorization vulnerability in the integrations module
magento/community-edition, magento/community-edition, magento/project-community-edition
Magento cross-site request forgery (CSRF) vulnerability via the GraphQL API
magento/community-edition/ magento/community-edition/ magento/project-community-edition
Magento cross-site request forgery (CSRF) vulnerability via the GraphQL API
magento/community-edition, magento/community-edition, magento/project-community-edition
Magento stored cross-site scripting vulnerability in the admin console
magento/community-edition/ magento/community-edition/ magento/project-community-edition
Magento stored cross-site scripting vulnerability in the admin console
magento/community-edition, magento/community-edition
Magento OS Command Injection
magento/community-edition/ magento/community-edition
Magento OS Command Injection
magento/community-edition, magento/community-edition, magento/project-community-edition
Magento vulnerable to a file upload restriction bypass
magento/community-edition/ magento/community-edition/ magento/project-community-edition
Magento vulnerable to a file upload restriction bypass
magento/community-edition, magento/community-edition, magento/project-community-edition
Magento Improper Access Control
magento/community-edition/ magento/community-edition/ magento/project-community-edition
Magento Improper Access Control
magento/community-edition, magento/community-edition, magento/project-community-edition
Magento XPath Injection
magento/community-edition/ magento/community-edition/ magento/project-community-edition
Magento XPath Injection
magento/community-edition, magento/community-edition
Magento OS command injection via the customer attribute save controller
magento/community-edition/ magento/community-edition
Magento OS command injection via the customer attribute save controller
magento/community-edition, magento/community-edition, magento/project-community-edition
Magento OS command injection via the WebAPI
magento/community-edition/ magento/community-edition/ magento/project-community-edition
Magento OS command injection via the WebAPI
qwutils
insert_slice_clone can double drop if Clone panics.
qwutils
insert_slice_clone can double drop if Clone panics.
com.squareup.okhttp3:okhttp
Square OkHttp can accept the wrong certificate
com.squareup.okhttp3:okhttp
Square OkHttp can accept the wrong certificate
org.elasticsearch:elasticsearch, org.elasticsearch:elasticsearch
Insertion of Sensitive Information into Log File in Elasticsearch
org.elasticsearch:elasticsearch/ org.elasticsearch:elasticsearch
Insertion of Sensitive Information into Log File in Elasticsearch
org.jetbrains.kotlin:kotlin-stdlib
Incorrect Default Permissions in JetBrains Kotlin
org.jetbrains.kotlin:kotlin-stdlib
Incorrect Default Permissions in JetBrains Kotlin
mantisbt/mantisbt
MantisBT Insecure Storage in manage_proj_edit_page.php
mantisbt/mantisbt
MantisBT Insecure Storage in manage_proj_edit_page.php
mantisbt/mantisbt
MantisBT Incorrect Authorization in bug_actiongroup_page.php
mantisbt/mantisbt
MantisBT Incorrect Authorization in bug_actiongroup_page.php
mantisbt/mantisbt
MantisBT Missing Authorization access check in bug_actiongroup.php
mantisbt/mantisbt
MantisBT Missing Authorization access check in bug_actiongroup.php
moodle/moodle
Moodle Vulnerable to Reflected Cross-site Scripting
moodle/moodle
Moodle Vulnerable to Reflected Cross-site Scripting
moodle/moodle, moodle/moodle, moodle/moodle
Moodle Grade information disclosure in grade's external fetch functions
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle Grade information disclosure in grade's external fetch functions
moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle
Moodle Arbitrary PHP code execution by site admins via Shibboleth configuration
moodle/moodle/ moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle Arbitrary PHP code execution by site admins via Shibboleth configuration
moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle
Moodle Client side denial of service via personal message
moodle/moodle/ moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle Client side denial of service via personal message
moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle
Moodle Cross-site Scripting
moodle/moodle/ moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle Cross-site Scripting
codiad/codiad
Codiad Vulnerable to PHP Magic Hash Vulnerability
codiad/codiad
Codiad Vulnerable to PHP Magic Hash Vulnerability
zencart/zencart
Zen Cart vulnerable to authenticated remote code execution
zencart/zencart
Zen Cart vulnerable to authenticated remote code execution
ckeditor4-dev
CKEditor 4 ReDoS Vulnerability
smallvec, smallvec
Buffer overflow in SmallVec::insert_many
smallvec/ smallvec
Buffer overflow in SmallVec::insert_many
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Time-of-check Time-of-use (TOCTOU) Race Condition in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Time-of-check Time-of-use (TOCTOU) Race Condition in Jenkins
async-h1
Async-h1 request smuggling possible with long unread bodies
async-h1
Async-h1 request smuggling possible with long unread bodies
cakephp/cakephp, cakephp/cakephp
CakePHP allows method override parameters to bypass CSRF checks
cakephp/cakephp/ cakephp/cakephp
CakePHP allows method override parameters to bypass CSRF checks
feehi/cms
Feehi CMS vulnerable to Cross-site Scripting in Username Field
feehi/cms
Feehi CMS vulnerable to Cross-site Scripting in Username Field
feehi/cms
Feehi CMS arbitrary file upload vulnerability
feehi/cms
Feehi CMS arbitrary file upload vulnerability
github.com/hashicorp/vault-csi-provider, github.com/Azure/secrets-store-csi-driver-provider-azure, github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp
Kubernetes Secrets Store CSI Driver plugins arbitrary file write
github.com/hashicorp/vault-csi-provider/ github.com/Azure/secrets-store-csi-driver-provider-azure/ github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp
Kubernetes Secrets Store CSI Driver plugins arbitrary file write
