Open Source Vulnerabilities
wp-premium/gravityforms
Gravity Forms stored Cross-Site Scripting (XSS) vulnerability
wp-premium/gravityforms
Gravity Forms stored Cross-Site Scripting (XSS) vulnerability
wp-premium/gravityforms
Gravity Forms stored Cross-Site Scripting (XSS) vulnerability in the survey feature
wp-premium/gravityforms
Gravity Forms stored Cross-Site Scripting (XSS) vulnerability in the survey feature
wp-premium/gravityforms
Gravity Forms stored HTML injection vulnerability
wp-premium/gravityforms
Gravity Forms stored HTML injection vulnerability
mautic/core, mautic/core
Mautic stored Cross-site Scripting (XSS)
mautic/core/ mautic/core
Mautic stored Cross-site Scripting (XSS)
io.jenkins.plugins:tics
XSS vulnerability in Jenkins TICS Plugin
io.jenkins.plugins:tics
XSS vulnerability in Jenkins TICS Plugin
git-big-picture
git-big-picture Code Execution
de.tracetronic.jenkins.plugins:ecutest
Credentials stored in plain text by Jenkins TraceTronic ECU-TEST Plugin
de.tracetronic.jenkins.plugins:ecutest
Credentials stored in plain text by Jenkins TraceTronic ECU-TEST Plugin
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Path traversal vulnerability in Jenkins agent names
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Path traversal vulnerability in Jenkins agent names
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Stored XSS vulnerability in Jenkins on new item page
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Stored XSS vulnerability in Jenkins on new item page
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Reflected XSS vulnerability in Jenkins markup formatter preview
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Reflected XSS vulnerability in Jenkins markup formatter preview
org.jenkins-ci.plugins:bumblebee
Credentials stored in plain text by Jenkins Bumblebee HP ALM Plugin
org.jenkins-ci.plugins:bumblebee
Credentials stored in plain text by Jenkins Bumblebee HP ALM Plugin
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Excessive memory allocation in graph URLs leads to denial of service in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Excessive memory allocation in graph URLs leads to denial of service in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Stored XSS vulnerability in Jenkins button labels
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Stored XSS vulnerability in Jenkins button labels
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Arbitrary file read vulnerability in workspace browsers in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Arbitrary file read vulnerability in workspace browsers in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Improper handling of REST API XML deserialization errors in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Improper handling of REST API XML deserialization errors in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Missing permission check for paths with specific prefix in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Missing permission check for paths with specific prefix in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
XSS vulnerability in Jenkins notification bar
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
XSS vulnerability in Jenkins notification bar
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Arbitrary file existence check in file fingerprints in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Arbitrary file existence check in file fingerprints in Jenkins
jupyterhub
Cross-Site Request Forgery in JupyterHub
zoujingli/thinkadmin
ThinkAdmin insecure unserialize vulnerability
zoujingli/thinkadmin
ThinkAdmin insecure unserialize vulnerability
Microsoft.AspNetCore.Server.Kestrel.Core, Microsoft.AspNetCore.App.Runtime.linux-arm, Microsoft.AspNetCore.App.Runtime.linux-arm, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-x64, Microsoft.AspNetCore.App.Runtime.linux-musl-x64, Microsoft.AspNetCore.App.Runtime.linux-x64, Microsoft.AspNetCore.App.Runtime.linux-x64, Microsoft.AspNetCore.App.Runtime.osx-x64, Microsoft.AspNetCore.App.Runtime.osx-x64, Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.win-arm64, Microsoft.AspNetCore.App.Runtime.win-arm64, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-x86, Microsoft.AspNetCore.App.Runtime.win-x86, Microsoft.AspNetCore.App.Runtime.linux-musl-arm
ASP.NET Core and Visual Studio Denial of Service Vulnerability
Microsoft.AspNetCore.Server.Kestrel.Core/ Microsoft.AspNetCore.App.Runtime.linux-arm/ Microsoft.AspNetCore.App.Runtime.linux-arm/ Microsoft.AspNetCore.App.Runtime.linux-arm64/ Microsoft.AspNetCore.App.Runtime.linux-arm64/ Microsoft.AspNetCore.App.Runtime.linux-musl-arm64/ Microsoft.AspNetCore.App.Runtime.linux-musl-arm64/ Microsoft.AspNetCore.App.Runtime.linux-musl-x64/ Microsoft.AspNetCore.App.Runtime.linux-musl-x64/ Microsoft.AspNetCore.App.Runtime.linux-x64/ Microsoft.AspNetCore.App.Runtime.linux-x64/ Microsoft.AspNetCore.App.Runtime.osx-x64/ Microsoft.AspNetCore.App.Runtime.osx-x64/ Microsoft.AspNetCore.App.Runtime.win-arm/ Microsoft.AspNetCore.App.Runtime.win-arm/ Microsoft.AspNetCore.App.Runtime.win-arm64/ Microsoft.AspNetCore.App.Runtime.win-arm64/ Microsoft.AspNetCore.App.Runtime.win-x64/ Microsoft.AspNetCore.App.Runtime.win-x64/ Microsoft.AspNetCore.App.Runtime.win-x86/ Microsoft.AspNetCore.App.Runtime.win-x86/ Microsoft.AspNetCore.App.Runtime.linux-musl-arm
ASP.NET Core and Visual Studio Denial of Service Vulnerability
crmsh
ClusterLabs crmsh vulnerable to shell code injection
crmsh
ClusterLabs crmsh vulnerable to shell code injection
formstone
Formstone Vulnerable to Reflected XSS
com.liferay.portal:release.portal.bom, com.liferay.portal:release.portal.bom
Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via User Name Parameter
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.portal.bom
Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via User Name Parameter
UmbracoCms.Core
Umbraco CMS vulnerable to stored XSS
futures-task
futures_task::waker may cause a use-after-free if used on a type that isn't 'static
futures-task
futures_task::waker may cause a use-after-free if used on a type that isn't 'static
futures-util
MutexGuard::map can cause a data race in safe code
futures-util
MutexGuard::map can cause a data race in safe code
futures-task
futures_task::noop_waker_ref can segfault due to dereferencing a NULL pointer
futures-task
futures_task::noop_waker_ref can segfault due to dereferencing a NULL pointer
futures-util
Improper `Sync` implementation on `FuturesUnordered` in futures-utils can cause data corruption
futures-util
Improper `Sync` implementation on `FuturesUnordered` in futures-utils can cause data corruption
net2
`net2` invalidly assumes the memory layout of std::net::SocketAddr
net2
`net2` invalidly assumes the memory layout of std::net::SocketAddr
mantisbt/mantisbt
MantisBT Incorrect Authorization for bug_revision_view_page.php check
mantisbt/mantisbt
MantisBT Incorrect Authorization for bug_revision_view_page.php check
mantisbt/mantisbt
MantisBT SQL Injection via mc_project_get_users function
mantisbt/mantisbt
MantisBT SQL Injection via mc_project_get_users function
github.com/dhowden/tag
dhowden tag panic due to out-of-bounds read
github.com/dhowden/tag
dhowden tag panic due to out-of-bounds read
github.com/dhowden/tag
dhowden tag panic due to out-of-bounds read
github.com/dhowden/tag
dhowden tag panic due to out-of-bounds read
opencart/opencart
OpenCart Stored Cross-Site Scripting
opencart/opencart
OpenCart Cross-site Scripting (XSS) in the Subject field of mail.
opencart/opencart
OpenCart Cross-site Scripting (XSS) in the Subject field of mail.
woocommerce/woocommerce
WooCommerce Incorrect Authorization
woocommerce/woocommerce
WooCommerce Incorrect Authorization
dset
dset vulnerable to prototype pollution
github.com/dhowden/tag
dhowden tag panic due to out-of-bounds read
github.com/dhowden/tag
dhowden tag panic due to out-of-bounds read
deep-set
Prototype pollution vulnerability in 'deep-set'
deep-set
Prototype pollution vulnerability in 'deep-set'
flattenizer
flattenizer vulnerable to prototype pollution
shvl
shvl vulnerable to prototype pollution
arc-swap, arc-swap
Dangling reference in `access::Map` with Constant
arc-swap/ arc-swap
Dangling reference in `access::Map` with Constant
http
http before 0.13.3 vulnerable to header injection
dolibarr/dolibarr
Dolibarr authenticated Remote Code Execution
dolibarr/dolibarr
Dolibarr authenticated Remote Code Execution
github.com/opencontainers/runc
Default inheritable capabilities for linux container should be empty
github.com/opencontainers/runc
Default inheritable capabilities for linux container should be empty
jsonpickle
jsonpickle unsafe deserialization
org.keycloak:keycloak-core
Keycloak vulnerable to Server-Side Request Forgery
org.keycloak:keycloak-core
Keycloak vulnerable to Server-Side Request Forgery
QuantConnect.Common
QuantConnect Lean vulnerable to insecure deserialization
QuantConnect.Common
QuantConnect Lean vulnerable to insecure deserialization
spatie/browsershot
browsershot local file inclusion vulnerability
spatie/browsershot
browsershot local file inclusion vulnerability
