Open Source Vulnerabilities
github.com/mattermost/mattermost-server
Mattermost Server exposes sensitive information via its System Console UI
github.com/mattermost/mattermost-server
Mattermost Server exposes sensitive information via its System Console UI
github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to XSS through lack of link relationship attributes `noreferrer` and `noopener`
github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to XSS through lack of link relationship attributes `noreferrer` and `noopener`
github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to XSS through customizable theme color-code values
github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to XSS through customizable theme color-code values
github.com/mattermost/mattermost-server
Mattermost Server vulnerable to Cross-site Scripting through file preview feature
github.com/mattermost/mattermost-server
Mattermost Server vulnerable to Cross-site Scripting through file preview feature
dolibarr/dolibarr
Dolibarr SQL injection vulnerability in accountancy/customer/card.php
dolibarr/dolibarr
Dolibarr SQL injection vulnerability in accountancy/customer/card.php
omero-web
OMERO-web Sensitive Data Exposure
mjml
MJML vulnerable to path traversal
kumbiaphp/kumbiapp
KumbiaPHP Cross-site Scripting
org.springframework.batch:spring-batch-core
Deserialization of Untrusted Data in Spring Batch
org.springframework.batch:spring-batch-core
Deserialization of Untrusted Data in Spring Batch
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Fails to Sanitize API Data
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Fails to Sanitize API Data
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Arbitrary Code Execution
com.liferay.portal:release.portal.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom/ com.liferay.portal:release.dxp.bom
Liferay Portal and Liferay DXP Vulnerable to Arbitrary Code Execution
cinder, cinder, cinder, os-brick, os-brick, os-brick
Openstack cinder Improper handling of ScaleIO backend credentials
cinder/ cinder/ cinder/ os-brick/ os-brick/ os-brick
Openstack cinder Improper handling of ScaleIO backend credentials
Microsoft.ChakraCore
ChakraCore RCE Vulnerability
opencart/opencart
OpenCart Cross-site Scripting
verbb/comments
Comments plugin Cross-Site Request Forgery (CSRF)
verbb/comments
Comments plugin Cross-Site Request Forgery (CSRF)
verbb/comments
Comments plugin stored Cross-site Scripting (XSS) via an asset volume name
verbb/comments
Comments plugin stored Cross-site Scripting (XSS) via an asset volume name
verbb/comments
Comments plugin stored Cross-site Scripting via a guest name
verbb/comments
Comments plugin stored Cross-site Scripting via a guest name
org.jenkins-ci.plugins:swarm
CSRF vulnerability in Jenkins Swarm Plugin
org.jenkins-ci.plugins:swarm
CSRF vulnerability in Jenkins Swarm Plugin
org.jenkins-ci.plugins:play-autotest-plugin
OS command injection vulnerability in Jenkins Play Framework Plugin
org.jenkins-ci.plugins:play-autotest-plugin
OS command injection vulnerability in Jenkins Play Framework Plugin
hudson.plugins:project-inheritance
Missing permission check in Jenkins Project Inheritance Plugin
hudson.plugins:project-inheritance
Missing permission check in Jenkins Project Inheritance Plugin
org.jenkins-ci.plugins:svn-partial-release-mgr
XSS vulnerability in Jenkins Subversion Partial Release Manager Plugin
org.jenkins-ci.plugins:svn-partial-release-mgr
XSS vulnerability in Jenkins Subversion Partial Release Manager Plugin
hudson.plugins:project-inheritance
Missing permission check in Jenkins Project Inheritance Plugin
hudson.plugins:project-inheritance
Missing permission check in Jenkins Project Inheritance Plugin
org.jenkins-ci.plugins:swarm
Improper permission checks in Jenkins Swarm Plugin
org.jenkins-ci.plugins:swarm
Improper permission checks in Jenkins Swarm Plugin
io.jenkins.plugins:echarts-api
Stored XSS vulnerability in Jenkins ECharts API Plugin
io.jenkins.plugins:echarts-api
Stored XSS vulnerability in Jenkins ECharts API Plugin
org.jenkins-ci.plugins:script-security
Improper Neutralization of Input During Web Page Generation in Jenkins Script Security Plugin
org.jenkins-ci.plugins:script-security
Improper Neutralization of Input During Web Page Generation in Jenkins Script Security Plugin
org.jenkins-ci.plugins:selenium
Complete lack of CSRF protection in Jenkins Selenium Plugin can lead to OS command injection
org.jenkins-ci.plugins:selenium
Complete lack of CSRF protection in Jenkins Selenium Plugin can lead to OS command injection
org.jenkins-ci.plugins:compact-columns
Stored XSS vulnerability in Jenkins Compact Columns Plugin
org.jenkins-ci.plugins:compact-columns
Stored XSS vulnerability in Jenkins Compact Columns Plugin
io.jenkins.plugins:echarts-api
Stored XSS vulnerability in Jenkins ECharts API Plugin
io.jenkins.plugins:echarts-api
Stored XSS vulnerability in Jenkins ECharts API Plugin
github.com/containernetworking/plugins
containernetworking/plugins vulnerable to MitM attacks
github.com/containernetworking/plugins
containernetworking/plugins vulnerable to MitM attacks
wp-premium/gravityforms
Gravity Forms plugin leak hashed passwords
wp-premium/gravityforms
Gravity Forms plugin leak hashed passwords
mediawiki/core
MediaWiki Open Redirect vulnerability
github.com/grafana/grafana
Grafana XSS via a column style
bbpress/bbpress
bbPress unauthenticated privilege-escalation
bbpress/bbpress
bbPress unauthenticated privilege-escalation
forkcms/forkcms
Fork CMS Cross-site Scripting Vulnerability
forkcms/forkcms
Fork CMS Cross-site Scripting Vulnerability
verbb/knock-knock
Knock Knock plugin Open redirection vulnerability
verbb/knock-knock
Knock Knock plugin Open redirection vulnerability
centreon/centreon, centreon/centreon, centreon/centreon, centreon/centreon
Centreon Sensitive Data Exposure vulnerability
centreon/centreon/ centreon/centreon/ centreon/centreon/ centreon/centreon
Centreon Sensitive Data Exposure vulnerability
bbpress/bbpress
bbPress stored Cross-Site Scripting (XSS) vulnerability in the Forum creation section
bbpress/bbpress
bbPress stored Cross-Site Scripting (XSS) vulnerability in the Forum creation section
verbb/knock-knock
Knock Knock plugin IP Whitelist bypass via an X-Forwarded-For HTTP header
verbb/knock-knock
Knock Knock plugin IP Whitelist bypass via an X-Forwarded-For HTTP header
verbb/image-resizer
Image Resizer Cross-Site Request Forgery (CSRF)
verbb/image-resizer
Image Resizer Cross-Site Request Forgery (CSRF)
verbb/image-resizer
Image Resizer Cross-site Scripting (XSS) in the Bulk Resize action
verbb/image-resizer
Image Resizer Cross-site Scripting (XSS) in the Bulk Resize action
github.com/grafana/grafana
Grafana XSS via the OpenTSDB datasource
github.com/grafana/grafana
Grafana XSS via the OpenTSDB datasource
meinheld
meinheld vulnerable to HTTP Request Smuggling
Microsoft.AspNetCore.App.Runtime.linux-arm, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-x64, Microsoft.AspNetCore.App.Runtime.linux-x64, Microsoft.AspNetCore.App.Runtime.osx-x64, Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-x86
ASP.NET Core Denial of Service Vulnerability
Microsoft.AspNetCore.App.Runtime.linux-arm/ Microsoft.AspNetCore.App.Runtime.linux-arm64/ Microsoft.AspNetCore.App.Runtime.linux-musl-arm64/ Microsoft.AspNetCore.App.Runtime.linux-musl-x64/ Microsoft.AspNetCore.App.Runtime.linux-x64/ Microsoft.AspNetCore.App.Runtime.osx-x64/ Microsoft.AspNetCore.App.Runtime.win-arm/ Microsoft.AspNetCore.App.Runtime.win-x64/ Microsoft.AspNetCore.App.Runtime.win-x86
ASP.NET Core Denial of Service Vulnerability
Microsoft.NETCore.App, Microsoft.NETCore.App.Runtime.linux-arm, Microsoft.NETCore.App.Runtime.linux-arm64, Microsoft.NETCore.App.Runtime.linux-musl-arm64, Microsoft.NETCore.App.Runtime.linux-musl-x64, Microsoft.NETCore.App.Runtime.linux-x64, Microsoft.NETCore.App.Runtime.osx-x64, Microsoft.NETCore.App.Runtime.rhel.6-x64, Microsoft.NETCore.App.Runtime.win-arm, Microsoft.NETCore.App.Runtime.win-arm64, Microsoft.NETCore.App.Runtime.win-x64, Microsoft.NETCore.App.Runtime.win-x86
.NET Core & .NET Framework Denial of Service Vulnerability
Microsoft.NETCore.App/ Microsoft.NETCore.App.Runtime.linux-arm/ Microsoft.NETCore.App.Runtime.linux-arm64/ Microsoft.NETCore.App.Runtime.linux-musl-arm64/ Microsoft.NETCore.App.Runtime.linux-musl-x64/ Microsoft.NETCore.App.Runtime.linux-x64/ Microsoft.NETCore.App.Runtime.osx-x64/ Microsoft.NETCore.App.Runtime.rhel.6-x64/ Microsoft.NETCore.App.Runtime.win-arm/ Microsoft.NETCore.App.Runtime.win-arm64/ Microsoft.NETCore.App.Runtime.win-x64/ Microsoft.NETCore.App.Runtime.win-x86
.NET Core & .NET Framework Denial of Service Vulnerability
Microsoft.ChakraCore
ChakraCore RCE Vulnerability
Microsoft.ChakraCore
ChakraCore Remote Code Execution Vulnerability
Microsoft.ChakraCore
ChakraCore Remote Code Execution Vulnerability
moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle
Moodle vulnerable to RCE
moodle/moodle/ moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle vulnerable to RCE
microweber/microweber
Microweber allows Unrestricted File Upload
microweber/microweber
Microweber allows Unrestricted File Upload
dolibarr/dolibarr
Dolibarr Stored Cross-site Scripting via file upload
dolibarr/dolibarr
Dolibarr Stored Cross-site Scripting via file upload
