Open Source Vulnerabilities
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Inbound TCP Agent Protocol/3 authentication bypass in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Inbound TCP Agent Protocol/3 authentication bypass in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Memory usage graphs accessible to anyone with Overall/Read
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Memory usage graphs accessible to anyone with Overall/Read
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Non-constant time comparison of inbound TCP agent connection secret
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Non-constant time comparison of inbound TCP agent connection secret
com.liferay.portal:release.portal.bom
Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet
com.liferay.portal:release.portal.bom
Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet
dolibarr/dolibarr
Dolibarr Improper Restriction of Excessive Authentication Attempts
dolibarr/dolibarr
Dolibarr Improper Restriction of Excessive Authentication Attempts
typo3/cms, typo3/cms
Typo3 Cross-Site Scripting in Flash component (ELTS)
typo3/cms/ typo3/cms
Typo3 Cross-Site Scripting in Flash component (ELTS)
dolibarr/dolibarr
Dolibarr cross-site scripting (XSS) vulnerability
dolibarr/dolibarr
Dolibarr cross-site scripting (XSS) vulnerability
zendframework/zend-http, zendframework/zend-http, zendframework/zendframework, zendframework/zendframework, zendframework/zendframework1, zendframework/zend-http
Zenario CMS vulnerable to CRLF injection
zendframework/zend-http/ zendframework/zend-http/ zendframework/zendframework/ zendframework/zendframework/ zendframework/zendframework1/ zendframework/zend-http
Zenario CMS vulnerable to CRLF injection
codecov
Improper Neutralization of Special Elements in Output Used by a Downstream Component in Codecov
codecov
Improper Neutralization of Special Elements in Output Used by a Downstream Component in Codecov
plone, plone, plone
Plone Open Redirect Vulnerability
plone
Plone cross site scripting (XSS)
plone, plone, plone
Plone allows weak passwords
plone
Plone SQL Injection Vulnerability
plone, plone-app-contenttypes
Plone Unauthenticated Write Vulnerability
plone/ plone-app-contenttypes
Plone Unauthenticated Write Vulnerability
plone-restapi, plone
Plone Privilege Escallation
UmbracoCMS.Core
Umbraco CMS vulnerable to CSRF
io.undertow:undertow-core
Undertow vulnerable to Uncontrolled Resource Consumption
io.undertow:undertow-core
Undertow vulnerable to Uncontrolled Resource Consumption
waitress
Duplicate Advisory: Inconsistent Interpretation of HTTP Requests in Waitress
waitress
Duplicate Advisory: Inconsistent Interpretation of HTTP Requests in Waitress
papercrop
papercrop does not properly handle crop input
salt
SaltStack Salt is vulnerable to command injection
phpbb/phpbb
phpBB Cross-Site Request Forgery (CSRF)
org.jenkins-ci.ruby-plugins:gitlab-hook
Reflected XSS vulnerability in Jenkins gitlab-hook Plugin
org.jenkins-ci.ruby-plugins:gitlab-hook
Reflected XSS vulnerability in Jenkins gitlab-hook Plugin
org.jenkins-ci.plugins:cloudbees-jenkins-advisor
Missing permission checks in Health Advisor by CloudBees Plugin
org.jenkins-ci.plugins:cloudbees-jenkins-advisor
Missing permission checks in Health Advisor by CloudBees Plugin
org.jenkins-ci.plugins:sounds
Missing permission checks in Jenkins Sounds Plugin allow OS command execution
org.jenkins-ci.plugins:sounds
Missing permission checks in Jenkins Sounds Plugin allow OS command execution
org.jenkins-ci.plugins:robot
XXE vulnerability in Jenkins Robot Framework Plugin
org.jenkins-ci.plugins:robot
XXE vulnerability in Jenkins Robot Framework Plugin
com.redgate.plugins.redgatesqlci:redgate-sql-ci
Redgate SQL Change Automation Plugin stored credentials in plain text
com.redgate.plugins.redgatesqlci:redgate-sql-ci
Redgate SQL Change Automation Plugin stored credentials in plain text
org.jenkins-ci.plugins:sounds
CSRF vulnerability in Jenkins Sounds Plugin allow OS command execution
org.jenkins-ci.plugins:sounds
CSRF vulnerability in Jenkins Sounds Plugin allow OS command execution
org.jenkins-ci.plugins:ec2
Missing permission checks in Jenkins Amazon EC2 Plugin
org.jenkins-ci.plugins:ec2
Missing permission checks in Jenkins Amazon EC2 Plugin
org.jenkins-ci.plugins:ec2
CSRF vulnerability in Jenkins Amazon EC2 Plugin
org.jenkins-ci.plugins:ec2
CSRF vulnerability in Jenkins Amazon EC2 Plugin
org.jenkins-ci.plugins:cloudbees-jenkins-advisor
CSRF vulnerability in Health Advisor by CloudBees Plugin
org.jenkins-ci.plugins:cloudbees-jenkins-advisor
CSRF vulnerability in Health Advisor by CloudBees Plugin
Microsoft.AspNetCore.All, Microsoft.AspNetCore.App, Microsoft.AspNetCore.App, Microsoft.AspNetCore.App, Microsoft.AspNetCore.Http.Connections, Microsoft.AspNetCore.App.Runtime.linux-arm, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-x64, Microsoft.AspNetCore.App.Runtime.linux-x64, Microsoft.AspNetCore.App.Runtime.osx-x64, Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-x86
Denial of service in ASP.NET Core
Microsoft.AspNetCore.All/ Microsoft.AspNetCore.App/ Microsoft.AspNetCore.App/ Microsoft.AspNetCore.App/ Microsoft.AspNetCore.Http.Connections/ Microsoft.AspNetCore.App.Runtime.linux-arm/ Microsoft.AspNetCore.App.Runtime.linux-arm64/ Microsoft.AspNetCore.App.Runtime.linux-musl-x64/ Microsoft.AspNetCore.App.Runtime.linux-x64/ Microsoft.AspNetCore.App.Runtime.osx-x64/ Microsoft.AspNetCore.App.Runtime.win-arm/ Microsoft.AspNetCore.App.Runtime.win-x64/ Microsoft.AspNetCore.App.Runtime.win-x86
Denial of service in ASP.NET Core
Microsoft.AspNetCore.All, Microsoft.AspNetCore.App, Microsoft.AspNetCore.App, Microsoft.AspNetCore.App, Microsoft.AspNetCore.Http.Connections, Microsoft.AspNetCore.App.Runtime.linux-arm, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-x64, Microsoft.AspNetCore.App.Runtime.linux-x64, Microsoft.AspNetCore.App.Runtime.osx-x64, Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-x86
Remote code execution in ASP.NET Core
Microsoft.AspNetCore.All/ Microsoft.AspNetCore.App/ Microsoft.AspNetCore.App/ Microsoft.AspNetCore.App/ Microsoft.AspNetCore.Http.Connections/ Microsoft.AspNetCore.App.Runtime.linux-arm/ Microsoft.AspNetCore.App.Runtime.linux-arm64/ Microsoft.AspNetCore.App.Runtime.linux-musl-arm64/ Microsoft.AspNetCore.App.Runtime.linux-musl-x64/ Microsoft.AspNetCore.App.Runtime.linux-x64/ Microsoft.AspNetCore.App.Runtime.osx-x64/ Microsoft.AspNetCore.App.Runtime.win-arm/ Microsoft.AspNetCore.App.Runtime.win-x64/ Microsoft.AspNetCore.App.Runtime.win-x86
Remote code execution in ASP.NET Core
Microsoft.WindowsDesktop.App.Ref, Microsoft.WindowsDesktop.App.Ref, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x64
Remote code execution in Microsoft.WindowsDesktop.App.Ref
Microsoft.WindowsDesktop.App.Ref/ Microsoft.WindowsDesktop.App.Ref/ Microsoft.WindowsDesktop.App.Runtime.win-x86/ Microsoft.WindowsDesktop.App.Runtime.win-x86/ Microsoft.WindowsDesktop.App.Runtime.win-x64/ Microsoft.WindowsDesktop.App.Runtime.win-x64
Remote code execution in Microsoft.WindowsDesktop.App.Ref
magento/core
Magento arbitrary PHP code execution via the productData parameter
magento/core
Magento arbitrary PHP code execution via the productData parameter
pyamf
PyAMF vulnerable to XML external entity (XXE)
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
XML external entity (XXE) vulnerability in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
XML external entity (XXE) vulnerability in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
XML external entity (XXE) vulnerability in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
XML external entity (XXE) vulnerability in Jenkins
k8s.io/ingress-nginx
Kubernetes ingress exposes sensitive information
k8s.io/ingress-nginx
Kubernetes ingress exposes sensitive information
phpmyadmin/phpmyadmin, phpmyadmin/phpmyadmin
phpMyAdmin SQL injection in user accounts page
phpmyadmin/phpmyadmin/ phpmyadmin/phpmyadmin
phpMyAdmin SQL injection in user accounts page
org.keycloak:keycloak-core
keycloak vulnerable to unauthorized login via mail server setup
org.keycloak:keycloak-core
keycloak vulnerable to unauthorized login via mail server setup
moodle/moodle, moodle/moodle, moodle/moodle
Moodle does not revoke role capabilities correctly
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle does not revoke role capabilities correctly
hashbrown-cms
HashBrown CMS Directory Traversal
pillow
Buffer Copy without Checking Size of Input in Pillow
pillow
Buffer Copy without Checking Size of Input in Pillow
org.springframework:spring-web
Pivotal Spring Framework contains unsafe Java deserialization methods
org.springframework:spring-web
Pivotal Spring Framework contains unsafe Java deserialization methods
bolt/bolt
Bolt Cross-site Scripting via the slug, teaser or title parameters
bolt/bolt
Bolt Cross-site Scripting via the slug, teaser or title parameters
mikehaertl/php-shellcommand
php-shellcommand command injection vulnerability
mikehaertl/php-shellcommand
php-shellcommand command injection vulnerability
com.yahoo.athenz:athenz
Athenz vulnerable to Open Redirect
com.yahoo.athenz:athenz
Athenz vulnerable to Open Redirect
