Open Source Vulnerabilities
needrestart, needrestart, needrestart, needrestart
Server-Side Request Forgery (SSRF) in jgraph/drawio
openldap, openldap, openldap
openldap vulnerability
clamav, clamav, clamav
clamav vulnerabilities
chromium-browser-stable
Updated chromium-browser-stable packages fix security vulnerability
chromium-browser-stable
Updated chromium-browser-stable packages fix security vulnerability
Server-Side Request Forgery (SSRF) in jgraph/drawio
Apache ShenYu (incubating) Regular expression denial of service
Apache ShenYu (incubating) Regular expression denial of service
e2fsprogs, e2fsprogs, e2fsprogs, e2fsprogs, e2fsprogs, e2fsprogs, e2fsprogs
Security update for e2fsprogs
e2fsprogs/ e2fsprogs/ e2fsprogs/ e2fsprogs/ e2fsprogs/ e2fsprogs/ e2fsprogs
Security update for e2fsprogs
nodejs8, nodejs8
Security update for nodejs8
pidgin, pidgin
Security update for pidgin
moin
MoinMoin improper access control on the included page for the rst parser
moin
MoinMoin improper access control on the included page for the rst parser
phpbb/phpbb
phpBB vulnerable to sensitive information disclosure
phpbb/phpbb
phpBB vulnerable to sensitive information disclosure
moin
MoinMoin Denial of Service vulnerability via password_checker function
moin
MoinMoin Denial of Service vulnerability via password_checker function
org.apache.struts:struts2-core, org.apache.struts:struts2-core
Apache Struts is vulnerable to Cross-site Scripting
org.apache.struts:struts2-core/ org.apache.struts:struts2-core
Apache Struts is vulnerable to Cross-site Scripting
org.apache.struts:struts2-core, org.apache.struts:struts2-core
Apache Struts directory traversal vulnerability
org.apache.struts:struts2-core/ org.apache.struts:struts2-core
Apache Struts directory traversal vulnerability
org.geoserver:gs-main, org.geoserver.web:gs-web-app
PartialBufferOutputStream2 flush issues
org.geoserver:gs-main/ org.geoserver.web:gs-web-app
PartialBufferOutputStream2 flush issues
phpbb/phpbb
phpBB vulnerability related to use of "forum id" in circumstances related to a "global announcement."
phpbb/phpbb
phpBB vulnerability related to use of "forum id" in circumstances related to a "global announcement."
org.apache.myfaces.core:myfaces-core-module, org.apache.myfaces.core:myfaces-core-module
Apache MyFaces Cross-site Scripting vulnerability
org.apache.myfaces.core:myfaces-core-module/ org.apache.myfaces.core:myfaces-core-module
Apache MyFaces Cross-site Scripting vulnerability
org.dojotoolkit:dojo, org.dojotoolkit:dojo, org.dojotoolkit:dojo, org.dojotoolkit:dojo, org.dojotoolkit:dojo
Dojo Open Redirect vulnerability
org.dojotoolkit:dojo/ org.dojotoolkit:dojo/ org.dojotoolkit:dojo/ org.dojotoolkit:dojo/ org.dojotoolkit:dojo
Dojo Open Redirect vulnerability
plone
Plone Cross-site Scripting vulnerability in PortalTransforms
plone
Plone Cross-site Scripting vulnerability in PortalTransforms
ezyang/htmlpurifier
HTML Purifier Cross-site Scripting (XSS) vulnerability
ezyang/htmlpurifier
HTML Purifier Cross-site Scripting (XSS) vulnerability
python-cjson
Improper Restriction of Operations within the Bounds of a Memory Buffer in python-cjson
python-cjson
Improper Restriction of Operations within the Bounds of a Memory Buffer in python-cjson
moin, moin
MoinMoin cross-site scripting (XSS) vulnerability
moin/ moin
MoinMoin cross-site scripting (XSS) vulnerability
moin, moin, moin
MoinMoin Cross-site Scripting (XSS) vulnerability
moin/ moin/ moin
MoinMoin Cross-site Scripting (XSS) vulnerability
moin
MoinMoin cross-site scripting (XSS) vulnerability
mako
Mako contains Cross-site Scripting vulnerability
zope, zope
Zope Denial of Service (DoS) vulnerability in ZServer
zope/ zope
Zope Denial of Service (DoS) vulnerability in ZServer
phpmyadmin/phpmyadmin
phpMyAdmin Cross-site Scripting vulnerability
phpmyadmin/phpmyadmin
phpMyAdmin Cross-site Scripting vulnerability
drupal/drupal
Drupal cross-site scripting vulnerability via actions feature and trigger module
drupal/drupal
Drupal cross-site scripting vulnerability via actions feature and trigger module
in2code/powermail
powermail extension for TYPO3 vulnerable to SQL Injection
in2code/powermail
powermail extension for TYPO3 vulnerable to SQL Injection
pyftpdlib
Concurrent Execution using Shared Resource with Improper Synchronization in pyftpdlib
pyftpdlib
Concurrent Execution using Shared Resource with Improper Synchronization in pyftpdlib
pyftpdlib
Improper input validation in pyftpdlib
pyftpdlib
Directory traversal in pyftpdlib
pyftpdlib
Improper Authentication in pyftpdlib
typo3/cms-backend, typo3/cms-backend, typo3/cms-backend
TYPO3 cross-site scripting (XSS) vulnerability in the RemoveXSS function and the backend
typo3/cms-backend/ typo3/cms-backend/ typo3/cms-backend
TYPO3 cross-site scripting (XSS) vulnerability in the RemoveXSS function and the backend
org.apache.myfaces.shared:myfaces-shared-core, org.apache.myfaces.shared:myfaces-shared-core, org.apache.myfaces.shared:myfaces-shared-core, org.apache.myfaces.core:myfaces-impl, org.apache.myfaces.core:myfaces-impl, org.apache.myfaces.core:myfaces-impl
Improper Authentication in Apache MyFaces
org.apache.myfaces.shared:myfaces-shared-core/ org.apache.myfaces.shared:myfaces-shared-core/ org.apache.myfaces.shared:myfaces-shared-core/ org.apache.myfaces.core:myfaces-impl/ org.apache.myfaces.core:myfaces-impl/ org.apache.myfaces.core:myfaces-impl
Improper Authentication in Apache MyFaces
cobbler
Cobbler is vulnerable to code injection
paste
Paste is vulnerable to Cross-site Scripting via vectors involving a 404 status code
paste
Paste is vulnerable to Cross-site Scripting via vectors involving a 404 status code
org.drools:drools-core
Drools Improper Input Validation vulnerability allows remote attackers to execute arbitrary code in JBoss EAP
org.drools:drools-core
Drools Improper Input Validation vulnerability allows remote attackers to execute arbitrary code in JBoss EAP
cakephp/cakephp
CakePHP allows remote attackers to modify internal Cake cache and execute arbitrary code
cakephp/cakephp
CakePHP allows remote attackers to modify internal Cake cache and execute arbitrary code
