Open Source Vulnerabilities
zodb3
Zope Object Database Denial of Service vulnerability
zodb3
Zope Object Database Denial of Service vulnerability
phpmyadmin/phpmyadmin
phpMyAdmin allows remote attackers to bypass authentication and obtain sensitive information
phpmyadmin/phpmyadmin
phpMyAdmin allows remote attackers to bypass authentication and obtain sensitive information
phpmyadmin/phpmyadmin
phpMyAdmin unsafely handles temporary files
phpmyadmin/phpmyadmin
phpMyAdmin unsafely handles temporary files
pywebdav
PyWebDAV SQL Injection vulnerability
org.apache.struts:struts2-parent
Apache Struts Multiple XSS Vulnerabilities
org.apache.struts:struts2-parent
Apache Struts Multiple XSS Vulnerabilities
fabric
Fabric vulnerable to symlink attack on tmp files
apache-libcloud
Apache Libcloud does not verify SSL certificates for HTTPS connections
apache-libcloud
Apache Libcloud does not verify SSL certificates for HTTPS connections
org.apache.httpcomponents:httpclient
Exposure of Sensitive Information to an Unauthorized Actor in Apache HttpClient
org.apache.httpcomponents:httpclient
Exposure of Sensitive Information to an Unauthorized Actor in Apache HttpClient
zope2, zope2
Zope Command Execution Vulnerability
plone, plone, plone
Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable
plone/ plone/ plone
Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable
com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer
OWASP HTML Sanitizer allows redirecting to an arbitrary URL when JavaScript is disabled
com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer
OWASP HTML Sanitizer allows redirecting to an arbitrary URL when JavaScript is disabled
joomla/joomla-cms
Joomla! vulnerable to Cross-site Scripting
joomla/joomla-cms
Joomla! vulnerable to Cross-site Scripting
celery, celery, celery
Celery local privilege escalation vulnerability
celery/ celery/ celery
Celery local privilege escalation vulnerability
org.apache.activemq:activemq-core
Denial of Service in Apache ActiveMQ
org.apache.activemq:activemq-core
Denial of Service in Apache ActiveMQ
org.apache.struts:struts2-core
Cross-site Scripting in Apache Struts
org.apache.struts:struts2-core
Cross-site Scripting in Apache Struts
virtualenv
Virtualenv Allows Symlink Attack on /tmp/
phpmyadmin/phpmyadmin
phpMyAdmin Open Redirect in redirector
phpmyadmin/phpmyadmin
phpMyAdmin Open Redirect in redirector
org.apache.tomcat:tomcat, org.apache.tomcat:tomcat
Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests
org.apache.tomcat:tomcat/ org.apache.tomcat:tomcat
Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests
ejabberd, ejabberd
Ejabberd DoS via malformed stanza
ezyang/htmlpurifier
HTML Purifier allows remote attackers to obtain sensitive information
ezyang/htmlpurifier
HTML Purifier allows remote attackers to obtain sensitive information
cakephp/cakephp
CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file
cakephp/cakephp
CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file
spree
Spree does not properly restrict the use of a hash to provide values for a model's attributes
spree
Spree does not properly restrict the use of a hash to provide values for a model's attributes
spree
Spree uses a hardcoded hash value
dompdf/dompdf
DOMPDF Remote File Inclusion Vulnerability
roundup
Roundup Cross-site Scripting (XSS) vulnerability
typo3/cms, typo3/cms, typo3/cms
TYPO3 Remote File Disclosure vulnerability in the jumpUrl mechanism
typo3/cms/ typo3/cms/ typo3/cms
TYPO3 Remote File Disclosure vulnerability in the jumpUrl mechanism
org.apache.sling:org.apache.sling.servlets.post
Apache Sling POST Servlets Denial of Service Vulnerability
org.apache.sling:org.apache.sling.servlets.post
Apache Sling POST Servlets Denial of Service Vulnerability
cobbler
Cobbler subject to Command Injection
chef
Chef Improper Access Control vulnerability
nova
OpenStack Nova Arbitrary file injection/corruption through directory traversal issues
nova
OpenStack Nova Arbitrary file injection/corruption through directory traversal issues
nova
OpenStack Nova Directory traversal vulnerability
phpmyadmin/phpmyadmin
phpMyAdmin Multiple XSS Vulnerabilities
phpmyadmin/phpmyadmin
phpMyAdmin Multiple XSS Vulnerabilities
nova
OpenStack Nova Scheduler denial of service through scheduler_hints
nova
OpenStack Nova Scheduler denial of service through scheduler_hints
elixir
Elixir can leak information due to weak use of crypto
elixir
Elixir can leak information due to weak use of crypto
com.caucho:resin
Caucho Quercus, as distributed in Resin, does not properly implement the `==` operator for comparisons
com.caucho:resin
Caucho Quercus, as distributed in Resin, does not properly implement the `==` operator for comparisons
com.caucho:resin
Caucho Quercus, as distributed in Resin, overwrites entries in SERVER superglobal array on basis of POST parameters
com.caucho:resin
Caucho Quercus, as distributed in Resin, overwrites entries in SERVER superglobal array on basis of POST parameters
com.caucho:resin
Caucho Quercus, as distributed in Resin, does not properly handle unspecified characters in the names of variables
com.caucho:resin
Caucho Quercus, as distributed in Resin, does not properly handle unspecified characters in the names of variables
tornado
Tornado CRLF injection vulnerability
typo3/cms, typo3/cms, typo3/cms
Typo3 Backend XSS Vulnerabilities
typo3/cms/ typo3/cms/ typo3/cms
Typo3 Backend XSS Vulnerabilities
typo3/cms, typo3/cms, typo3/cms
TYPO3 allows remote attackers to obtain the database name via a direct request
typo3/cms/ typo3/cms/ typo3/cms
TYPO3 allows remote attackers to obtain the database name via a direct request
typo3/cms, typo3/cms, typo3/cms
Typo3 API XSS Vulnerabilities
typo3/cms/ typo3/cms/ typo3/cms
Typo3 API XSS Vulnerabilities
typo3/cms, typo3/cms, typo3/cms
Typo3 Extbase Framework Unsafe Deserialization
typo3/cms/ typo3/cms/ typo3/cms
Typo3 Extbase Framework Unsafe Deserialization
keystone
OpenStack Keystone token expiration issues
keystone
OpenStack Keystone Allows Remote User Account Creation
keystone
OpenStack Keystone Allows Remote User Account Creation
beaker
Beaker Sensitive Information Disclosure vulnerability
beaker
Beaker Sensitive Information Disclosure vulnerability
silverstripe/framework, silverstripe/framework
Silverstripe XSS Vulnerabilities
silverstripe/framework/ silverstripe/framework
Silverstripe XSS Vulnerabilities
silverstripe/cms
Silverstripe CMS Arbitrary Code Execution
silverstripe/cms
Silverstripe CMS Arbitrary Code Execution
impresspages/impresspages
ImpressPages CMS eval injection vulnerability
impresspages/impresspages
ImpressPages CMS eval injection vulnerability
org.postgresql:postgresql
Unescaped parameters in the PostgreSQL JDBC driver
org.postgresql:postgresql
Unescaped parameters in the PostgreSQL JDBC driver
