Open Source Vulnerabilities
phpmyadmin/phpmyadmin, phpmyadmin/phpmyadmin
phpMyAdmin Vulnerable to Cross-Site Scripting
phpmyadmin/phpmyadmin/ phpmyadmin/phpmyadmin
phpMyAdmin Vulnerable to Cross-Site Scripting
apache-libcloud
Apache Libcloud vulnerable to certificate impersonation
apache-libcloud
Apache Libcloud vulnerable to certificate impersonation
phpmyadmin/phpmyadmin
phpMyAdmin vulnerable to Cross-site Scripting
phpmyadmin/phpmyadmin
phpMyAdmin vulnerable to Cross-site Scripting
org.jboss.mod_cluster:mod_cluster
Improper Access Control in JBoss mod_cluster
org.jboss.mod_cluster:mod_cluster
Improper Access Control in JBoss mod_cluster
com.dotcms:dotcms
dotCMS allows remote authenticated users to execute arbitrary Java code
com.dotcms:dotcms
dotCMS allows remote authenticated users to execute arbitrary Java code
keyring
Python Keyring does not securely initialize encryption cipher
keyring
Python Keyring does not securely initialize encryption cipher
org.springframework.security:spring-security-core, org.springframework.security:spring-security-core
Improper Control of Generation of Code in Spring Security
org.springframework.security:spring-security-core/ org.springframework.security:spring-security-core
Improper Control of Generation of Code in Spring Security
symfony/symfony, symfony/symfony, symfony/symfony
Symfony Access Control Vulnerability
symfony/symfony/ symfony/symfony/ symfony/symfony
Symfony Access Control Vulnerability
org.springframework.security:spring-security-core, org.springframework.security:spring-security-core, org.springframework.security:spring-security-core
Exposure of Sensitive Information to an Unauthorized Actor in Spring Security
org.springframework.security:spring-security-core/ org.springframework.security:spring-security-core/ org.springframework.security:spring-security-core
Exposure of Sensitive Information to an Unauthorized Actor in Spring Security
moin
MoinMoin Directory Traversal vulnerability
moin
MoinMoin Multiple vulnerable to directory traversal
symfony/http-foundation, symfony/routing, symfony/security, symfony/symfony
Symfony Allows URI Restrictions Bypass Via Double-Encoded String
symfony/http-foundation/ symfony/routing/ symfony/security/ symfony/symfony
Symfony Allows URI Restrictions Bypass Via Double-Encoded String
moin
MoinMoin Cross-site scripting (XSS) vulnerability
org.jboss.ironjacamar:ironjacamar-jdbc
User confusion in IronJacamar
org.jboss.ironjacamar:ironjacamar-jdbc
User confusion in IronJacamar
phpmyadmin/phpmyadmin
phpMyAdmin Unsafe Fetching of Javascript Code
phpmyadmin/phpmyadmin
phpMyAdmin Unsafe Fetching of Javascript Code
phpmyadmin/phpmyadmin
phpMyAdmin multiple cross-site scripting vulnerabilities
phpmyadmin/phpmyadmin
phpMyAdmin multiple cross-site scripting vulnerabilities
org.apache.axis2:axis2
Apache Axis2 Vulnerable to XML Signature wrapping attack
org.apache.axis2:axis2
Apache Axis2 Vulnerable to XML Signature wrapping attack
nova
OpenStack Nova Information leak in libvirt LVM-backed instances
nova
OpenStack Nova Information leak in libvirt LVM-backed instances
org.openid4java:openid4java
OpenID4Java does not verify that Attribute Exchange (AX) information is signed
org.openid4java:openid4java
OpenID4Java does not verify that Attribute Exchange (AX) information is signed
zendframework/zendframework1, zendframework/zendframework1
Zend Framework XEE Vulnerability
zendframework/zendframework1/ zendframework/zendframework1
Zend Framework XEE Vulnerability
spree_auth_devise
spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles
spree_auth_devise
spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles
org.apache.qpid:qpid-client
Improper Authentication in Apache Qpid
org.apache.qpid:qpid-client
Improper Authentication in Apache Qpid
katello, katello
Katello uses hard coded credential
phpmyadmin/phpmyadmin, phpmyadmin/phpmyadmin
phpMyAdmin Multiple Cross-site Scripting Vulnerabilities in the Database Structure page
phpmyadmin/phpmyadmin/ phpmyadmin/phpmyadmin
phpMyAdmin Multiple Cross-site Scripting Vulnerabilities in the Database Structure page
pastescript, paste
Paste Script has improper group memberships permissions
pastescript/ paste
Paste Script has improper group memberships permissions
django, django
Django Image Field Vulnerable to Image Decompression Bombs
django/ django
Django Image Field Vulnerable to Image Decompression Bombs
django, django
Django vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer
django/ django
Django vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer
django, django
Django Allows Redirect via Data URL
moin
MoinMoin Improper Access Control
zendframework/zendframework1, zendframework/zendframework1
Zend Framework XXE Vulnerability
zendframework/zendframework1/ zendframework/zendframework1
Zend Framework XXE Vulnerability
zendframework/zendframework1, zendframework/zendframework1
Zend Framework XEE Vulnerability
zendframework/zendframework1/ zendframework/zendframework1
Zend Framework XEE Vulnerability
django, django
Django Allows Arbitrary URL Generation
django, django
XML Entity Expansion (XEE) in Django
django, django
XML External Entity (XXE) in Django
typo3/cms-core, typo3/cms-core, typo3/cms-core, typo3/cms-core
TYPO3 SQL injection vulnerability in the Extbase Framework
typo3/cms-core/ typo3/cms-core/ typo3/cms-core/ typo3/cms-core
TYPO3 SQL injection vulnerability in the Extbase Framework
typo3/cms-core, typo3/cms-core, typo3/cms-core, typo3/cms-core
TYPO3 Open redirect vulnerability in the Access tracking mechanism
typo3/cms-core/ typo3/cms-core/ typo3/cms-core/ typo3/cms-core
TYPO3 Open redirect vulnerability in the Access tracking mechanism
org.apache.rave:rave-core, org.apache.rave:rave-web, org.apache.rave:rave-portal-resources
Apache Rave information disclosure vulnerability
org.apache.rave:rave-core/ org.apache.rave:rave-web/ org.apache.rave:rave-portal-resources
Apache Rave information disclosure vulnerability
phpmyadmin/phpmyadmin
phpMyAdmin Global variables scope injection vulnerability
phpmyadmin/phpmyadmin
phpMyAdmin Global variables scope injection vulnerability
net.liftweb:lift-webkit, net.liftweb:lift-webkit_2.7.7, net.liftweb:lift-webkit_2.8.0, net.liftweb:lift-webkit_2.8.1, net.liftweb:lift-webkit_2.8.2, net.liftweb:lift-webkit_2.9.0, net.liftweb:lift-webkit_2.9.0-1, net.liftweb:lift-webkit_2.9.1
Lift Sensitive Information Disclosure
net.liftweb:lift-webkit/ net.liftweb:lift-webkit_2.7.7/ net.liftweb:lift-webkit_2.8.0/ net.liftweb:lift-webkit_2.8.1/ net.liftweb:lift-webkit_2.8.2/ net.liftweb:lift-webkit_2.9.0/ net.liftweb:lift-webkit_2.9.0-1/ net.liftweb:lift-webkit_2.9.1
Lift Sensitive Information Disclosure
cakephp/cakephp, cakephp/cakephp
CakePHPallows remote attackers to read arbitrary files via XML data containing external entity references
cakephp/cakephp/ cakephp/cakephp
CakePHPallows remote attackers to read arbitrary files via XML data containing external entity references
phpmyadmin/phpmyadmin
phpMyAdmin Multiple cross-site scripting (XSS) vulnerabilities
phpmyadmin/phpmyadmin
phpMyAdmin Multiple cross-site scripting (XSS) vulnerabilities
org.opencms:opencms-core
Alkacon OpenCMS XSS via title and requestedResource parameters
org.opencms:opencms-core
Alkacon OpenCMS XSS via title and requestedResource parameters
egroupware/egroupware, egroupware/egroupware, egroupware/egroupware
EGroupware Code Injection vulnerability
egroupware/egroupware/ egroupware/egroupware/ egroupware/egroupware
EGroupware Code Injection vulnerability
rack-cache
Rack-Cache caches sensitive headers
org.jclouds.api:eucalyptus
Eucalyptus Unauthorized Access to CC/NC Log Files
org.jclouds.api:eucalyptus
Eucalyptus Unauthorized Access to CC/NC Log Files
nova
OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
nova
OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
pyshop
pyshop vulnerable to man-in-the-middle attacks due to using HTTP to retrieve packages from the PyPI repository
pyshop
pyshop vulnerable to man-in-the-middle attacks due to using HTTP to retrieve packages from the PyPI repository
graphite-web
graphite-web is vulnerable to Remote Code Execution
graphite-web
graphite-web is vulnerable to Remote Code Execution
graphite-web
graphite-web is vulnerable to Remote Code Execution via renderLocalView function
graphite-web
graphite-web is vulnerable to Remote Code Execution via renderLocalView function
net.bull.javamelody:javamelody-core
Improper Neutralization of Input During Web Page Generation in JavaMelody
net.bull.javamelody:javamelody-core
Improper Neutralization of Input During Web Page Generation in JavaMelody
