Open Source Vulnerabilities
org.opensaml:opensaml, org.opensaml:opensaml
Improper Authentication in OpenSAML
org.opensaml:opensaml/ org.opensaml:opensaml
Improper Authentication in OpenSAML
setuptools
Setuptools vulnerable to Man-in-the-middle attacks
setuptools
Setuptools vulnerable to Man-in-the-middle attacks
bvbmedia/multishop
Multishop extension for TYPO3 has SQL Injection vulnerability
bvbmedia/multishop
Multishop extension for TYPO3 has SQL Injection vulnerability
friendsofsymfony/user-bundle, friendsofsymfony/user-bundle
FriendsOfSymfony FOSUserBundle denial of service via login form
friendsofsymfony/user-bundle/ friendsofsymfony/user-bundle
FriendsOfSymfony FOSUserBundle denial of service via login form
org.springframework.security:spring-security-core, org.springframework.security:spring-security-core
Concurrent Execution using Shared Resource with Improper Synchronization in Spring Security
org.springframework.security:spring-security-core/ org.springframework.security:spring-security-core
Concurrent Execution using Shared Resource with Improper Synchronization in Spring Security
org.apache.shindig:shindig-php
Apache Shindig PHP Sensitive Information Disclosure
org.apache.shindig:shindig-php
Apache Shindig PHP Sensitive Information Disclosure
org.apache.sling:org.apache.sling.auth.core
Apache Sling Auth Core bundle vulnerable to Open Redirection
org.apache.sling:org.apache.sling.auth.core
Apache Sling Auth Core bundle vulnerable to Open Redirection
pycrypto
PyCrypto does not properly reseed PRNG before allowing access
pycrypto
PyCrypto does not properly reseed PRNG before allowing access
rack, rack, rack, org.jruby:jruby-parent
Rack Gem Subject to Denial of Service via Hash Collisions
rack/ rack/ rack/ org.jruby:jruby-parent
Rack Gem Subject to Denial of Service via Hash Collisions
swift
OpenStack Swift allows authenticated users to cause a denial of service
swift
OpenStack Swift allows authenticated users to cause a denial of service
cinder
OpenStack Cinder LVMVolumeDriver does not zero deleted snapshots
cinder
OpenStack Cinder LVMVolumeDriver does not zero deleted snapshots
nova
OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
nova
OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
keystone
OpenStack Identity (Keystone) allows remote attackers to bypass intended access restrictions via revoked PKI token
keystone
OpenStack Identity (Keystone) allows remote attackers to bypass intended access restrictions via revoked PKI token
apache-solr-for-typo3/solr
Apache Solr for TYPO3 (solr) extension is vulnerable to Cross-site scripting (XSS)
apache-solr-for-typo3/solr
Apache Solr for TYPO3 (solr) extension is vulnerable to Cross-site scripting (XSS)
apache-solr-for-typo3/solr
Apache Solr for TYPO3 (solr) extension is vulnerable to Insecure Unserialize
apache-solr-for-typo3/solr
Apache Solr for TYPO3 (solr) extension is vulnerable to Insecure Unserialize
salt
SaltStack Privilege Escalation vulnerability
tikiwiki/tiki-manager, tikiwiki/tiki-manager, tikiwiki/tiki-manager, tikiwiki/tiki-manager
Tiki Wiki CMS Groupware Cross-site scripting (XSS) vulnerability
tikiwiki/tiki-manager/ tikiwiki/tiki-manager/ tikiwiki/tiki-manager/ tikiwiki/tiki-manager
Tiki Wiki CMS Groupware Cross-site scripting (XSS) vulnerability
nova
OpenStack Compute Nova Improper Access Control
salt
Minion identity not validated in saltstack
salt
SaltStack insecurely uses /tmp
salt
SaltStack MITM SSH attack in salt-ssh
salt
Salt has insufficient argument validation in several modules
salt
Salt has insufficient argument validation in several modules
phpmyadmin/phpmyadmin
phpMyAdmin Remote Code Execution
trytond
Tryton Directory Traversal vulnerability
org.apache.struts:struts2-core
Apache Struts is vulnerable to Cross-site Scripting
org.apache.struts:struts2-core
Apache Struts is vulnerable to Cross-site Scripting
keystone
OpenStack Keystone Improper Authentication vulnerability
keystone
OpenStack Keystone Improper Authentication vulnerability
zendframework/zendframework1, zendframework/zendframework1
Zend Framework XXE Vulnerability
zendframework/zendframework1/ zendframework/zendframework1
Zend Framework XXE Vulnerability
django, django
Django Directory Traversal via ssi template tag
django/ django
Django Directory Traversal via ssi template tag
sup, sup
Sup Code Injection vulnerability
pyopenssl
PyOpenSSL Mishandles NUL Byte In Certificate Subject Alternative Name
pyopenssl
PyOpenSSL Mishandles NUL Byte In Certificate Subject Alternative Name
drupal/drupal
Drupal Open Redirect
drupal/drupal
Drupal improper access restrictions
moin
MoinMoin Multiple unrestricted file upload vulnerabilities
moin
MoinMoin Multiple unrestricted file upload vulnerabilities
org.jenkins-ci.plugins:sonar
Jenkins SonarQube Plugin Stores Passwords in Cleartext
org.jenkins-ci.plugins:sonar
Jenkins SonarQube Plugin Stores Passwords in Cleartext
fat_free_crm
Fat Free CRM allows remote attackers to obtain sensitive information via a direct request
fat_free_crm
Fat Free CRM allows remote attackers to obtain sensitive information via a direct request
fat_free_crm
Fat Free CRM vulnerable to SQL Injection
fat_free_crm
Fat Free CRM vulnerable to Exposure of Sensitive Information
fat_free_crm
Fat Free CRM vulnerable to Exposure of Sensitive Information
fat_free_crm
Fat Free CRM has fixed token value
fat_free_crm
Fat Free CRM contains Cross-site Request Forgery vulnerablilities
fat_free_crm
Fat Free CRM contains Cross-site Request Forgery vulnerablilities
drupal/drupal
Drupal has open redirect vulnerability in the Overlay module
drupal/drupal
Drupal has open redirect vulnerability in the Overlay module
nova
OpenStack Compute (Nova) does not verify the virtual size of a QCOW2 image
nova
OpenStack Compute (Nova) does not verify the virtual size of a QCOW2 image
rubygems-update
RubyGems HTTPS to HTTP redirect
rubygems-update
RubyGems does not verify SSL certificate
typo3/cms, typo3/cms, typo3/cms, typo3/cms
TYPO3 vulnerable to Insecure Unserialize via Content Editing Wizards component
typo3/cms/ typo3/cms/ typo3/cms/ typo3/cms
TYPO3 vulnerable to Insecure Unserialize via Content Editing Wizards component
typo3/cms-core, typo3/cms-core, typo3/cms-core, typo3/cms-core
TYPO3 Improper Access Control vulnerability
typo3/cms-core/ typo3/cms-core/ typo3/cms-core/ typo3/cms-core
TYPO3 Improper Access Control vulnerability
typo3/cms-core, typo3/cms-core, typo3/cms-core
TYPO3 is vulnerable to Mass Assignment in the Extension table administration library
typo3/cms-core/ typo3/cms-core/ typo3/cms-core
TYPO3 is vulnerable to Mass Assignment in the Extension table administration library
python-keystoneclient
python-keystoneclient missing expiration check in PKI token validation
python-keystoneclient
python-keystoneclient missing expiration check in PKI token validation
ec-cube/ec-cube
EC-CUBE vulnerable to authorization bypass
ec-cube/ec-cube
EC-CUBE vulnerable to authorization bypass
django, django
Django Denial of Service Vulnerability in the authentication framework
django/ django
Django Denial of Service Vulnerability in the authentication framework
com.smartbear.soapui:soapui
Code injection via property expansion in SoapUI
com.smartbear.soapui:soapui
Code injection via property expansion in SoapUI
