Open Source Vulnerabilities
python-swiftclient
Python Swift client is vulnerable to Missing SSL Certificate Check
python-swiftclient
Python Swift client is vulnerable to Missing SSL Certificate Check
civicrm/civicrm-core, civicrm/civicrm-core
CiviCRM SQL injection vulnerability via Quick Search API
civicrm/civicrm-core/ civicrm/civicrm-core
CiviCRM SQL injection vulnerability via Quick Search API
keystone
OpenStack Identity Keystone Privilege Escalation vulnerability
keystone
OpenStack Identity Keystone Privilege Escalation vulnerability
org.apache.solr:solr-core
Improper Restriction of XML External Entity Reference in Apache Solr
org.apache.solr:solr-core
Improper Restriction of XML External Entity Reference in Apache Solr
org.jgroups:jgroups, org.jgroups:jgroups
Exposure of Sensitive Information to an Unauthorized Actor in JGroup
org.jgroups:jgroups/ org.jgroups:jgroups
Exposure of Sensitive Information to an Unauthorized Actor in JGroup
nova
OpenStack Nova Router metadata queries are not restricted by tenant
nova
OpenStack Nova Router metadata queries are not restricted by tenant
glance
OpenStack Glance sensitive information disclosure via logs
glance
OpenStack Glance sensitive information disclosure via logs
swift, swift, swift
OpenStack Swift Discloses Secret URLs to Timing Attack
swift/ swift/ swift
OpenStack Swift Discloses Secret URLs to Timing Attack
plone, plone, plone
Plone Authenticated Denial of Service vulnerability
plone/ plone/ plone
Plone Authenticated Denial of Service vulnerability
plone, plone, plone
Plone Privilege escalation due improper authorization
plone/ plone/ plone
Plone Privilege escalation due improper authorization
plone, plone, plone
Plone Denial of Service vulnerability via decompressing large zip archives
plone/ plone/ plone
Plone Denial of Service vulnerability via decompressing large zip archives
plone, plone, plone
Plone is vulnerable to information exposure via the object manager implementation
plone/ plone/ plone
Plone is vulnerable to information exposure via the object manager implementation
plone, plone, plone
Plone's authenticated users able to alter their password despite of policy definition
plone/ plone/ plone
Plone's authenticated users able to alter their password despite of policy definition
plone, plone, plone
Plone vulnerable to cross-site scripting
plone/ plone/ plone
Plone vulnerable to cross-site scripting
plone, plone, plone
Plone is vulnerable to email spoofing
plone, plone, plone
Plone is vulnerable to Information Exposure when generating zip archives
plone/ plone/ plone
Plone is vulnerable to Information Exposure when generating zip archives
plone, plone, plone
Plone is vulnerable to File System Path Exposure
plone/ plone/ plone
Plone is vulnerable to File System Path Exposure
plone, plone, plone
Plone Unrestricted Filed Manipulation vulnerability via content edit forms
plone/ plone/ plone
Plone Unrestricted Filed Manipulation vulnerability via content edit forms
DotNetNuke.Core, DotNetNuke.Core
DotNetNuke (DNN) Open redirect vulnerability
DotNetNuke.Core/ DotNetNuke.Core
DotNetNuke (DNN) Open redirect vulnerability
plone, plone, plone
Plone Multiple open redirect vulnerabilities
plone/ plone/ plone
Plone Multiple open redirect vulnerabilities
plone, plone, plone
Plone Improper Access Control Vulnerability
plone/ plone/ plone
Plone Improper Access Control Vulnerability
nova
OpenStack Nova VMWare driver leaks rescued images
org.apache.geronimo.framework:geronimo-jmx-remoting
Apache Geronimo JMX Remoting functionality allows remote code execution in 3.x before v3.0.1
org.apache.geronimo.framework:geronimo-jmx-remoting
Apache Geronimo JMX Remoting functionality allows remote code execution in 3.x before v3.0.1
MongooseIM
Erlang Solutions MongooseIM vulnerable to denial of service (DoS) via crafted XMPP stream
MongooseIM
Erlang Solutions MongooseIM vulnerable to denial of service (DoS) via crafted XMPP stream
reviewboard, reviewboard
Review Board Cross-site scripting (XSS) vulnerability in the reviews dropdown
reviewboard/ reviewboard
Review Board Cross-site scripting (XSS) vulnerability in the reviews dropdown
pimcore/pimcore
Pimcore Vulnerable to PHP Object Injection Attacks
pimcore/pimcore
Pimcore Vulnerable to PHP Object Injection Attacks
org.fitnesse:fitnesse
Improper Neutralization of Special Elements used in a Command in FitNesse Wiki
org.fitnesse:fitnesse
Improper Neutralization of Special Elements used in a Command in FitNesse Wiki
ajenti
Ajenti Cross-site scripting (XSS) vulnerability
transifex-client
Transifex command-line client has improper certificate validation
transifex-client
Transifex command-line client has improper certificate validation
python-keystoneclient
OpenStack Nova uses insecure keystone middleware tmpdir by default
python-keystoneclient
OpenStack Nova uses insecure keystone middleware tmpdir by default
keystone
OpenStack Keystone Sensitive information disclosure via log files
keystone
OpenStack Keystone Sensitive information disclosure via log files
org.apache.struts:struts2-core
Apache Struts2 Broken Access Control Vulnerability
org.apache.struts:struts2-core
Apache Struts2 Broken Access Control Vulnerability
org.igniterealtime.openfire:parent
Ignite Realtime Openfire vulnerable to XMPPbomb attack
org.igniterealtime.openfire:parent
Ignite Realtime Openfire vulnerable to XMPPbomb attack
org.jenkins-ci.plugins:subversion
Jenkins Subversion Plugin Stores Credentials with Base64 Encoding
org.jenkins-ci.plugins:subversion
Jenkins Subversion Plugin Stores Credentials with Base64 Encoding
kafo, kafo
Kafo allows local users to obtain passwords and other sensitive information by reading default_values.yaml
kafo/ kafo
Kafo allows local users to obtain passwords and other sensitive information by reading default_values.yaml
soappy
SOAPpy vulnerable to XXE attacks
soappy
SOAPpy vulnerable to XML External Entity attacks
soappy
SOAPpy vulnerable to XML External Entity attacks
gitlab-grit
GitLab Grit Gem for Ruby contains a flaw allowing arbitrary commands to be executed
gitlab-grit
GitLab Grit Gem for Ruby contains a flaw allowing arbitrary commands to be executed
typo3/cms, typo3/cms, typo3/cms
Typo3 Backend History Module Vulnerable to XSS
typo3/cms/ typo3/cms/ typo3/cms
Typo3 Backend History Module Vulnerable to XSS
typo3/cms, typo3/cms
TYPO3 vulnerable to remote authenticated arbitrary code execution
typo3/cms/ typo3/cms
TYPO3 vulnerable to remote authenticated arbitrary code execution
typo3/cms-core, typo3/cms-core
TYPO3 Improper Access Management in the File Abstraction Layer
typo3/cms-core/ typo3/cms-core
TYPO3 Improper Access Management in the File Abstraction Layer
typo3/cms, typo3/cms
TYPO3 doesn't properly check file extensions
typo3/cms/ typo3/cms
TYPO3 doesn't properly check file extensions
typo3/cms
Typo3 Information Disclosure
typo3/cms
TYPO3 Improper Session Invalidation
typo3/cms
TYPO3 vulnerable to authentication bypass via leveraging knowledge of password hash
typo3/cms
TYPO3 vulnerable to authentication bypass via leveraging knowledge of password hash
phpoffice/phpexcel
PHPExcel vulnerable to XXE attacks through libxml
phpoffice/phpexcel
PHPExcel vulnerable to XXE attacks through libxml
glance
OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
glance
OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
sabre/dav, sabre/dav
XXE in SabreDAV
neutron
OpenStack Neutron Improper Authentication vulnerability
neutron
OpenStack Neutron Improper Authentication vulnerability
