Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-f3f3-5q5j-6v47
    Fix available
    Packages

    geshi/geshi

    Summary

    GeSHi vulnerable to Cross-site Scripting

    Published
    17 May 2022
    GHSA-f5jh-q6mp-9c8p
    No fix available
    Packages

    impresscms/impresscms

    Summary

    ImpressCMS Cross-site scripting Vulnerability

    Published
    17 May 2022
    GHSA-fw3x-2pr2-5j64
    Fix available
    Packages

    geshi/geshi

    Summary

    GeSHi vulnerable to Directory Traversal

    Published
    17 May 2022
    GHSA-4xf6-xr96-7vmp
    Fix available
    Packages

    djblets, djblets

    Summary

    Djblets Cross-site scripting Vulnerability

    Published
    17 May 2022
    GHSA-wpvx-26f7-65q3
    No fix available
    Packages

    mayan-edms

    Summary

    Mayan EDMS multiple cross-site scripting (XSS) vulnerabilities

    Published
    17 May 2022
    GHSA-5644-2v3h-5w4x
    Fix available
    Packages

    nova

    Summary

    OpenStack Nova denial of service through compressed disk images

    Published
    17 May 2022
    GHSA-p258-xmh3-72pv
    Fix available
    Packages

    nova

    Summary

    OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests

    Published
    17 May 2022
    GHSA-2w87-5qcj-j6gx
    Fix available
    Packages

    nova

    Summary

    OpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image

    Published
    17 May 2022
    GHSA-w429-xc55-hc48
    Fix available
    Packages

    nova

    Summary

    OpenStack Nova host data leak to vm instance in rescue mode

    Published
    17 May 2022
    GHSA-rg52-j87w-pf83
    Fix available
    Packages

    plone, products-cmfplone

    Summary

    Plone Filesystem path information leak

    Published
    17 May 2022
    GHSA-4vr8-r7qr-fpvq
    Fix available
    Packages

    plone, products-cmfplone

    Summary

    Plone Privilege escalation through exposed underlying API

    Published
    17 May 2022
    GHSA-45w3-2hvv-pfxq
    Fix available
    Packages

    org.apache.solr:solr-core

    Summary

    XML Injection in Apache Solr

    Published
    17 May 2022
    GHSA-998j-j6v9-5846
    Fix available
    Packages

    org.apache.solr:solr-core

    Summary

    Apache Solr UpdateRequestHandler for XML resolves XML External Entities

    Published
    17 May 2022
    GHSA-3jcq-cwr7-6332
    Fix available
    Packages

    jplayer

    Summary

    jplayer Cross Site Scripting vulnerability

    Published
    17 May 2022
    GHSA-74qv-rv53-5wcx
    Fix available
    Packages

    yiisoft/yii

    Summary

    Yii PHP Framework arbitrary PHP scripts execution

    Published
    17 May 2022
    GHSA-x626-q4v7-7xc6
    Fix available
    Packages

    org.neo4j:neo4j

    Summary

    Neo4J vulnerable to Cross-Site Request Forgery

    Published
    17 May 2022
    GHSA-wcfx-3m6v-4frg
    Fix available
    Packages

    fat_free_crm

    Summary

    Fat Free CRM subject to Cross-site Scripting

    Published
    17 May 2022
    GHSA-f8pg-wp5j-rjxx
    Fix available
    Packages

    plone, plone

    Summary

    Plone Information Disclosure

    Published
    17 May 2022
    GHSA-6w93-4c4p-xv2x
    Fix available
    Packages

    plone, plone

    Summary

    Plone Metadata Disclosure

    Published
    17 May 2022
    GHSA-9m4g-f42q-vrrh
    Fix available
    Packages

    plone, plone

    Summary

    Plone Sandbox Bypass

    Published
    17 May 2022
    GHSA-hr59-35cr-qf43
    Fix available
    Packages

    plone, plone

    Summary

    Plone Cross-site scripting Vulnerability

    Published
    17 May 2022
    GHSA-q46g-v7r4-9vhr
    Fix available
    Packages

    plone, plone

    Summary

    Plone Cross-site scripting Vulnerability

    Published
    17 May 2022
    GHSA-pvhv-qwc8-r2pg
    Fix available
    Packages

    plone, plone

    Summary

    Plone Arbitrary File Read

    Published
    17 May 2022
    GHSA-25jh-5h5r-h33m
    Fix available
    Packages

    plone, plone

    Summary

    Plone Sandbox Bypass

    Published
    17 May 2022
    GHSA-3g6w-4m7x-97v6
    Fix available
    Packages

    plone, plone

    Summary

    Plone Cross-site scripting Vulnerability

    Published
    17 May 2022
    GHSA-5whw-5cmm-9jw4
    Fix available
    Packages

    plone, plone

    Summary

    Plone Cross-site scripting Vulnerability

    Published
    17 May 2022
    GHSA-cq5g-924m-7fxh
    Fix available
    Packages

    plone, plone

    Summary

    Plone Information Disclosure

    Published
    17 May 2022
    GHSA-gx6w-hcw3-5r37
    Fix available
    Packages

    plone

    Summary

    Plone DoS via Crafted URL

    Published
    17 May 2022
    GHSA-79hj-474h-v4xv
    Fix available
    Packages

    plone, plone

    Summary

    Plone denial of service via RSS Feed Request

    Published
    17 May 2022
    GHSA-w6pw-5gh5-4952
    Fix available
    Packages

    plone, plone

    Summary

    Plone python code injection

    Published
    17 May 2022
    GHSA-46fq-683f-2jwq
    Fix available
    Packages

    dl/yag, punktde/pt_extbase

    Summary

    yag and pt_extbase extensions for TYPO3 allow remote attackers to bypass access restrictions

    Published
    17 May 2022
    GHSA-f3v6-g4mv-pjhq
    Fix available
    Packages

    web-tp3/wec_map, jbartels/wec-map

    Summary

    WEC Map (wec_map) extension for TYPO3 allows SQL Injection

    Published
    17 May 2022
    GHSA-mqhg-c7w9-w3cv
    Fix available
    Packages

    web-tp3/wec_map, jbartels/wec-map

    Summary

    WEC Map (wec_map) extension for TYPO3 allows Cross-site Scripting

    Published
    17 May 2022
    GHSA-fjhw-8222-g2hg
    Fix available
    Packages

    org.jolokia:jolokia-core

    Summary

    Cross-Site Request Forgery in Jolokia

    Published
    17 May 2022
    GHSA-7hxc-mwx7-5hmc
    Fix available
    Packages

    plone, plone

    Summary

    Plone Code Injection vulnerability

    Published
    17 May 2022
    GHSA-cxw7-85xm-3xrc
    Fix available
    Packages

    plone, plone

    Summary

    Plone Code Injection vulnerability

    Published
    17 May 2022
    GHSA-wrf2-2rch-cmr9
    Fix available
    Packages

    plone, plone

    Summary

    Plone is vulnerable to denial of service

    Published
    17 May 2022
    GHSA-683w-84m7-p8pw
    Fix available
    Packages

    plone, plone

    Summary

    Plone User account enumeration via crafted URL

    Published
    17 May 2022
    GHSA-v8fq-gq9j-3v7h
    Fix available
    Packages

    keystone

    Summary

    OpenStack Identity (Keystone) UUID v2 tokens does not expire with revocation events

    Published
    17 May 2022
    GHSA-2jq7-pgqq-gqqj
    Fix available
    Packages

    in2code/powermail

    Summary

    TYPO3 powermail extension allows remote attackers to bypass CAPTCHA protection mechanism

    Published
    17 May 2022
    GHSA-m278-c6gg-4jrr
    Fix available
    Packages

    in2code/powermail, in2code/powermail

    Summary

    TYPO3 powermail extension has unrestricted file upload vulnerability

    Published
    17 May 2022
    GHSA-77w8-qv8m-386h
    Fix available
    Packages

    keystone

    Summary

    OpenStack Keystone Domain-scoped tokens don't get revoked

    Published
    17 May 2022
    GHSA-gmvp-5rf9-mxcm
    Fix available
    Packages

    keystone

    Summary

    OpenStack Identity (Keystone) Multiple vulnerabilities in revocation events

    Published
    17 May 2022
    GHSA-hpj3-5p46-g87w
    Fix available
    Packages

    cobbler

    Summary

    Cobbler vulnerable to code injection via unsafe YAML loading

    Published
    17 May 2022
    GHSA-2q75-f7cp-w86q
    Fix available
    Packages

    plone, plone

    Summary

    Plone contains Cross-site Request Forgery

    Published
    17 May 2022
    GHSA-wprr-mc54-c62q
    Fix available
    Packages

    plone, plone

    Summary

    Exposure of Sensitive Information in Plone

    Published
    17 May 2022
    GHSA-qhch-g8qr-p497
    Fix available
    Packages

    cinder

    Summary

    OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability

    Published
    17 May 2022
    GHSA-q5v2-2v66-6hwm
    Fix available
    Packages

    org.directwebremoting:dwr, org.directwebremoting:dwr

    Summary

    Improper Neutralization of Input During Web Page Generation in Direct Web Remoting

    Published
    17 May 2022
    GHSA-jpmf-8cj2-595g
    Fix available
    Packages

    org.apache.hadoop:hadoop-client, org.apache.hadoop:hadoop-client

    Summary

    Improper Link Resolution Before File Access in Apache Hadoop

    Published
    17 May 2022
    GHSA-873q-wpqr-xfgw
    Fix available
    Packages

    bottle, bottle, bottle

    Summary

    Bottle does not properly limit content-types

    Published
    17 May 2022