Open Source Vulnerabilities
geshi/geshi
GeSHi vulnerable to Cross-site Scripting
impresscms/impresscms
ImpressCMS Cross-site scripting Vulnerability
impresscms/impresscms
ImpressCMS Cross-site scripting Vulnerability
geshi/geshi
GeSHi vulnerable to Directory Traversal
djblets, djblets
Djblets Cross-site scripting Vulnerability
djblets/ djblets
Djblets Cross-site scripting Vulnerability
mayan-edms
Mayan EDMS multiple cross-site scripting (XSS) vulnerabilities
mayan-edms
Mayan EDMS multiple cross-site scripting (XSS) vulnerabilities
nova
OpenStack Nova denial of service through compressed disk images
nova
OpenStack Nova denial of service through compressed disk images
nova
OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
nova
OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
nova
OpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image
nova
OpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image
nova
OpenStack Nova host data leak to vm instance in rescue mode
nova
OpenStack Nova host data leak to vm instance in rescue mode
plone, products-cmfplone
Plone Filesystem path information leak
plone/ products-cmfplone
Plone Filesystem path information leak
plone, products-cmfplone
Plone Privilege escalation through exposed underlying API
plone/ products-cmfplone
Plone Privilege escalation through exposed underlying API
org.apache.solr:solr-core
XML Injection in Apache Solr
org.apache.solr:solr-core
Apache Solr UpdateRequestHandler for XML resolves XML External Entities
org.apache.solr:solr-core
Apache Solr UpdateRequestHandler for XML resolves XML External Entities
jplayer
jplayer Cross Site Scripting vulnerability
yiisoft/yii
Yii PHP Framework arbitrary PHP scripts execution
yiisoft/yii
Yii PHP Framework arbitrary PHP scripts execution
org.neo4j:neo4j
Neo4J vulnerable to Cross-Site Request Forgery
org.neo4j:neo4j
Neo4J vulnerable to Cross-Site Request Forgery
fat_free_crm
Fat Free CRM subject to Cross-site Scripting
plone, plone
Plone Information Disclosure
plone, plone
Plone Metadata Disclosure
plone, plone
Plone Cross-site scripting Vulnerability
plone, plone
Plone Cross-site scripting Vulnerability
plone, plone
Plone Arbitrary File Read
plone, plone
Plone Cross-site scripting Vulnerability
plone, plone
Plone Cross-site scripting Vulnerability
plone, plone
Plone Information Disclosure
plone, plone
Plone denial of service via RSS Feed Request
plone, plone
Plone python code injection
dl/yag, punktde/pt_extbase
yag and pt_extbase extensions for TYPO3 allow remote attackers to bypass access restrictions
dl/yag/ punktde/pt_extbase
yag and pt_extbase extensions for TYPO3 allow remote attackers to bypass access restrictions
web-tp3/wec_map, jbartels/wec-map
WEC Map (wec_map) extension for TYPO3 allows SQL Injection
web-tp3/wec_map/ jbartels/wec-map
WEC Map (wec_map) extension for TYPO3 allows SQL Injection
web-tp3/wec_map, jbartels/wec-map
WEC Map (wec_map) extension for TYPO3 allows Cross-site Scripting
web-tp3/wec_map/ jbartels/wec-map
WEC Map (wec_map) extension for TYPO3 allows Cross-site Scripting
org.jolokia:jolokia-core
Cross-Site Request Forgery in Jolokia
org.jolokia:jolokia-core
Cross-Site Request Forgery in Jolokia
plone, plone
Plone Code Injection vulnerability
plone, plone
Plone Code Injection vulnerability
plone, plone
Plone is vulnerable to denial of service
plone, plone
Plone User account enumeration via crafted URL
plone/ plone
Plone User account enumeration via crafted URL
keystone
OpenStack Identity (Keystone) UUID v2 tokens does not expire with revocation events
keystone
OpenStack Identity (Keystone) UUID v2 tokens does not expire with revocation events
in2code/powermail
TYPO3 powermail extension allows remote attackers to bypass CAPTCHA protection mechanism
in2code/powermail
TYPO3 powermail extension allows remote attackers to bypass CAPTCHA protection mechanism
in2code/powermail, in2code/powermail
TYPO3 powermail extension has unrestricted file upload vulnerability
in2code/powermail/ in2code/powermail
TYPO3 powermail extension has unrestricted file upload vulnerability
keystone
OpenStack Keystone Domain-scoped tokens don't get revoked
keystone
OpenStack Keystone Domain-scoped tokens don't get revoked
keystone
OpenStack Identity (Keystone) Multiple vulnerabilities in revocation events
keystone
OpenStack Identity (Keystone) Multiple vulnerabilities in revocation events
cobbler
Cobbler vulnerable to code injection via unsafe YAML loading
cobbler
Cobbler vulnerable to code injection via unsafe YAML loading
plone, plone
Plone contains Cross-site Request Forgery
plone, plone
Exposure of Sensitive Information in Plone
cinder
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability
cinder
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability
org.directwebremoting:dwr, org.directwebremoting:dwr
Improper Neutralization of Input During Web Page Generation in Direct Web Remoting
org.directwebremoting:dwr/ org.directwebremoting:dwr
Improper Neutralization of Input During Web Page Generation in Direct Web Remoting
org.apache.hadoop:hadoop-client, org.apache.hadoop:hadoop-client
Improper Link Resolution Before File Access in Apache Hadoop
org.apache.hadoop:hadoop-client/ org.apache.hadoop:hadoop-client
Improper Link Resolution Before File Access in Apache Hadoop
bottle, bottle, bottle
Bottle does not properly limit content-types
bottle/ bottle/ bottle
Bottle does not properly limit content-types
