Open Source Vulnerabilities
phpmyadmin/phpmyadmin
phpMyAdmin Multiple XSS Vulnerabilities After Inline Editing and Save
phpmyadmin/phpmyadmin
phpMyAdmin Multiple XSS Vulnerabilities After Inline Editing and Save
phpmyadmin/phpmyadmin
phpMyAdmin Multiple XSS Vulnerabilities
phpmyadmin/phpmyadmin
phpMyAdmin Multiple XSS Vulnerabilities
james-heinrich/phpthumb
phpThumb is vulnerable to Server-Side Request Forgery (SSRF)
james-heinrich/phpthumb
phpThumb is vulnerable to Server-Side Request Forgery (SSRF)
symfony/symfony, symfony/symfony, symfony/symfony, symfony/symfony, symfony/polyfill, symfony/security, symfony/security, symfony/security, symfony/security
Symfony Denial of Service Via Long Password Hashing
symfony/symfony/ symfony/symfony/ symfony/symfony/ symfony/symfony/ symfony/polyfill/ symfony/security/ symfony/security/ symfony/security/ symfony/security
Symfony Denial of Service Via Long Password Hashing
typo3/cms, typo3/cms, typo3/cms, typo3/cms, typo3/cms, typo3/cms, typo3/cms
Typo3 Vulnerable to Cache Poisoning
typo3/cms/ typo3/cms/ typo3/cms/ typo3/cms/ typo3/cms/ typo3/cms/ typo3/cms
Typo3 Vulnerable to Cache Poisoning
org.apache.solr:solr
Improper Neutralization of Input During Web Page Generation in Apache Solr
org.apache.solr:solr
Improper Neutralization of Input During Web Page Generation in Apache Solr
zf-commons/zfc-user
ZF-Commons ZfcUser Vulnerable to XSS in Login Redirect
zf-commons/zfc-user
ZF-Commons ZfcUser Vulnerable to XSS in Login Redirect
org.jruby:jruby-parent
JRuby denial of service via Hash Collision
org.jruby:jruby-parent
JRuby denial of service via Hash Collision
org.fusesource.hawtjni:hawtjni-runtime
Improper Control of Generation of Code in HawtJNI
org.fusesource.hawtjni:hawtjni-runtime
Improper Control of Generation of Code in HawtJNI
io.undertow:undertow-core, io.undertow:undertow-core, io.undertow:undertow-core
Improper Limitation of a Pathname to a Restricted Directory in JBoss Undertow
io.undertow:undertow-core/ io.undertow:undertow-core/ io.undertow:undertow-core
Improper Limitation of a Pathname to a Restricted Directory in JBoss Undertow
dulwich
Dulwich Buffer Overflow when handling pack files
dulwich
Dulwich Arbitrary code execution via commit with directory path starting with .git
dulwich
Dulwich Arbitrary code execution via commit with directory path starting with .git
keystone
OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend
keystone
OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend
org.jboss.resteasy:resteasy-jaxrs
XML External Entity Reference in RESTEasy
org.jboss.resteasy:resteasy-jaxrs
XML External Entity Reference in RESTEasy
django-markupfield
django-markupfield Arbitrary File Read
org.drools:drools-core, org.jbpm:jbpm-bpmn2
Improper Input Validation in Drools and jBPM
org.drools:drools-core/ org.jbpm:jbpm-bpmn2
Improper Input Validation in Drools and jBPM
org.elasticsearch:elasticsearch, org.elasticsearch:elasticsearch
Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch
org.elasticsearch:elasticsearch/ org.elasticsearch:elasticsearch
Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch
ceph-deploy
ceph-deploy uses world-readable permissions on client.admin key
ceph-deploy
ceph-deploy uses world-readable permissions on client.admin key
impresscms/impresscms
ImpressCMS Path Traversal to Arbitrary File Delete
impresscms/impresscms
ImpressCMS Path Traversal to Arbitrary File Delete
org.picketlink:picketlink-tomcat-common
PicketLink does not properly check role based authorization
org.picketlink:picketlink-tomcat-common
PicketLink does not properly check role based authorization
drupal/core
Drupal Access Control Bypass
october/october
October CMS XSS In Caption Tag of Profile
ckeditor/ckeditor
The Preview plugin in CKEditor allows Cross-site scripting (XSS)
ckeditor/ckeditor
The Preview plugin in CKEditor allows Cross-site scripting (XSS)
mediawiki/core, mediawiki/core
Cross-site scripting vulnerability in includes/actions/InfoAction.php
mediawiki/core/ mediawiki/core
Cross-site scripting vulnerability in includes/actions/InfoAction.php
swift
OpenStack Swift Cross-site Scriping vulnerability
org.apache.solr:solr-core
Improper Limitation of a Pathname to a Restricted Directory in Apache Solr
org.apache.solr:solr-core
Improper Limitation of a Pathname to a Restricted Directory in Apache Solr
glance, glance
OpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions
glance/ glance
OpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions
org.apache.ambari:ambari
Apache Ambari Open Redirect
org.apache.ambari:ambari
Apache Ambari SSRF Vulnerability
keystone
OpenStack Identity (Keystone) DoS through V3 API authentication chaining
keystone
OpenStack Identity (Keystone) DoS through V3 API authentication chaining
smarty/smarty
Cross-site Scripting in SmartyException
plone, plone
Plone denial of service via Caching Bypass
ipsilon
Ipsilon denial of service via a duplicate SP name
jinja2
Insecure Temporary File in Jinja2
joomla/session
Joomla! Framework Remote Code Injection Vulnerability
joomla/session
Joomla! Framework Remote Code Injection Vulnerability
typo3/cms, typo3/cms
TYPO3 Cross-site Scripting vulnerability
typo3/cms/ typo3/cms
TYPO3 Cross-site Scripting vulnerability
typo3/cms
TYPO3 CMS indexed search Cross-site Scripting vulnerability
typo3/cms
TYPO3 CMS indexed search Cross-site Scripting vulnerability
typo3/cms
TYPO3 allows remote attackers to embed Flash videos from external domain
typo3/cms
TYPO3 allows remote attackers to embed Flash videos from external domain
typo3/cms, typo3/cms
Typo3 XSS Vulnerability
dolibarr/dolibarr
Dolibarr ERP and CRM contain XSS Vulnerabilities
dolibarr/dolibarr
Dolibarr ERP and CRM contain XSS Vulnerabilities
org.apache.solr:solr-core
Improper Neutralization of Input During Web Page Generation in Apache Solr
org.apache.solr:solr-core
Improper Neutralization of Input During Web Page Generation in Apache Solr
org.apache.solr:solr-core
Improper Neutralization of Input During Web Page Generation in Apache Solr
org.apache.solr:solr-core
Improper Neutralization of Input During Web Page Generation in Apache Solr
phpmyadmin/phpmyadmin, phpmyadmin/phpmyadmin, phpmyadmin/phpmyadmin
phpMyAdmin cross-site scripting Vulnerability via ENUM value
phpmyadmin/phpmyadmin/ phpmyadmin/phpmyadmin/ phpmyadmin/phpmyadmin
phpMyAdmin cross-site scripting Vulnerability via ENUM value
drupal/drupal, drupal/drupal, drupal/drupal, drupal/core, drupal/core, drupal/core
Drupal Open Redirect
drupal/drupal/ drupal/drupal/ drupal/drupal/ drupal/core/ drupal/core/ drupal/core
Drupal Open Redirect
org.apache.ranger:ranger
Apache Ranger Cross-site Scripting vulnerability
org.apache.ranger:ranger
Apache Ranger Cross-site Scripting vulnerability
drupal/core, drupal/drupal
Drupal CRLF injection vulnerability in the drupal_set_header function
drupal/core/ drupal/drupal
Drupal CRLF injection vulnerability in the drupal_set_header function
drupal/core, drupal/core, drupal/drupal, drupal/drupal
Drupal saving user accounts can sometimes grant the user all roles
drupal/core/ drupal/core/ drupal/drupal/ drupal/drupal
Drupal saving user accounts can sometimes grant the user all roles
drupal/core, drupal/drupal
Drupal Form API ignores access restrictions on submit buttons
drupal/core/ drupal/drupal
Drupal Form API ignores access restrictions on submit buttons
org.apache.ranger:ranger
Apache Ranger allows users to bypass intended access restrictions via direct access to module URLs
org.apache.ranger:ranger
Apache Ranger allows users to bypass intended access restrictions via direct access to module URLs
org.apache.ranger:ranger
Apache Ranger allows users to bypass intended access restrictions via the REST API
org.apache.ranger:ranger
Apache Ranger allows users to bypass intended access restrictions via the REST API
