Open Source Vulnerabilities
librsvg
librsvg DoS via Cyclic References
requests
Exposure of Sensitive Information to an Unauthorized Actor in Requests
requests
Exposure of Sensitive Information to an Unauthorized Actor in Requests
ajenti
Eugene Pankov Ajenti Cross-site scripting Vulnerabilities
ajenti
Eugene Pankov Ajenti Cross-site scripting Vulnerabilities
org.jboss.resteasy:resteasy-client, org.jboss.resteasy:resteasy-client
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
org.jboss.resteasy:resteasy-client/ org.jboss.resteasy:resteasy-client
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
trytond, trytond, trytond, trytond, trytond
Tryton allows users to read the hashed password
trytond/ trytond/ trytond/ trytond/ trytond
Tryton allows users to read the hashed password
murano, murano-dashboard, murano-dashboard, python-muranoclient, python-muranoclient
OpenStack Murano Code Execution
murano/ murano-dashboard/ murano-dashboard/ python-muranoclient/ python-muranoclient
OpenStack Murano Code Execution
org.apache.jackrabbit:jackrabbit-webdav, org.apache.jackrabbit:jackrabbit-webdav, org.apache.jackrabbit:jackrabbit-webdav, org.apache.jackrabbit:jackrabbit-webdav, org.apache.jackrabbit:jackrabbit-webdav, org.apache.jackrabbit:jackrabbit-webdav
Apache Jackrabbit Authentication Hijacking Vulnerability
org.apache.jackrabbit:jackrabbit-webdav/ org.apache.jackrabbit:jackrabbit-webdav/ org.apache.jackrabbit:jackrabbit-webdav/ org.apache.jackrabbit:jackrabbit-webdav/ org.apache.jackrabbit:jackrabbit-webdav/ org.apache.jackrabbit:jackrabbit-webdav
Apache Jackrabbit Authentication Hijacking Vulnerability
drupal/drupal, drupal/core
Drupal Users without "Administer comments" can set comment visibility on nodes they can edit
drupal/drupal/ drupal/core
Drupal Users without "Administer comments" can set comment visibility on nodes they can edit
drupal/core, drupal/drupal
Drupal Cross-site scripting (XSS) vulnerability
drupal/core/ drupal/drupal
Drupal Cross-site scripting (XSS) vulnerability
drupal/core, drupal/drupal
Drupal Unprivileged access to config export
drupal/core/ drupal/drupal
Drupal Unprivileged access to config export
org.apache.tomcat:tomcat
Deserialization of Untrusted Data in Apache Tomcat
org.apache.tomcat:tomcat
Deserialization of Untrusted Data in Apache Tomcat
org.apache.activemq:activemq-core
Cross-site Scripting in Apache ActiveMQ
org.apache.activemq:activemq-core
Cross-site Scripting in Apache ActiveMQ
org.apache.activemq:apache-activemq, org.apache.activemq:activemq-web-demo
Apache ActiveMQ default configuration subject to denial of service
org.apache.activemq:apache-activemq/ org.apache.activemq:activemq-web-demo
Apache ActiveMQ default configuration subject to denial of service
org.apache.activemq:activemq-core
Apache ActiveMQ Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet
org.apache.activemq:activemq-core
Apache ActiveMQ Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet
oauth2
SimpleGeo python-oauth2 vulnerable to the use of Insufficiently Random Values to generate nonces
oauth2
SimpleGeo python-oauth2 vulnerable to the use of Insufficiently Random Values to generate nonces
oauth2
SimpleGeo python-oauth2 does not check the nonce allowing replay attacks
oauth2
SimpleGeo python-oauth2 does not check the nonce allowing replay attacks
openid/php-openid, typo3/cms
PHP OpenID Library Denial of Service vulnerability
openid/php-openid/ typo3/cms
PHP OpenID Library Denial of Service vulnerability
org.apache.activemq:activemq-client
Improper Authentication in Apache ActiveMQ
org.apache.activemq:activemq-client
Improper Authentication in Apache ActiveMQ
pywbem
PyWBEM TOCTOU vulnerability in certificate validation
pywbem
PyWBEM TOCTOU vulnerability in certificate validation
pywbem
PyWBEM TOCTOU vulnerability in certificate validation
pywbem
PyWBEM TOCTOU vulnerability in certificate validation
typo3/cms, typo3/cms, typo3/cms, typo3/cms
TYPO3 vulnerable to Information Disclosure via Content Editing Wizards component
typo3/cms/ typo3/cms/ typo3/cms/ typo3/cms
TYPO3 vulnerable to Information Disclosure via Content Editing Wizards component
org.directwebremoting:dwr, org.directwebremoting:dwr
Exposure of Sensitive Information to an Unauthorized Actor in Direct Web Remoting
org.directwebremoting:dwr/ org.directwebremoting:dwr
Exposure of Sensitive Information to an Unauthorized Actor in Direct Web Remoting
typo3/cms, typo3/cms, typo3/cms
Typo3 Open Redirect In Frontend Rendering
typo3/cms/ typo3/cms/ typo3/cms
Typo3 Open Redirect In Frontend Rendering
keystonemiddleware, keystonemiddleware, python-keystoneclient, python-keystoneclient
OpenStack keystonemiddleware does not verify certificate
keystonemiddleware/ keystonemiddleware/ python-keystoneclient/ python-keystoneclient
OpenStack keystonemiddleware does not verify certificate
org.apache.hadoop:hadoop-common
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
org.apache.hadoop:hadoop-common
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
glance, glance
OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service
glance/ glance
OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service
glance
OpenStack Image Service (Glance) allows remote authenticated users to read arbitrary file
glance
OpenStack Image Service (Glance) allows remote authenticated users to read arbitrary file
doctrine/annotations, doctrine/cache, doctrine/common, doctrine/common, doctrine/orm, doctrine/mongodb-odm, doctrine/mongodb-odm-bundle, zendframework/zendframework1, zendframework/zend-cache, aws/aws-sdk-php, doctrine/cache, zendframework/zend-cache, zendframework/zendframework, zfcampus/zf-apigility-doctrine
Doctrine Security Misconfiguration Vulnerability
doctrine/annotations/ doctrine/cache/ doctrine/common/ doctrine/common/ doctrine/orm/ doctrine/mongodb-odm/ doctrine/mongodb-odm-bundle/ zendframework/zendframework1/ zendframework/zend-cache/ aws/aws-sdk-php/ doctrine/cache/ zendframework/zend-cache/ zendframework/zendframework/ zfcampus/zf-apigility-doctrine
Doctrine Security Misconfiguration Vulnerability
zendframework/zendframework1
Zend Framework SQL injection vector using null byte for PDO
zendframework/zendframework1
Zend Framework SQL injection vector using null byte for PDO
glance
OpenStack Image Service (Glance) vulnerable to Improper Access Control
glance
OpenStack Image Service (Glance) vulnerable to Improper Access Control
radicale
Radicale is vulnerable to directory traversal on Windows Filesystem Storage Backend component
radicale
Radicale is vulnerable to directory traversal on Windows Filesystem Storage Backend component
phpmyadmin/phpmyadmin, phpmyadmin/phpmyadmin, phpmyadmin/phpmyadmin
phpMyAdmin Cryptographic Vulnerability
phpmyadmin/phpmyadmin/ phpmyadmin/phpmyadmin/ phpmyadmin/phpmyadmin
phpMyAdmin Cryptographic Vulnerability
django
Django Access Restrictions Bypass
org.apache.struts:struts2-core
Apache Struts XSS Vulnerability
org.apache.struts:struts2-core
Apache Struts XSS Vulnerability
org.apache.struts:struts2-core, org.apache.struts:struts2-core, org.apache.struts:struts2-core
Remote Code Execution in Apache Struts
org.apache.struts:struts2-core/ org.apache.struts:struts2-core/ org.apache.struts:struts2-core
Remote Code Execution in Apache Struts
org.apache.struts:struts2-core, ognl:ognl
Denial of service in Apache Struts
org.apache.struts:struts2-core/ ognl:ognl
Denial of service in Apache Struts
keystone
OpenStack Identity Keystone Improper Access Control
keystone
OpenStack Identity Keystone Improper Access Control
neutron, neutron
OpenStack Neutron Intended MAC-spoofing protection mechanism bypass
neutron/ neutron
OpenStack Neutron Intended MAC-spoofing protection mechanism bypass
drupal/core, drupal/drupal
Drupal Views can allow unauthorized users to see Statistics information
drupal/core/ drupal/drupal
Drupal Views can allow unauthorized users to see Statistics information
drupal/core, drupal/drupal
Drupal Saving user accounts can sometimes grant the user all roles
drupal/core/ drupal/drupal
Drupal Saving user accounts can sometimes grant the user all roles
jwcrypto
jwcrypto lacks the Random Filling protection mechanism
jwcrypto
jwcrypto lacks the Random Filling protection mechanism
drupal/core, drupal/drupal
Drupal Denial of service via transliterate mechanism
drupal/core/ drupal/drupal
Drupal Denial of service via transliterate mechanism
moodle/moodle
Moodle Unrestricted file upload vulnerability
moodle/moodle
Moodle Unrestricted file upload vulnerability
moodle/moodle
Moodle XSS Vulnerability
drupal/core, drupal/drupal
Drupal Incorrect cache context on password reset page
drupal/core/ drupal/drupal
Drupal Incorrect cache context on password reset page
org.opensaml:opensaml, edu.internet2.middleware:shibboleth-identityprovider
Improper Certificate Validation in Shibboleth Identity Provider and OpenSAML
org.opensaml:opensaml/ edu.internet2.middleware:shibboleth-identityprovider
Improper Certificate Validation in Shibboleth Identity Provider and OpenSAML
org.apache.hadoop:hadoop-common, org.apache.hadoop:hadoop-common
Improper Access Control in Apache Hadoop
org.apache.hadoop:hadoop-common/ org.apache.hadoop:hadoop-common
Improper Access Control in Apache Hadoop
mediaelement, contao-components/mediaelement, contao/core
MediaElement Vulnerable to Reflected XSS
mediaelement/ contao-components/mediaelement/ contao/core
MediaElement Vulnerable to Reflected XSS
slim/slim
Slim vulnerable to PHP object injection
django, django
Django Cross-site Scripting Vulnerability
