Open Source Vulnerabilities
neutron, neutron
OpenStack Neutron allows remote authenticated users to cause a denial of service
neutron/ neutron
OpenStack Neutron allows remote authenticated users to cause a denial of service
glance
OpenStack Glance improper validation of the image_size_cap configuration option
glance
OpenStack Glance improper validation of the image_size_cap configuration option
drupal/core, drupal/core
Drupal Open Redirect
drupal/core, drupal/core, drupal/drupal, drupal/drupal
Drupal sensitive information disclosure
drupal/core/ drupal/core/ drupal/drupal/ drupal/drupal
Drupal sensitive information disclosure
bottle
bottle.py vulnerable to CRLF Injection
web2py
Web2py Reflected XSS vulnerability
urllib3
Urllib3 Incorrect Certificate Validation
trytond, trytond, trytond, trytond, trytond
Tryton allow authenticated users with certain permissions to read arbitrary files via the name parameter
trytond/ trytond/ trytond/ trytond/ trytond
Tryton allow authenticated users with certain permissions to read arbitrary files via the name parameter
com.liferay.portal:portal-impl, com.liferay.portal:portal-service
Shell command injection in Liferay Portal
com.liferay.portal:portal-impl/ com.liferay.portal:portal-service
Shell command injection in Liferay Portal
web2py
Web2py Cross-Site Request Forgery vulnerability
typo3/cms
TYPO3 Backend component Cross-site scripting (XSS) vulnerability
typo3/cms
TYPO3 Backend component Cross-site scripting (XSS) vulnerability
moodle/moodle
Moodle Glossary search displays entries without checking user permissions to view them
moodle/moodle
Moodle Glossary search displays entries without checking user permissions to view them
moodle/moodle, moodle/moodle
Moodle Cross-site Scripting in assignment submission page
moodle/moodle/ moodle/moodle
Moodle Cross-site Scripting in assignment submission page
typo3/cms-extbase, typo3/cms-extbase, typo3/cms-extbase
Extbase for TYPO3 allows RCE
typo3/cms-extbase/ typo3/cms-extbase/ typo3/cms-extbase
Extbase for TYPO3 allows RCE
priority
priority vulnerable to denial of service
python-jose
python-jose failure to use a constant time comparison for HMAC keys
python-jose
python-jose failure to use a constant time comparison for HMAC keys
moin
MoinMoin Cross-site Scripting (XSS) vulnerability
moin
MoinMoin Cross-site Scripting (XSS) vulnerability
moin
MoinMoin Cross-site Scripting (XSS) vulnerability
salt, salt
Salt Insecure configuration of PAM external authentication service
salt/ salt
Salt Insecure configuration of PAM external authentication service
salt
Salt allows deleted minions to read or write to minions with the same id
salt
Salt allows deleted minions to read or write to minions with the same id
plone, plone
Plone XSS in Zope ZMI
org.apache.poi:poi
Loop with Unreachable Exit Condition in Apache POI
org.apache.poi:poi
Loop with Unreachable Exit Condition in Apache POI
openpyxl
Improper Restriction of XML External Entity Reference in Openpyxl
openpyxl
Improper Restriction of XML External Entity Reference in Openpyxl
flask-oidc
flask-oidc Open Redirect vulnerability
mantisbt/mantisbt, mantisbt/mantisbt
MantisBT XSS through weak CSP when using Gravatar plugin
mantisbt/mantisbt/ mantisbt/mantisbt
MantisBT XSS through weak CSP when using Gravatar plugin
html5lib
Improper Neutralization of Input During Web Page Generation in html5lib
html5lib
Improper Neutralization of Input During Web Page Generation in html5lib
html5lib
Cross-site Scripting in html5lib
froxlor/froxlor
Froxlor guessable password reset token
plone, plone
Plone vulnerable to unauthorized disclosure of site content
plone/ plone
Plone vulnerable to unauthorized disclosure of site content
plone, plone, plone
Plone vulnerable to privilege escalation in WebDAV
plone/ plone/ plone
Plone vulnerable to privilege escalation in WebDAV
org.jenkins-ci.plugins:script-security
Jenkins Script Security Plugin allows for Bypass of Groovy Sandbox Protection
org.jenkins-ci.plugins:script-security
Jenkins Script Security Plugin allows for Bypass of Groovy Sandbox Protection
plone, plone
Chameleon in Plone allows Authentication Bypass
plone/ plone
Chameleon in Plone allows Authentication Bypass
movim/moxl
XMPP Clients User Impersonation Vulnerability in Movim Moxl
movim/moxl
XMPP Clients User Impersonation Vulnerability in Movim Moxl
salt
Salt uses weak permissions on the cache data
Umbraco.CMS
Umbraco CMS vulnerable to CSRF
Umbraco.CMS
Umbraco CMS vulnerable to CSRF
pysaml2
PySAML2 XML external entity attack
gethue
Cloudera HUE Account Enumeration
epiceditor
EpicEditor XSS Vulnerability
bcit-ci/codeigniter
CodeIgniter arbitrary code execution
weblate
Weblate user account enumeration via reset password form
weblate
Weblate user account enumeration via reset password form
org.apache.hadoop:hadoop-client
Client BlockTokens not checked in Apache Hadoop
org.apache.hadoop:hadoop-client
Client BlockTokens not checked in Apache Hadoop
org.apache.hadoop:hadoop-common, org.apache.hadoop:hadoop-common
Improper Authentication in Apache Hadoop
org.apache.hadoop:hadoop-common/ org.apache.hadoop:hadoop-common
Improper Authentication in Apache Hadoop
org.apache.hadoop:hadoop-main, org.apache.hadoop:hadoop-main
Apache Hadoop allows impersonation of arbitrary cluster user accounts
org.apache.hadoop:hadoop-main/ org.apache.hadoop:hadoop-main
Apache Hadoop allows impersonation of arbitrary cluster user accounts
imdbphp/imdbphp
imdbphp Cross-Site Scripting (XSS)
org.apache.hadoop:hadoop-common, org.apache.hadoop:hadoop-common
Improper Authentication in Apache Hadoop
org.apache.hadoop:hadoop-common/ org.apache.hadoop:hadoop-common
Improper Authentication in Apache Hadoop
security-monkey
Netflix Security Monkey Open Redirect vulnerability
security-monkey
Netflix Security Monkey Open Redirect vulnerability
cherrymusic
Cherry Music directory traversal vulnerability
cherrymusic
Cherry Music directory traversal vulnerability
cherrymusic
Cherry Music Cross-site Scripting (XSS) vulnerability
cherrymusic
Cherry Music Cross-site Scripting (XSS) vulnerability
