Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-x53v-v9xp-gf6g
    Fix available
    Packages

    mantisbt/mantisbt, mantisbt/mantisbt, mantisbt/mantisbt

    Summary

    MantisBT XSS via move_attachments_page.php

    Published
    17 May 2022
    GHSA-v7qf-22rw-chph
    Fix available
    Packages

    mantisbt/mantisbt, mantisbt/mantisbt, mantisbt/mantisbt

    Summary

    MantisBT XSS via adm_config_report.php's action parameter

    Published
    17 May 2022
    GHSA-4w6c-3hcx-rfj5
    Fix available
    Packages

    mantisbt/mantisbt, mantisbt/mantisbt, mantisbt/mantisbt

    Summary

    MantisBT vulnerable to XSS through config_option parameter in adm_config_report.php

    Published
    17 May 2022
    GHSA-pxj9-mw96-q634
    Fix available
    Packages

    org.apache.openmeetings:openmeetings-parent

    Summary

    Apache OpenMeetings Cross-site Scripting vulnerability

    Published
    17 May 2022
    GHSA-335g-xcjh-ghc2
    Fix available
    Packages

    org.apache.openmeetings:openmeetings-parent

    Summary

    Apache OpenMeetings vulnerable to SQL injection

    Published
    17 May 2022
    GHSA-4v67-wg88-37p9
    Fix available
    Packages

    org.apache.openmeetings:openmeetings-parent

    Summary

    Apache OpenMeetings displays Tomcat version and detailed error stack trace

    Published
    17 May 2022
    GHSA-67q3-gwww-pm4g
    Fix available
    Packages

    org.apache.openmeetings:openmeetings-parent

    Summary

    Apache OpenMeetings does not correctly validate uploaded XML documents

    Published
    17 May 2022
    GHSA-m5pm-rgvf-vg22
    Fix available
    Packages

    org.apache.openmeetings:openmeetings-parent

    Summary

    Apache OpenMeetings vulnerable to Cross-Site Request Forgery

    Published
    17 May 2022
    GHSA-5r9j-698h-2h5m
    No fix available
    Packages

    bolt/bolt

    Summary

    Bolt stored Cross-site Scripting (XSS)

    Published
    17 May 2022
    GHSA-hqxc-w9vw-3hp5
    No fix available
    Packages

    bolt/bolt

    Summary

    Bolt CMS Stored XSS

    Published
    17 May 2022
    GHSA-54r2-r67g-fr9m
    Fix available
    Packages

    moodle/moodle, moodle/moodle, moodle/moodle

    Summary

    Moodle User fullname disclosure on user preferences page

    Published
    17 May 2022
    GHSA-phhm-6pgm-mxw9
    Fix available
    Packages

    modx/revolution

    Summary

    MODX Revolution blind SQL injection

    Published
    17 May 2022
    GHSA-7g54-vgp6-jj5w
    Fix available
    Packages

    org.apache.sling:org.apache.sling.xss, org.apache.sling:org.apache.sling.xss.compat

    Summary

    XML External Entity Reference in Apache Sling

    Published
    17 May 2022
    GHSA-4c64-w8fg-xcq2
    Fix available
    Packages

    yiisoft/yii2-dev, yiisoft/yii2

    Summary

    Yii Cross-site Scripting Framework vulnerability

    Published
    17 May 2022
    GHSA-mx3q-j2g2-5qxq
    Fix available
    Packages

    Nancy, Nancy

    Summary

    Deserialization of Untrusted Data in NancyFX Nancy

    Published
    17 May 2022
    GHSA-j2cq-h6v2-f875
    Fix available
    Packages

    phpmyadmin/phpmyadmin

    Summary

    phpMyAdmin Cookie attribute injection attack

    Published
    17 May 2022
    GHSA-92mr-4w2q-4578
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

    Published
    17 May 2022
    GHSA-8vvh-crqv-jm64
    Fix available
    Packages

    org.apache.qpid:qpid-broker, org.apache.qpid:qpid-broker

    Summary

    Exposure of Sensitive Information to an Unauthorized Actor in Apache Qpid Broker for Java

    Published
    17 May 2022
    GHSA-4fxw-g29w-r8mx
    Fix available
    Packages

    org.apache.solr:solr

    Summary

    Apache Solr Cross-site scripting Vulnerability

    Published
    17 May 2022
    GHSA-23vv-v25h-qwqw
    Fix available
    Packages

    org.apache.axis2.wso2:axis2

    Summary

    Improper Input Validation in Apache Axis2

    Published
    17 May 2022
    GHSA-cggm-52qp-wvw7
    Fix available
    Packages

    txaws

    Summary

    txAWS AWSServiceEndpoint defaults to not verifying server certificates

    Published
    17 May 2022
    GHSA-c9r9-3h38-r7vj
    No fix available
    Packages

    zencart/zencart

    Summary

    Authenticated RCE in Zen Cart 1.5.5e

    Published
    17 May 2022
    GHSA-4vwv-x3gp-2j4g
    Fix available
    Packages

    org.wildfly:wildfly-parent

    Summary

    The Undertow module of WildFly allows source code disclosure

    Published
    17 May 2022
    GHSA-ph2j-5hxq-gxrr
    Fix available
    Packages

    drupal/drupal

    Summary

    Drupal Node Validation Bypass in the node module API

    Published
    17 May 2022
    GHSA-x7r4-26m9-hmgq
    Fix available
    Packages

    moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle

    Summary

    Moodle vulnerable to symlink attack

    Published
    17 May 2022
    GHSA-437p-qw95-wqqr
    Fix available
    Packages

    trac

    Summary

    Trac vulnerable to denial of service

    Published
    17 May 2022
    GHSA-733v-22mg-7f8w
    Fix available
    Packages

    typo3/cms-backend

    Summary

    TYPO3 Cross-site Scripting vulnerability in the file backend module

    Published
    17 May 2022
    GHSA-xvx2-wqf5-jjgv
    Fix available
    Packages

    typo3/cms-felogin

    Summary

    typo3/cms-felogin Cross-site Scripting vulnerability

    Published
    17 May 2022
    GHSA-ww53-wxxr-8f9w
    Fix available
    Packages

    trac

    Summary

    Trac has vulnerability in HTML sanitizer filter

    Published
    17 May 2022
    GHSA-m3p9-c7p3-xxmp
    Fix available
    Packages

    com.github.seasarorg.mayaa:mayaa

    Summary

    Mayaa Cross-site Scripting vulnerability

    Published
    17 May 2022
    GHSA-wv88-pf73-x22p
    Fix available
    Packages

    org.springframework:spring-core, org.springframework:spring-core, org.springframework:spring-core

    Summary

    Improper Neutralization of Directives in Dynamically Evaluated Code in Spring Framework

    Published
    17 May 2022
    GHSA-xm92-v2mq-842q
    Fix available
    Packages

    org.apache.struts:struts2-core, org.apache.struts:struts2-core

    Summary

    Apache Struts improper action name cleanup

    Published
    17 May 2022
    GHSA-xg75-68x3-7p3q
    Fix available
    Packages

    org.apache.struts:struts2-core, org.apache.struts:struts2-core

    Summary

    Apache Struts vulnerable to possible DoS attack when using URLValidator

    Published
    17 May 2022
    GHSA-wm8w-qp2f-728q
    Fix available
    Packages

    org.apache.struts.xwork:xwork-core

    Summary

    Apache Struts Open Redirect

    Published
    17 May 2022
    GHSA-vq79-mgpx-2wx4
    Fix available
    Packages

    org.apache.struts:struts-parent

    Summary

    Apache Struts Access Control Redirect

    Published
    17 May 2022
    GHSA-75x7-w445-5gwr
    Fix available
    Packages

    com.liferay.portal:release.portal.bom

    Summary

    Liferay Portal Vulnerable to XSS via a Knowledge Base Article Title

    Published
    17 May 2022
    GHSA-8gqf-26xw-x3gx
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay:com.liferay.login.authentication.openid.connect.web, com.liferay:com.liferay.login.web

    Summary

    Liferay Portal XSS Vulnerability

    Published
    17 May 2022
    GHSA-cm99-x97g-9qx8
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay:com.liferay.frontend.taglib

    Summary

    Liferay Portal XSS Vulnerability

    Published
    17 May 2022
    GHSA-p7vm-phxx-g722
    Fix available
    Packages

    org.apache.commons:commons-email

    Summary

    Improper Input Validation in Apache Commons Email

    Published
    17 May 2022
    GHSA-6q67-5wvc-rmw9
    Fix available
    Packages

    com.liferay.portal:release.portal.bom

    Summary

    Liferay Portal Vulnerable to XSS via Mishandled Title or Summary in the Web Content Display

    Published
    17 May 2022
    GHSA-cvrj-cw2f-25qw
    Fix available
    Packages

    com.liferay.portal:release.portal.bom

    Summary

    Liferay Portal Vulnerable to XSS via an Invalid portletId

    Published
    17 May 2022
    GHSA-jmjf-cmq5-7w25
    Fix available
    Packages

    com.liferay.portal:release.portal.bom

    Summary

    Liferay Portal Vulnerable to XSS via a Crafted Redirect Field

    Published
    17 May 2022
    GHSA-qmvq-f3fj-m3wg
    Fix available
    Packages

    openpgp

    Summary

    OpenPGP 1.2.0 and earlier decrypts arbitrary messages

    Published
    17 May 2022
    GHSA-6pvw-hh48-jx7p
    Fix available
    Packages

    craftcms/cms

    Summary

    Craft CMS XSS Vulnerability

    Published
    17 May 2022
    GHSA-7fv9-m79r-j9x8
    Fix available
    Packages

    electron

    Summary

    Electron vulnerable to remote command execution

    Published
    17 May 2022
    GHSA-h6m7-jphx-f9p5
    Fix available
    Packages

    Microsoft.ChakraCore

    Summary

    ChakraCore information disclosure vulnerability

    Published
    17 May 2022
    GHSA-w93w-rx52-24qh
    Fix available
    Packages

    mantisbt/mantisbt

    Summary

    MantisBT vulnerable to XSS via unsanitized filter field in manage_user_page.php

    Published
    17 May 2022
    GHSA-xhq3-455r-xv44
    Fix available
    Packages

    moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle

    Summary

    Moodle SQL injection via user preferences

    Published
    17 May 2022
    GHSA-rrmf-fpmm-jpwr
    No fix available
    Packages

    opensolutions/vimbadmin

    Summary

    ViMbAdmin CSRF Vulnerabilities

    Published
    17 May 2022
    GHSA-wxw2-2mx5-c5qf
    Fix available
    Packages

    com.opensymphony:xwork, com.opensymphony:xwork

    Summary

    Improper Input Validation in OpenSymphony XWork

    Published
    17 May 2022