Open Source Vulnerabilities
mantisbt/mantisbt, mantisbt/mantisbt, mantisbt/mantisbt
MantisBT XSS via move_attachments_page.php
mantisbt/mantisbt/ mantisbt/mantisbt/ mantisbt/mantisbt
MantisBT XSS via move_attachments_page.php
mantisbt/mantisbt, mantisbt/mantisbt, mantisbt/mantisbt
MantisBT XSS via adm_config_report.php's action parameter
mantisbt/mantisbt/ mantisbt/mantisbt/ mantisbt/mantisbt
MantisBT XSS via adm_config_report.php's action parameter
mantisbt/mantisbt, mantisbt/mantisbt, mantisbt/mantisbt
MantisBT vulnerable to XSS through config_option parameter in adm_config_report.php
mantisbt/mantisbt/ mantisbt/mantisbt/ mantisbt/mantisbt
MantisBT vulnerable to XSS through config_option parameter in adm_config_report.php
org.apache.openmeetings:openmeetings-parent
Apache OpenMeetings Cross-site Scripting vulnerability
org.apache.openmeetings:openmeetings-parent
Apache OpenMeetings Cross-site Scripting vulnerability
org.apache.openmeetings:openmeetings-parent
Apache OpenMeetings vulnerable to SQL injection
org.apache.openmeetings:openmeetings-parent
Apache OpenMeetings vulnerable to SQL injection
org.apache.openmeetings:openmeetings-parent
Apache OpenMeetings displays Tomcat version and detailed error stack trace
org.apache.openmeetings:openmeetings-parent
Apache OpenMeetings displays Tomcat version and detailed error stack trace
org.apache.openmeetings:openmeetings-parent
Apache OpenMeetings does not correctly validate uploaded XML documents
org.apache.openmeetings:openmeetings-parent
Apache OpenMeetings does not correctly validate uploaded XML documents
org.apache.openmeetings:openmeetings-parent
Apache OpenMeetings vulnerable to Cross-Site Request Forgery
org.apache.openmeetings:openmeetings-parent
Apache OpenMeetings vulnerable to Cross-Site Request Forgery
bolt/bolt
Bolt stored Cross-site Scripting (XSS)
moodle/moodle, moodle/moodle, moodle/moodle
Moodle User fullname disclosure on user preferences page
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle User fullname disclosure on user preferences page
modx/revolution
MODX Revolution blind SQL injection
org.apache.sling:org.apache.sling.xss, org.apache.sling:org.apache.sling.xss.compat
XML External Entity Reference in Apache Sling
org.apache.sling:org.apache.sling.xss/ org.apache.sling:org.apache.sling.xss.compat
XML External Entity Reference in Apache Sling
yiisoft/yii2-dev, yiisoft/yii2
Yii Cross-site Scripting Framework vulnerability
yiisoft/yii2-dev/ yiisoft/yii2
Yii Cross-site Scripting Framework vulnerability
Nancy, Nancy
Deserialization of Untrusted Data in NancyFX Nancy
Nancy/ Nancy
Deserialization of Untrusted Data in NancyFX Nancy
phpmyadmin/phpmyadmin
phpMyAdmin Cookie attribute injection attack
phpmyadmin/phpmyadmin
phpMyAdmin Cookie attribute injection attack
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
org.apache.qpid:qpid-broker, org.apache.qpid:qpid-broker
Exposure of Sensitive Information to an Unauthorized Actor in Apache Qpid Broker for Java
org.apache.qpid:qpid-broker/ org.apache.qpid:qpid-broker
Exposure of Sensitive Information to an Unauthorized Actor in Apache Qpid Broker for Java
org.apache.solr:solr
Apache Solr Cross-site scripting Vulnerability
org.apache.solr:solr
Apache Solr Cross-site scripting Vulnerability
org.apache.axis2.wso2:axis2
Improper Input Validation in Apache Axis2
org.apache.axis2.wso2:axis2
Improper Input Validation in Apache Axis2
txaws
txAWS AWSServiceEndpoint defaults to not verifying server certificates
txaws
txAWS AWSServiceEndpoint defaults to not verifying server certificates
zencart/zencart
Authenticated RCE in Zen Cart 1.5.5e
org.wildfly:wildfly-parent
The Undertow module of WildFly allows source code disclosure
org.wildfly:wildfly-parent
The Undertow module of WildFly allows source code disclosure
drupal/drupal
Drupal Node Validation Bypass in the node module API
drupal/drupal
Drupal Node Validation Bypass in the node module API
moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle
Moodle vulnerable to symlink attack
moodle/moodle/ moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle vulnerable to symlink attack
trac
Trac vulnerable to denial of service
typo3/cms-backend
TYPO3 Cross-site Scripting vulnerability in the file backend module
typo3/cms-backend
TYPO3 Cross-site Scripting vulnerability in the file backend module
typo3/cms-felogin
typo3/cms-felogin Cross-site Scripting vulnerability
typo3/cms-felogin
typo3/cms-felogin Cross-site Scripting vulnerability
trac
Trac has vulnerability in HTML sanitizer filter
com.github.seasarorg.mayaa:mayaa
Mayaa Cross-site Scripting vulnerability
com.github.seasarorg.mayaa:mayaa
Mayaa Cross-site Scripting vulnerability
org.springframework:spring-core, org.springframework:spring-core, org.springframework:spring-core
Improper Neutralization of Directives in Dynamically Evaluated Code in Spring Framework
org.springframework:spring-core/ org.springframework:spring-core/ org.springframework:spring-core
Improper Neutralization of Directives in Dynamically Evaluated Code in Spring Framework
org.apache.struts:struts2-core, org.apache.struts:struts2-core
Apache Struts improper action name cleanup
org.apache.struts:struts2-core/ org.apache.struts:struts2-core
Apache Struts improper action name cleanup
org.apache.struts:struts2-core, org.apache.struts:struts2-core
Apache Struts vulnerable to possible DoS attack when using URLValidator
org.apache.struts:struts2-core/ org.apache.struts:struts2-core
Apache Struts vulnerable to possible DoS attack when using URLValidator
org.apache.struts.xwork:xwork-core
Apache Struts Open Redirect
org.apache.struts.xwork:xwork-core
Apache Struts Open Redirect
org.apache.struts:struts-parent
Apache Struts Access Control Redirect
org.apache.struts:struts-parent
Apache Struts Access Control Redirect
com.liferay.portal:release.portal.bom
Liferay Portal Vulnerable to XSS via a Knowledge Base Article Title
com.liferay.portal:release.portal.bom
Liferay Portal Vulnerable to XSS via a Knowledge Base Article Title
com.liferay.portal:release.portal.bom, com.liferay:com.liferay.login.authentication.openid.connect.web, com.liferay:com.liferay.login.web
Liferay Portal XSS Vulnerability
com.liferay.portal:release.portal.bom/ com.liferay:com.liferay.login.authentication.openid.connect.web/ com.liferay:com.liferay.login.web
Liferay Portal XSS Vulnerability
com.liferay.portal:release.portal.bom, com.liferay:com.liferay.frontend.taglib
Liferay Portal XSS Vulnerability
com.liferay.portal:release.portal.bom/ com.liferay:com.liferay.frontend.taglib
Liferay Portal XSS Vulnerability
org.apache.commons:commons-email
Improper Input Validation in Apache Commons Email
org.apache.commons:commons-email
Improper Input Validation in Apache Commons Email
com.liferay.portal:release.portal.bom
Liferay Portal Vulnerable to XSS via Mishandled Title or Summary in the Web Content Display
com.liferay.portal:release.portal.bom
Liferay Portal Vulnerable to XSS via Mishandled Title or Summary in the Web Content Display
com.liferay.portal:release.portal.bom
Liferay Portal Vulnerable to XSS via an Invalid portletId
com.liferay.portal:release.portal.bom
Liferay Portal Vulnerable to XSS via an Invalid portletId
com.liferay.portal:release.portal.bom
Liferay Portal Vulnerable to XSS via a Crafted Redirect Field
com.liferay.portal:release.portal.bom
Liferay Portal Vulnerable to XSS via a Crafted Redirect Field
openpgp
OpenPGP 1.2.0 and earlier decrypts arbitrary messages
openpgp
OpenPGP 1.2.0 and earlier decrypts arbitrary messages
craftcms/cms
Craft CMS XSS Vulnerability
electron
Electron vulnerable to remote command execution
Microsoft.ChakraCore
ChakraCore information disclosure vulnerability
Microsoft.ChakraCore
ChakraCore information disclosure vulnerability
mantisbt/mantisbt
MantisBT vulnerable to XSS via unsanitized filter field in manage_user_page.php
mantisbt/mantisbt
MantisBT vulnerable to XSS via unsanitized filter field in manage_user_page.php
moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle
Moodle SQL injection via user preferences
moodle/moodle/ moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle SQL injection via user preferences
opensolutions/vimbadmin
ViMbAdmin CSRF Vulnerabilities
com.opensymphony:xwork, com.opensymphony:xwork
Improper Input Validation in OpenSymphony XWork
com.opensymphony:xwork/ com.opensymphony:xwork
Improper Input Validation in OpenSymphony XWork
