Open Source Vulnerabilities
formencode
FormEncode Access Restrictions Bypass
moin, moin
MoinMoin Access Restrictions Bypassed due to improper ACL enforcement
moin/ moin
MoinMoin Access Restrictions Bypassed due to improper ACL enforcement
cobbler
Cobbler Web Interface Kickstart Template Remote Privilege Escalation Vulnerability
cobbler
Cobbler Web Interface Kickstart Template Remote Privilege Escalation Vulnerability
ocrodjvu
ocrodjvu is vulnerable to Arbitrary File Modification via symlink attack
ocrodjvu
ocrodjvu is vulnerable to Arbitrary File Modification via symlink attack
ec-cube/ec-cube
EC-CUBE XSS Vulnerabilities
loggerhead
Loggerhead XSS via filename
plone
Plone Privilege Escalation Vulnerability
phpmyadmin/phpmyadmin, phpmyadmin/phpmyadmin
phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file
phpmyadmin/phpmyadmin/ phpmyadmin/phpmyadmin
phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file
moin
MoinMoin Cross-site Scripting (XSS) vulnerability
org.apache.tomcat:tomcat
Apache Tomcat does not follow ServletSecurity annotations
org.apache.tomcat:tomcat
Apache Tomcat does not follow ServletSecurity annotations
qooxdoo
QooxDoo XSS in Callback Parameter
salt, salt
salt password information leaked in debug logs
restkit
Restkit Does Not Validate TLS certificates
com.google.gwt:gwt
Improper Neutralization of Input During Web Page Generation in Google Web Toolkit
com.google.gwt:gwt
Improper Neutralization of Input During Web Page Generation in Google Web Toolkit
org.springframework.batch:spring-batch-admin-manager
Spring Batch Admin vulnerable to Cross-site request forgery (CSRF) in the file upload functionality
org.springframework.batch:spring-batch-admin-manager
Spring Batch Admin vulnerable to Cross-site request forgery (CSRF) in the file upload functionality
django-cms, django-cms
django-cms CSRF Vulnerability
org.springframework.batch:spring-batch-admin-manager
Spring Batch Admin vulnerable to Stored Cross-site scripting (XSS) in the file upload functionality
org.springframework.batch:spring-batch-admin-manager
Spring Batch Admin vulnerable to Stored Cross-site scripting (XSS) in the file upload functionality
nova
OpenStack Compute (Nova) Improper Access Control
Microsoft.ChakraCore
ChakraCore RCE Vulnerability
attic
attic has improper verification of unencrypted backups
attic
attic has improper verification of unencrypted backups
trove
Openstack DBaaS (Trove) Improper Link Resolution Before File Access
trove
Openstack DBaaS (Trove) Improper Link Resolution Before File Access
dmk/webkitpdf
Webkit PDFs for TYPO3 allows remote attackers to execute arbitrary commands
dmk/webkitpdf
Webkit PDFs for TYPO3 allows remote attackers to execute arbitrary commands
dmk/webkitpdf
Webkit PDFs for TYPO3 has SQL Injection vulnerability
dmk/webkitpdf
Webkit PDFs for TYPO3 has SQL Injection vulnerability
typo3/cms-frontend, typo3/cms-frontend
TYPO3 Cross-site scripting (XSS) vulnerability in the click enlarge functionality
typo3/cms-frontend/ typo3/cms-frontend
TYPO3 Cross-site scripting (XSS) vulnerability in the click enlarge functionality
typo3/cms-frontend, typo3/cms-frontend, typo3/cms-frontend
TYPO3 Cross-site scripting (XSS) vulnerability in the FORM content object
typo3/cms-frontend/ typo3/cms-frontend/ typo3/cms-frontend
TYPO3 Cross-site scripting (XSS) vulnerability in the FORM content object
typo3/cms, typo3/cms, typo3/cms
TYPO3 Path Traversal vulnerability
typo3/cms/ typo3/cms/ typo3/cms
TYPO3 Path Traversal vulnerability
typo3/cms-install, typo3/cms-install, typo3/cms-install
TYPO3 Cross-Site Scripting vulnerability in the Install Tool
typo3/cms-install/ typo3/cms-install/ typo3/cms-install
TYPO3 Cross-Site Scripting vulnerability in the Install Tool
typo3/cms, typo3/cms, typo3/cms
TYPO3 Directory Traversal vulnerability
typo3/cms/ typo3/cms/ typo3/cms
TYPO3 Directory Traversal vulnerability
typo3/cms-core, typo3/cms-core, typo3/cms-core
TYPO3 Sensitive Information Disclosure via escapeStrForLike method
typo3/cms-core/ typo3/cms-core/ typo3/cms-core
TYPO3 Sensitive Information Disclosure via escapeStrForLike method
typo3/cms, typo3/cms, typo3/cms
TYPO3 SQL Injection vulnerability
typo3/cms/ typo3/cms/ typo3/cms
TYPO3 SQL Injection vulnerability
phpmyadmin/phpmyadmin
phpMyAdmin Directory Traversal Vulnerability
phpmyadmin/phpmyadmin
phpMyAdmin Directory Traversal Vulnerability
phpmyadmin/phpmyadmin, phpmyadmin/phpmyadmin
phpMyAdmin vulnerable to XML external entity (XXE) injection attack
phpmyadmin/phpmyadmin/ phpmyadmin/phpmyadmin
phpMyAdmin vulnerable to XML external entity (XXE) injection attack
symphonycms/symphony-2
Symphony CMS vulnerable to Cross-site Scripting
symphonycms/symphony-2
Symphony CMS vulnerable to Cross-site Scripting
phpmyadmin/phpmyadmin
phpMyAdmin Cross-site Scripting vulnerability
phpmyadmin/phpmyadmin
phpMyAdmin Cross-site Scripting vulnerability
org.jboss.resteasy:resteasy-jaxb-provider
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
org.jboss.resteasy:resteasy-jaxb-provider
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
org.jboss.resteasy:resteasy-client
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
org.jboss.resteasy:resteasy-client
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
org.apache.struts:struts2-parent, org.apache.struts:struts2-parent
Apache Struts Multiple Cross-site Scripting Vulnerabilities
org.apache.struts:struts2-parent/ org.apache.struts:struts2-parent
Apache Struts Multiple Cross-site Scripting Vulnerabilities
pyfribidi
PyFriBidi Buffer overflow in the fribidi_utf8_to_unicode function
pyfribidi
PyFriBidi Buffer overflow in the fribidi_utf8_to_unicode function
forkcms/forkcms
Fork CMS Multiple XSS Vulnerabilities
forkcms/forkcms
ForkCMS Directory Traversal vulnerability
elefant/cms, elefant/cms
Elefant CMS Multiple XSS Vulnerabilities
elefant/cms/ elefant/cms
Elefant CMS Multiple XSS Vulnerabilities
horizon
OpenStack Horizon Cross-site scripting (XSS) vulnerability
horizon
OpenStack Horizon Cross-site scripting (XSS) vulnerability
nova
Openstack Compute (Nova) Denial of service via network request that triggers large number of iptables rules
nova
Openstack Compute (Nova) Denial of service via network request that triggers large number of iptables rules
typo3/cms, typo3/cms, typo3/cms, typo3/cms
Typo3 Exception Handler XSS
typo3/cms/ typo3/cms/ typo3/cms/ typo3/cms
Typo3 Exception Handler XSS
horizon
OpenStack Horizon Session Fixation
pycrypto
PyCrypto makes Use of Insufficiently Random Values
pycrypto
PyCrypto makes Use of Insufficiently Random Values
nova
OpenStack Compute (Nova) Improper Input Validation
nova
Arbitrary file overwrite in OpenStack Nova
org.apache.qpid:qpid-parent
Apache QPID Allows Remote Authentication Bypass
org.apache.qpid:qpid-parent
Apache QPID Allows Remote Authentication Bypass
typo3/cms, typo3/cms, typo3/cms
TYPO3 allows remote authenticated backend users to unserialize arbitrary objects
typo3/cms/ typo3/cms/ typo3/cms
TYPO3 allows remote authenticated backend users to unserialize arbitrary objects
