Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-7w6c-5pr4-7qvp
    Fix available
    Packages

    typo3/cms, typo3/cms, typo3/cms

    Summary

    Typo3 Backend XSS Vulnerability

    Published
    17 May 2022
    GHSA-7gg8-3r6j-5g55
    Fix available
    Packages

    typo3/cms, typo3/cms, typo3/cms

    Summary

    Typo3 Backend Configuration XSS Vulnerability

    Published
    17 May 2022
    GHSA-94c2-g68f-9r98
    Fix available
    Packages

    typo3/cms, typo3/cms, typo3/cms

    Summary

    Typo3 API XSS Vulnerability

    Published
    17 May 2022
    GHSA-p9wg-jvj4-cx26
    Fix available
    Packages

    typo3/cms, typo3/cms, typo3/cms

    Summary

    Typo3 Install Tool XSS Vulnerability

    Published
    17 May 2022
    GHSA-2rvh-q539-q33v
    Fix available
    Packages

    org.apache.struts:struts2-core

    Summary

    Cross-Site Request Forgery in Apache Struts

    Published
    17 May 2022
    GHSA-hrgc-54mv-58gv
    Fix available
    Packages

    org.apache.struts.xwork:xwork-core

    Summary

    Denial of service in Apache Struts

    Published
    17 May 2022
    GHSA-v7mh-3jgf-r26c
    Fix available
    Packages

    swift

    Summary

    OpenStack Object Storage (swift) Code Injection vulnerability

    Published
    17 May 2022
    GHSA-mrxv-65rv-6hxq
    Fix available
    Packages

    keystone

    Summary

    OpenStack Keystone does not invalidate existing tokens when granting or revoking roles

    Published
    17 May 2022
    GHSA-6rrm-xxvh-7r87
    Fix available
    Packages

    glance

    Summary

    OpenStack Glance arbitrary deletion of non-protected images

    Published
    17 May 2022
    GHSA-vwr9-9f8v-vp5m
    Fix available
    Packages

    glance

    Summary

    OpenStack Glance arbitrary deletion of non-protected images

    Published
    17 May 2022
    GHSA-qvpr-qm6w-6rcc
    Fix available
    Packages

    keystone

    Summary

    OpenStack Keystone intended authorization restrictions bypass

    Published
    17 May 2022
    GHSA-w66p-78g4-mr7g
    Fix available
    Packages

    keystone

    Summary

    OpenStack Keystone Insufficient token expiration

    Published
    17 May 2022
    GHSA-wwq7-pxwc-p4rc
    Fix available
    Packages

    org.apache.axis2:axis2, org.apache.axis2:axis2-transport-http

    Summary

    Apache Axis2 has Improper Input Validation

    Published
    17 May 2022
    GHSA-5jc8-8xhv-g8qm
    No fix available
    Packages

    org.codehaus.xfire:xfire-core

    Summary

    Improper Input Validation in XFire

    Published
    17 May 2022
    GHSA-pwx5-xg7g-wpc5
    Fix available
    Packages

    tweepy

    Summary

    Tweepy does not verify SSL Certificate

    Published
    17 May 2022
    GHSA-28cq-6rmx-pjq4
    Fix available
    Packages

    org.apache.tomcat:tomcat, org.apache.tomcat:tomcat, org.apache.tomcat:tomcat

    Summary

    Improper Authentication in Apache Tomcat

    Published
    17 May 2022
    GHSA-7p53-8wjr-j8h4
    Fix available
    Packages

    b13/seo_basics

    Summary

    Basic SEO Features (seo_basics) extension TYPO3 vulnerable to Cross-site Scripting

    Published
    17 May 2022
    GHSA-9xrj-439h-62hg
    Fix available
    Packages

    org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina

    Summary

    Improper Authentication in Apache Tomcat

    Published
    17 May 2022
    GHSA-jjg9-mf63-vqrp
    No fix available
    Packages

    yui2

    Summary

    Cross-site scripting in yui 2.4.0

    Published
    17 May 2022
    GHSA-8cg3-jfjx-3pp2
    Fix available
    Packages

    in2code/powermail

    Summary

    powermail extension for TYPO3 has Cross-site Scripting vulnerability

    Published
    17 May 2022
    GHSA-m646-h2pw-56h4
    Fix available
    Packages

    sjbr/sr-feuser-register

    Summary

    Front End User Registration (sr_feuser_register) extension for TYPO3 allows remote attackers to obtain user names, passwords

    Published
    17 May 2022
    GHSA-5v6q-xqq8-g4xj
    Fix available
    Packages

    roundup

    Summary

    Roundup Cross-site Scripting (XSS) vulnerability

    Published
    17 May 2022
    GHSA-gw2q-cgvq-9g3v
    Fix available
    Packages

    roundup

    Summary

    Roundup Cross-site scripting (XSS) vulnerability

    Published
    17 May 2022
    GHSA-mccq-3m7h-fjxg
    Fix available
    Packages

    roundup

    Summary

    Roundup Cross-site Scripting (XSS) vulnerability

    Published
    17 May 2022
    GHSA-w563-rq37-cvq5
    Fix available
    Packages

    typo3/cms, typo3/cms, typo3/cms

    Summary

    Typo3 Backend History Module Vulnerable to XSS

    Published
    17 May 2022
    GHSA-947m-vgqc-x6v4
    Fix available
    Packages

    typo3/cms, typo3/cms, typo3/cms

    Summary

    Typo3 Backend History Module Vulnerable to SQL Injection

    Published
    17 May 2022
    GHSA-rgf6-9q7g-55qg
    Fix available
    Packages

    typo3/cms, typo3/cms, typo3/cms

    Summary

    Typo3 Function Menu API XSS Vulnerability

    Published
    17 May 2022
    GHSA-qmmw-ch2q-j6xx
    Fix available
    Packages

    typo3/cms, typo3/cms, typo3/cms

    Summary

    Typo3 Backend API XSS Vulnerability

    Published
    17 May 2022
    GHSA-2r5h-6r7v-5m7c
    Fix available
    Packages

    symfony/symfony, symfony/yaml

    Summary

    Symphony Vulnerable to PHP Code Injection via YAML Parsing

    Published
    17 May 2022
    GHSA-7w53-hfpw-rg3g
    Fix available
    Packages

    symfony/symfony, symfony/symfony, symfony/symfony, symfony/yaml, symfony/yaml, symfony/yaml

    Summary

    Symfony Arbitrary PHP code Execution

    Published
    17 May 2022
    GHSA-63fq-8fp9-vhwq
    Fix available
    Packages

    nova

    Summary

    OpenStack Compute (Nova) Denial of service via a large number of calls to the addFixedIp function

    Published
    17 May 2022
    GHSA-c8w9-83vg-r8vv
    Fix available
    Packages

    glance

    Summary

    OpenStack Glance is vulnerable to Exposure of Sensitive Information

    Published
    17 May 2022
    GHSA-mfhr-3xmc-r2gg
    Fix available
    Packages

    org.apache.activemq:activemq-client

    Summary

    Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ

    Published
    17 May 2022
    GHSA-4fvg-pwv7-v54g
    No fix available
    Packages

    karteek-docsplit

    Summary

    Karteek Docsplit vulnerable to OS Command Injection

    Published
    17 May 2022
    GHSA-hj89-qmx9-8qmh
    Fix available
    Packages

    keystone

    Summary

    OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user

    Published
    17 May 2022
    GHSA-8823-xphr-qw9v
    Fix available
    Packages

    portage

    Summary

    Gentoo Portage does not verify X.509 certificates from SSL servers

    Published
    17 May 2022
    GHSA-cxwh-vmhg-39r2
    Fix available
    Packages

    org.apache.sling:org.apache.sling.api

    Summary

    Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Sling

    Published
    17 May 2022
    GHSA-4894-5vqc-6r2r
    Fix available
    Packages

    django

    Summary

    Django cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget

    Published
    17 May 2022
    GHSA-rvrj-j7cc-236p
    Fix available
    Packages

    DotNetNuke.Core, DotNetNuke.Core

    Summary

    DotNetNuke (DNN) Cross-site scripting (XSS) vulnerability via the __dnnVariable parameter

    Published
    17 May 2022
    GHSA-rg6g-v4xm-g49q
    Fix available
    Packages

    georgringer/news

    Summary

    News system (news) extension for TYPO3 vulnerable to SQL Injection

    Published
    17 May 2022
    GHSA-4mm3-xgc2-656r
    Fix available
    Packages

    jambagecom/div2007

    Summary

    Static Methods since 2007 (div2007) extension for TYPO3 vulnerable to Cross-site Scripting

    Published
    17 May 2022
    GHSA-r3rw-h5v8-ff6h
    Fix available
    Packages

    bednee/cooluri

    Summary

    CoolURI extension for TYPO3 vulnerable to SQL Injection

    Published
    17 May 2022
    GHSA-6p8h-36qp-8h72
    Fix available
    Packages

    sjbr/static-info-tables

    Summary

    Static Info Tables (static_info_tables) extension TYPO3 vulnerable to Cross-site Scripting

    Published
    17 May 2022
    GHSA-52g6-pfrq-rxfv
    No fix available
    Packages

    org.jenkins-ci.main:jenkins-core

    Summary

    Jenkins allows Cross-Site Scripting (XSS) in User Configuration

    Published
    17 May 2022
    GHSA-qj69-chjp-g4f5
    Fix available
    Packages

    typo3/cms-core, typo3/cms-core, typo3/cms-core, typo3/cms-core

    Summary

    TYPO3 Cross-site scripting (XSS) vulnerability in the Extbase Framework

    Published
    17 May 2022
    GHSA-r8m7-792j-5jvq
    Fix available
    Packages

    typo3/cms, typo3/cms, typo3/cms, typo3/cms

    Summary

    TYPO3 Cross-Site Scripting (XSS) vulnerabilities in Content Editing Wizards component

    Published
    17 May 2022
    GHSA-vc74-c4m6-9979
    Fix available
    Packages

    neos/flow, neos/flow, typo3/flow, typo3/flow

    Summary

    TYPO3 Flow Cross-site scripting (XSS) vulnerability

    Published
    17 May 2022
    GHSA-5cmc-r23m-hvrr
    Fix available
    Packages

    typo3/cms-core, typo3/cms-core

    Summary

    TYPO3 Cross-site scripting (XSS) vulnerability in the Backend User Administration Module

    Published
    17 May 2022
    GHSA-99rx-9x8v-9j8p
    Fix available
    Packages

    nova

    Summary

    OpenStack Nova Live migration can leak root disk into ephemeral storage

    Published
    17 May 2022
    GHSA-9gcf-pq99-rjw3
    Fix available
    Packages

    rply

    Summary

    RPLY Predictable Tmpfile Names Allows Cache Spoofing

    Published
    17 May 2022