Open Source Vulnerabilities
silverstripe/cms, silverstripe/cms
Silverstripe CMS User Enumeration
silverstripe/cms/ silverstripe/cms
Silverstripe CMS User Enumeration
zendframework/zendframework, zendframework/zendframework, zendframework/zendframework, zendframework/zendframework, zendframework/zendframework1
Zend Access Restriction Bypass
zendframework/zendframework/ zendframework/zendframework/ zendframework/zendframework/ zendframework/zendframework/ zendframework/zendframework1
Zend Access Restriction Bypass
org.apache.xmlgraphics:batik
Improper Input Validation in Apache Batik
org.apache.xmlgraphics:batik
Improper Input Validation in Apache Batik
swiftmailer/swiftmailer
Swift Mailer mail transport Command Injection
swiftmailer/swiftmailer
Swift Mailer mail transport Command Injection
django, django, django
Django DNS Rebinding Vulnerability
django, django, django
Django user with hardcoded password created when running tests on Oracle
django/ django/ django
Django user with hardcoded password created when running tests on Oracle
org.apache.nifi:nifi
XML External Entity Reference in Apache NiFi
org.apache.nifi:nifi
XML External Entity Reference in Apache NiFi
zendframework/zendframework, zendframework/zend-crypt, zendframework/zend-crypt, zendframework/zendframework
Zend Framework Information Disclosure
zendframework/zendframework/ zendframework/zend-crypt/ zendframework/zend-crypt/ zendframework/zendframework
Zend Framework Information Disclosure
salt
salt leaks git usernames and passwords to the log
org.keycloak:keycloak-services
JBoss Keycloak CSRF Vulnerability
org.keycloak:keycloak-services
JBoss Keycloak CSRF Vulnerability
org.apache.nifi:nifi, org.apache.nifi:nifi
Injection in Apache NiFi
org.apache.nifi:nifi/ org.apache.nifi:nifi
Injection in Apache NiFi
typo3/cms-backend, typo3/cms-backend, typo3/cms-backend, typo3/cms-backend
TYPO3 Cross-site Scripting vulnerability in the extension manager and backend forms
typo3/cms-backend/ typo3/cms-backend/ typo3/cms-backend/ typo3/cms-backend
TYPO3 Cross-site Scripting vulnerability in the extension manager and backend forms
mistune
Cross-site Scripting in Mistune
org.apache.james:james-project
Apache James Privilege Escalation
org.apache.james:james-project
Apache James Privilege Escalation
mysql:mysql-connector-java
Improper Access Control in MySQL Connectors Java
mysql:mysql-connector-java
Improper Access Control in MySQL Connectors Java
salt, salt, salt
SaltStack Salt Directory traversal vulnerability in minion id validation
salt/ salt/ salt
SaltStack Salt Directory traversal vulnerability in minion id validation
org.apache.tomcat:tomcat-coyote, org.apache.tomcat.embed:tomcat-embed-core
Denial of service in Apache Tomcat
org.apache.tomcat:tomcat-coyote/ org.apache.tomcat.embed:tomcat-embed-core
Denial of service in Apache Tomcat
org.apache.storm:storm
Apache Storm log viewer path traversal vulnerability
org.apache.storm:storm
Apache Storm log viewer path traversal vulnerability
salt, salt, salt
SaltStack Salt Denial of Service via a crafted authentication request
salt/ salt/ salt
SaltStack Salt Denial of Service via a crafted authentication request
org.igniterealtime.openfire:parent
Ignite Realtime Openfire Server has Cross-site Scripting vulnerability in admin console
org.igniterealtime.openfire:parent
Ignite Realtime Openfire Server has Cross-site Scripting vulnerability in admin console
django, django
Django cross-site scripting (XSS) vulnerability via is_safe_url function
django/ django
Django cross-site scripting (XSS) vulnerability via is_safe_url function
org.apache.hadoop:hadoop-client, org.apache.hadoop:hadoop-client, org.apache.hadoop:hadoop-client
Use of a Broken or Risky Cryptographic Algorithm in Apache Hadoop
org.apache.hadoop:hadoop-client/ org.apache.hadoop:hadoop-client/ org.apache.hadoop:hadoop-client
Use of a Broken or Risky Cryptographic Algorithm in Apache Hadoop
concrete5/concrete5
Concrete5 Vulnerable to Cross-Site Scripting (XSS)
concrete5/concrete5
Concrete5 Vulnerable to Cross-Site Scripting (XSS)
github.com/vbatts/tar-split
tar-split memory exhaustion
org.jenkins-ci.plugins:git-client
Insecure temporary file usage in Jenkins Git Client Plugin
org.jenkins-ci.plugins:git-client
Insecure temporary file usage in Jenkins Git Client Plugin
github.com/moby/moby
Docker Moby /proc/scsi Path Exposure Allows Host Data Loss (SCSI MICDROP)
github.com/moby/moby
Docker Moby /proc/scsi Path Exposure Allows Host Data Loss (SCSI MICDROP)
genix/cms
MetalGenix GeniXCMS vulnerable to SQL Injection
genix/cms
MetalGenix GeniXCMS vulnerable to SQL Injection
home-assistant-frontend
Withdrawn Advisory: Home Assistant Frontend XSS Vulnerability
home-assistant-frontend
Withdrawn Advisory: Home Assistant Frontend XSS Vulnerability
Microsoft.ChakraCore
Chakra Core vulnerable to privilege escalation when writing to JavaScript null scope objects
Microsoft.ChakraCore
Chakra Core vulnerable to privilege escalation when writing to JavaScript null scope objects
Microsoft.ChakraCore
Chakra Core vulnerable to privilege escalation due to type confusion
Microsoft.ChakraCore
Chakra Core vulnerable to privilege escalation due to type confusion
Microsoft.ChakraCore
Chakra Core vulnerable to privilege escalation due to reading an invalid pointer
Microsoft.ChakraCore
Chakra Core vulnerable to privilege escalation due to reading an invalid pointer
sanic
Sanic arbitrary file read and directory traversal
filp/whoops
filp whoops Cross-site Scripting vulnerability
filp/whoops
filp whoops Cross-site Scripting vulnerability
Microsoft.NETCore.App, Microsoft.NETCore.App
Improper Input Validation in Microsoft.NETCore.App
Microsoft.NETCore.App/ Microsoft.NETCore.App
Improper Input Validation in Microsoft.NETCore.App
zetacomponents/mail
Zeta Components Mail Arbitrary code execution via a crafted email address
zetacomponents/mail
Zeta Components Mail Arbitrary code execution via a crafted email address
typo3/cms, typo3/cms
TYPO3 Arbitrary Code Execution
codeigniter4/framework
CodeIgniter HTTP Header Injection
com.neovisionaries:nv-websocket-client
nv-websocket-client allows attackers to spoof SSL/TLS servers via an arbitrary valid certificate
com.neovisionaries:nv-websocket-client
nv-websocket-client allows attackers to spoof SSL/TLS servers via an arbitrary valid certificate
moodle/moodle, moodle/moodle, moodle/moodle
Moodle Exposure of Sensitive Information to an Unauthorized Actor
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle Exposure of Sensitive Information to an Unauthorized Actor
nilsteampassnet/teampass
TeamPass stored cross-site scripting (XSS) vulnerability
nilsteampassnet/teampass
TeamPass stored cross-site scripting (XSS) vulnerability
nilsteampassnet/teampass
TeamPass arbitrary file upload vulnerability
nilsteampassnet/teampass
TeamPass arbitrary file upload vulnerability
rubygems-update, rubygems-update, rubygems-update, rubygems-update
RubyGems Regular Expression Denial of Service
rubygems-update/ rubygems-update/ rubygems-update/ rubygems-update
RubyGems Regular Expression Denial of Service
rubygems-update, rubygems-update, rubygems-update
RubyGems Improper Input Validation vulnerability
rubygems-update/ rubygems-update/ rubygems-update
RubyGems Improper Input Validation vulnerability
swauth
OpenStack Swauth object/proxy server writing Auth Token to log file
swauth
OpenStack Swauth object/proxy server writing Auth Token to log file
org.springframework.amqp:spring-amqp, org.springframework.amqp:spring-amqp, org.springframework.amqp:spring-amqp
Deserialization of Untrusted Data in Spring AMQP
org.springframework.amqp:spring-amqp/ org.springframework.amqp:spring-amqp/ org.springframework.amqp:spring-amqp
Deserialization of Untrusted Data in Spring AMQP
org.wildfly:wildfly-undertow
Improper Neutralization of CRLF Sequences in Wildfly Undertow
org.wildfly:wildfly-undertow
Improper Neutralization of CRLF Sequences in Wildfly Undertow
io.undertow:undertow-core, io.undertow:undertow-core
Undertow Uncaught Exception vulnerability
io.undertow:undertow-core/ io.undertow:undertow-core
Undertow Uncaught Exception vulnerability
aubio
Aubio Divide-By-Zero DoS vulnerability in new_aubio_source_wavread function
aubio
Aubio Divide-By-Zero DoS vulnerability in new_aubio_source_wavread function
org.richfaces:richfaces, org.richfaces:richfaces
JBoss RichFaces Improper Input Validation vulnerability
org.richfaces:richfaces/ org.richfaces:richfaces
JBoss RichFaces Improper Input Validation vulnerability
python-keystoneclient
python-keystoneclient vulnerable to context confusion in Keystone auth_token middleware
python-keystoneclient
python-keystoneclient vulnerable to context confusion in Keystone auth_token middleware
