Open Source Vulnerabilities
baserproject/basercms, baserproject/basercms
baserCMS arbitrary file upload vulnerability
baserproject/basercms/ baserproject/basercms
baserCMS arbitrary file upload vulnerability
deap
Improper Input Validation in Deap
angular-jwt
Auth0 angular-jwt misinterprets allowlist as regex
angular-jwt
Auth0 angular-jwt misinterprets allowlist as regex
org.jenkins-ci.plugins:badge
Jenkins Badge Plugin cross-site scripting vulnerability
org.jenkins-ci.plugins:badge
Jenkins Badge Plugin cross-site scripting vulnerability
io.jenkins:configuration-as-code
Jenkins Configuration as Code Plugin vulnerable to Exposure of Sensitive Information
io.jenkins:configuration-as-code
Jenkins Configuration as Code Plugin vulnerable to Exposure of Sensitive Information
org.jenkins-ci.plugins:fortify-cloudscan-jenkins-plugin
Arbitrary file write vulnerability in Jenkins Fortify CloudScan Plugin
org.jenkins-ci.plugins:fortify-cloudscan-jenkins-plugin
Arbitrary file write vulnerability in Jenkins Fortify CloudScan Plugin
org.jenkins-ci.plugins:urltrigger
URLTrigger Plugin server-side request forgery vulnerability
org.jenkins-ci.plugins:urltrigger
URLTrigger Plugin server-side request forgery vulnerability
org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server
Cloud Foundry UAA open redirect
org.cloudfoundry.identity:cloudfoundry-identity-server/ org.cloudfoundry.identity:cloudfoundry-identity-server/ org.cloudfoundry.identity:cloudfoundry-identity-server/ org.cloudfoundry.identity:cloudfoundry-identity-server
Cloud Foundry UAA open redirect
angular-redactor
Angular Redactor XSS Vulnerability
xapian-core
xapian-core Cross-site Scripting vulnerability
xapian-core
xapian-core Cross-site Scripting vulnerability
centreon/centreon, centreon/centreon
Centreon RCE Vulnerability
centreon/centreon/ centreon/centreon
Centreon RCE Vulnerability
galaxy-app, galaxy-app
Galaxy cross-site scripting (XSS)
opencart/opencart
OpenCart Cross-Site Request Forgery (CSRF)
opencart/opencart
OpenCart Cross-Site Request Forgery (CSRF)
github.com/ethereum/go-ethereum
Go Ethereum LES protocol implementation vulnerable to Denial of Service
github.com/ethereum/go-ethereum
Go Ethereum LES protocol implementation vulnerable to Denial of Service
dolibarr/dolibarr
Dolibarr SQL injection vulnerability in product/card.php
dolibarr/dolibarr
Dolibarr SQL injection vulnerability in product/card.php
dolibarr/dolibarr
Dolibarr SQL injection vulnerability in product/card.php
dolibarr/dolibarr
Dolibarr SQL injection vulnerability in product/card.php
com.github.wxpay:wxpay-sdk
WeChat Pay Java SDK allows XXE
com.github.wxpay:wxpay-sdk
WeChat Pay Java SDK allows XXE
System.Private.ServiceModel, System.Private.ServiceModel, System.Private.ServiceModel, System.Private.ServiceModel, System.ServiceModel.Duplex, System.ServiceModel.Duplex, System.ServiceModel.Duplex, System.ServiceModel.Duplex, System.ServiceModel.Http, System.ServiceModel.Http, System.ServiceModel.Http, System.ServiceModel.Http, System.ServiceModel.NetTcp, System.ServiceModel.NetTcp, System.ServiceModel.NetTcp, System.ServiceModel.NetTcp, System.ServiceModel.Primitives, System.ServiceModel.Primitives, System.ServiceModel.Primitives, System.ServiceModel.Primitives, System.ServiceModel.Security, System.ServiceModel.Security, System.ServiceModel.Security, System.ServiceModel.Security
Improper Certificate Validation in Microsoft .NET Framework components
System.Private.ServiceModel/ System.Private.ServiceModel/ System.Private.ServiceModel/ System.Private.ServiceModel/ System.ServiceModel.Duplex/ System.ServiceModel.Duplex/ System.ServiceModel.Duplex/ System.ServiceModel.Duplex/ System.ServiceModel.Http/ System.ServiceModel.Http/ System.ServiceModel.Http/ System.ServiceModel.Http/ System.ServiceModel.NetTcp/ System.ServiceModel.NetTcp/ System.ServiceModel.NetTcp/ System.ServiceModel.NetTcp/ System.ServiceModel.Primitives/ System.ServiceModel.Primitives/ System.ServiceModel.Primitives/ System.ServiceModel.Primitives/ System.ServiceModel.Security/ System.ServiceModel.Security/ System.ServiceModel.Security/ System.ServiceModel.Security
Improper Certificate Validation in Microsoft .NET Framework components
com.amazonaws:codedeploy
Jenkins AWS CodeDeploy Plugin has Insufficiently Protected Credentials
com.amazonaws:codedeploy
Jenkins AWS CodeDeploy Plugin has Insufficiently Protected Credentials
phpoffice/common
PHPOffice Common Improper Restriction of XML External Entity Reference
phpoffice/common
PHPOffice Common Improper Restriction of XML External Entity Reference
org.graylog2:graylog2-server
Cross-site Scripting in Graylog Server
org.graylog2:graylog2-server
Cross-site Scripting in Graylog Server
pagekit/pagekit
Pagekit open redirect vulnerability
aubio
Aubio is vulnerable to denial of service via aubio_source_avcodec_readframe function
aubio
Aubio is vulnerable to denial of service via aubio_source_avcodec_readframe function
org.glassfish:mojarra-parent
Path Traversal in Eclipse Mojarra
org.glassfish:mojarra-parent
Path Traversal in Eclipse Mojarra
gleez/cms
Gleez Cms Cross-site Scripting in Profile Page
gleez/cms
Gleez Cms Cross-site Scripting in Profile Page
paypal/permissions-sdk-php
paypal/permissions-sdk-php reflected Cross-site Scripting (XSS)
paypal/permissions-sdk-php
paypal/permissions-sdk-php reflected Cross-site Scripting (XSS)
paypal/invoice-sdk-php
paypal/invoice-sdk-php reflected XSS
paypal/invoice-sdk-php
paypal/invoice-sdk-php reflected XSS
intelliants/subrion
Subrion CMS XSS
org.jenkins-ci.plugins:meliora-testlab
Jenkins meliora-testlab Plugin allows attackers with file system access to Jenkins master to obtain API key
org.jenkins-ci.plugins:meliora-testlab
Jenkins meliora-testlab Plugin allows attackers with file system access to Jenkins master to obtain API key
org.jenkins-ci.plugins:shelve-project-plugin
Stored Cross-Site Scripting Vulnerability in Jenkins Shelve Project Plugin
org.jenkins-ci.plugins:shelve-project-plugin
Stored Cross-Site Scripting Vulnerability in Jenkins Shelve Project Plugin
mantisbt/mantisbt
MantisBT allows XSS on the Edit Filter page via crafted filter name
mantisbt/mantisbt
MantisBT allows XSS on the Edit Filter page via crafted filter name
simplesamlphp/simplesamlphp
SimpleSAMLphp Information leakage issue in the sanitycheck module
simplesamlphp/simplesamlphp
SimpleSAMLphp Information leakage issue in the sanitycheck module
com.tinfoilsecurity.plugins:tinfoil-scan
Exposure of sensitive information vulnerability
com.tinfoilsecurity.plugins:tinfoil-scan
Exposure of sensitive information vulnerability
simplesamlphp/saml2, simplesamlphp/saml2, simplesamlphp/saml2
SimpleSAMLphp SAML2 library Regular Expression Denial of Service vulnerability
simplesamlphp/saml2/ simplesamlphp/saml2/ simplesamlphp/saml2
SimpleSAMLphp SAML2 library Regular Expression Denial of Service vulnerability
org.apache.ws.security:wss4j, org.apache.ws.security:wss4j, wss4j:wss4j
Improper Access Control in Apache WSS4J
org.apache.ws.security:wss4j/ org.apache.ws.security:wss4j/ wss4j:wss4j
Improper Access Control in Apache WSS4J
apache-airflow
Apache Airflow Reflected Cross-site Scripting vulnerability in 404 Endpoint
apache-airflow
Apache Airflow Reflected Cross-site Scripting vulnerability in 404 Endpoint
de.tracetronic.jenkins.plugins:ecutest
Jenkins TraceTronic ECU-TEST Plugin Man in the middle vulnerability
de.tracetronic.jenkins.plugins:ecutest
Jenkins TraceTronic ECU-TEST Plugin Man in the middle vulnerability
de.tracetronic.jenkins.plugins:ecutest
Jenkins TraceTronic ECU-TEST Plugin server-side request forgery vulnerability
de.tracetronic.jenkins.plugins:ecutest
Jenkins TraceTronic ECU-TEST Plugin server-side request forgery vulnerability
drupal/core, drupal/drupal
Drupal PECL YAML parser unsafe object handling
drupal/core/ drupal/drupal
Drupal PECL YAML parser unsafe object handling
mantisbt/mantisbt
MantisBT allows XSS via View Filters page
mantisbt/mantisbt
MantisBT allows XSS via View Filters page
com.inedo.buildmaster:inedo-buildmaster
Jenkins Inedo BuildMaster Plugin globally and unconditionally disabled SSL/TLS certificate validation
com.inedo.buildmaster:inedo-buildmaster
Jenkins Inedo BuildMaster Plugin globally and unconditionally disabled SSL/TLS certificate validation
bacula-web/bacula-web
Bacula-web SQL Injection Vulnerabilities
bacula-web/bacula-web
Bacula-web SQL Injection Vulnerabilities
com.inedo.proget:inedo-proget
Jenkins Inedo ProGet Plugin globally and unconditionally disabled SSL/TLS certificate validation
com.inedo.proget:inedo-proget
Jenkins Inedo ProGet Plugin globally and unconditionally disabled SSL/TLS certificate validation
org.jenkins-ci.plugins:collabnet
Jenkins CollabNet Plugin man in the middle vulnerability
org.jenkins-ci.plugins:collabnet
Jenkins CollabNet Plugin man in the middle vulnerability
org.apache.tomcat:tomcat, org.apache.tomcat:tomcat
Apache Tomcat does not enforce the maxHttpHeaderSize limit
org.apache.tomcat:tomcat/ org.apache.tomcat:tomcat
Apache Tomcat does not enforce the maxHttpHeaderSize limit
org.apache.archiva:archiva, org.apache.continuum:continuum, org.apache.continuum:continuum
Apache Continuum and Archiva vulnerable to Cross-site Scripting
org.apache.archiva:archiva/ org.apache.continuum:continuum/ org.apache.continuum:continuum
Apache Continuum and Archiva vulnerable to Cross-site Scripting
org.apache.tomcat:tomcat
Apache Tomcat allows remote attackers to bypass intended access restrictions
org.apache.tomcat:tomcat
Apache Tomcat allows remote attackers to bypass intended access restrictions
org.apache.tomcat:tomcat
Access controll bypass in Apache Tomcat
org.apache.tomcat:tomcat
Access controll bypass in Apache Tomcat
org.apache.tomcat:tomcat
Access restriction bypass in Apache Tomcat
org.apache.tomcat:tomcat
Access restriction bypass in Apache Tomcat
org.apache.struts.xwork:xwork-core
XWork in Apache Struts Reveals Sensitive Information
org.apache.struts.xwork:xwork-core
XWork in Apache Struts Reveals Sensitive Information
