Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-c36r-g737-9qp8
    Fix available
    Packages

    nova

    Summary

    OpenStack Nova Potential Xen connection password leak via StorageError

    Published
    14 May 2022
    GHSA-92hc-c226-32q7
    Fix available
    Packages

    nova

    Summary

    OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service

    Published
    14 May 2022
    GHSA-x8xr-rm9r-7mvf
    Fix available
    Packages

    nova, nova

    Summary

    OpenStack Compute (Nova) has Insufficient Verification of Data Authenticity

    Published
    14 May 2022
    GHSA-3vx7-xff6-h2vx
    Fix available
    Packages

    nova

    Summary

    OpenStack Nova instance migration process does not stop when instance is deleted

    Published
    14 May 2022
    GHSA-43hc-pwvx-pmfg
    Fix available
    Packages

    nova, nova

    Summary

    OpenStack Compute (Nova) Denial of Service vulnerability

    Published
    14 May 2022
    GHSA-67rh-9p29-vrxr
    Fix available
    Packages

    nova, nova

    Summary

    OpenStack Compute (Nova) allows remote attackers to bypass intended restriction

    Published
    14 May 2022
    GHSA-v933-vx5p-j7w2
    Fix available
    Packages

    oslo-utils

    Summary

    OpenStack Oslo utility sensitive information exposure via log files

    Published
    14 May 2022
    GHSA-49jv-37hm-6gfp
    Fix available
    Packages

    nova

    Summary

    OpenStack Nova host data access through resize/migration

    Published
    14 May 2022
    GHSA-77cq-wgpf-g449
    No fix available
    Packages

    web-feet/coastercms

    Summary

    Coaster CMS Stored Cross-site Scripting vulnerability

    Published
    14 May 2022
    GHSA-77j2-7whr-6vpx
    Fix available
    Packages

    elefant/cms

    Summary

    Elefant CMS Code Execution Vulnerability

    Published
    14 May 2022
    GHSA-75fm-52mm-q5rm
    No fix available
    Packages

    topthink/framework

    Summary

    ThinkPHP SQL injection vulnerability

    Published
    14 May 2022
    GHSA-3p9v-xp6w-wcmc
    No fix available
    Packages

    quickapps/cms

    Summary

    QuickAppsCMS Cross-Site Request Forgery (CSRF)

    Published
    14 May 2022
    GHSA-7mj4-2984-955f
    No fix available
    Packages

    alchemy_cms

    Summary

    Withdrawn Advisory: AlchemyCMS is vulnerable to stored XSS via the /admin/pictures image field

    Published
    14 May 2022
    GHSA-vwhv-j36g-5rm8
    Fix available
    Packages

    org.apache.struts:struts2-core

    Summary

    Cross-site Scripting in Apache Struts

    Published
    14 May 2022
    GHSA-gqqm-564f-vvxq
    Fix available
    Packages

    org.apache.struts:struts2-core, org.apache.struts.xwork:xwork-core

    Summary

    Arbitrary code execution in Apache Struts 2

    Published
    14 May 2022
    GHSA-m3x6-9v6h-4g28
    Fix available
    Packages

    org.apache.struts:struts2-core

    Summary

    Cross-site Scripting in Apache Struts

    Published
    14 May 2022
    GHSA-pw8r-x2qm-3h5m
    Fix available
    Packages

    org.apache.struts:struts2-core, org.apache.struts.xwork:xwork-core

    Summary

    Arbitrary code execution in Apache Struts 2

    Published
    14 May 2022
    GHSA-2c28-7gwv-cpgf
    Fix available
    Packages

    mediawiki/core

    Summary

    Mediawiki tarball is missing .htaccess files

    Published
    14 May 2022
    GHSA-c82r-qg3w-q5mv
    Fix available
    Packages

    org.apache.solr:solr-core, org.apache.solr:solr-core

    Summary

    Apache Solr insecure inter-node communication

    Published
    14 May 2022
    GHSA-9qh2-6fxg-9m4g
    Fix available
    Packages

    opencc

    Summary

    Open Chinese Convert subject to Denial of Service via Out-of-bounds Read

    Published
    14 May 2022
    GHSA-8qxg-mff5-j3wc
    Fix available
    Packages

    rubygems-update, org.jruby:jruby-stdlib

    Summary

    RubyGems Path Traversal vulnerability

    Published
    14 May 2022
    GHSA-22cq-xxr9-jrrv
    No fix available
    Packages

    tribalsystems/zenario

    Summary

    Zenario CMS vulnerable to CSRF

    Published
    14 May 2022
    GHSA-78q9-24gv-g288
    No fix available
    Packages

    topthink/framework

    Summary

    ThinkPHP SQLi Vulnerability

    Published
    14 May 2022
    GHSA-7xfj-4jpg-58vf
    No fix available
    Packages

    topthink/framework

    Summary

    ThinkPHP SQLi Vulnerability

    Published
    14 May 2022
    GHSA-9m82-f3wx-p625
    Fix available
    Packages

    librenms/librenms

    Summary

    LibreNMS XSS Vulnerability

    Published
    14 May 2022
    GHSA-j7g8-3qqg-8cvm
    No fix available
    Packages

    topthink/framework

    Summary

    ThinkPHP SQLi Vulnerability

    Published
    14 May 2022
    GHSA-wp35-6jqv-r33m
    No fix available
    Packages

    org.apache.xmlrpc:xmlrpc

    Summary

    Apache XML-RPC XXE Vulnerability

    Published
    14 May 2022
    GHSA-4gqp-296r-j5mq
    No fix available
    Packages

    org.apache.xmlrpc:xmlrpc

    Summary

    Apache XML-RPC vulnerable to Deserialization of Untrusted Data

    Published
    14 May 2022
    GHSA-5pcv-m8w2-62m9
    No fix available
    Packages

    ajenti

    Summary

    Ajenti Cross-site Scripting Via Filename

    Published
    14 May 2022
    GHSA-826f-32qm-vm3j
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Jenkins vulnerable to Cross-site Scripting

    Published
    14 May 2022
    GHSA-qg5v-jw6f-rpfj
    Fix available
    Packages

    sabre/dav, sabre/dav, sabre/dav

    Summary

    SabreDAV Directory Traversal vulnerability

    Published
    14 May 2022
    GHSA-q48q-77qv-cf9p
    Fix available
    Packages

    httplib2

    Summary

    httplib2 incorrectly checks SSL certificate

    Published
    14 May 2022
    GHSA-gcqw-45xq-xc63
    Fix available
    Packages

    mantisbt/mantisbt

    Summary

    MantisBT allows XSS via Edit Filter page

    Published
    14 May 2022
    GHSA-ggjm-7m5f-7xjv
    Fix available
    Packages

    mantisbt/mantisbt

    Summary

    MantisBT allows XSS via the Manage Filter page

    Published
    14 May 2022
    GHSA-mwrx-hx6x-3hhv
    Fix available
    Packages

    org.apache.struts:struts2-core, org.apache.struts.xwork:xwork-core

    Summary

    Apache Struts Code injection due to conversion error

    Published
    14 May 2022
    GHSA-fx2m-5m9v-jhgp
    Fix available
    Packages

    baserproject/basercms

    Summary

    XSS in baserCMS before 4.1.4

    Published
    14 May 2022
    GHSA-62g2-m955-v383
    No fix available
    Packages

    org.apache.spark:spark-core_2.11, org.apache.spark:spark-core_2.10

    Summary

    Improper Input Validation in Apache Spark

    Published
    14 May 2022
    GHSA-qfwq-chf4-jvwg
    No fix available
    Packages

    karo

    Summary

    karo Metacharacter Handling Remote Command Execution

    Published
    14 May 2022
    GHSA-p575-cf9h-wv42
    Fix available
    Packages

    mercurial

    Summary

    Mercurial Out-of-bounds Read vulnerability

    Published
    14 May 2022
    GHSA-34hf-g744-jw64
    Fix available
    Packages

    i18n

    Summary

    i18n Vulnerable to Denial of Service Attack

    Published
    14 May 2022
    GHSA-pc5h-m95g-v6rh
    No fix available
    Packages

    athlon1600/php-proxy

    Summary

    LFI in PHP-Proxy 5.1.0

    Published
    14 May 2022
    GHSA-j78w-6r73-22vh
    No fix available
    Packages

    fineuploader/php-traditional-server

    Summary

    FineUploader php-traditional-server unauthenticated arbitrary file upload vulnerability

    Published
    14 May 2022
    GHSA-3x3m-p2wx-g7cw
    No fix available
    Packages

    athlon1600/php-proxy-app

    Summary

    Unauthenticated File Read in PHP Proxy

    Published
    14 May 2022
    GHSA-cwh9-f8m6-6r63
    Fix available
    Packages

    org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core

    Summary

    Jenkins Cross-site Scripting vulnerability

    Published
    14 May 2022
    GHSA-mffc-9gx5-99g3
    Fix available
    Packages

    kerberos, pykerberos

    Summary

    python-kerberos vulnerable to KDC spoofing attacks

    Published
    14 May 2022
    GHSA-6xx7-cphv-pxgr
    No fix available
    Packages

    showdoc/showdoc

    Summary

    Showdoc Forced Browsing

    Published
    14 May 2022
    GHSA-3p87-gqw8-4pf2
    No fix available
    Packages

    showdoc/showdoc

    Summary

    Showdoc CSRF Vulnerability

    Published
    14 May 2022
    GHSA-cghj-w42g-hqmr
    Fix available
    Packages

    athlon1600/php-proxy-app

    Summary

    XSS in PHP-Proxy-App through v3.0

    Published
    14 May 2022
    GHSA-g7wm-22m6-5774
    Fix available
    Packages

    org.grails.plugins:asset-pipeline

    Summary

    Asset Pipeline plugin for Grails vulnerable to Path Traversal

    Published
    14 May 2022
    GHSA-wrrj-r2j4-969w
    No fix available
    Packages

    umbraco

    Summary

    Umbraco CMS vulnerable to stored XSS

    Published
    14 May 2022