Open Source Vulnerabilities
nova
OpenStack Nova Potential Xen connection password leak via StorageError
nova
OpenStack Nova Potential Xen connection password leak via StorageError
nova
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
nova
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
nova, nova
OpenStack Compute (Nova) has Insufficient Verification of Data Authenticity
nova/ nova
OpenStack Compute (Nova) has Insufficient Verification of Data Authenticity
nova
OpenStack Nova instance migration process does not stop when instance is deleted
nova
OpenStack Nova instance migration process does not stop when instance is deleted
nova, nova
OpenStack Compute (Nova) Denial of Service vulnerability
nova/ nova
OpenStack Compute (Nova) Denial of Service vulnerability
nova, nova
OpenStack Compute (Nova) allows remote attackers to bypass intended restriction
nova/ nova
OpenStack Compute (Nova) allows remote attackers to bypass intended restriction
oslo-utils
OpenStack Oslo utility sensitive information exposure via log files
oslo-utils
OpenStack Oslo utility sensitive information exposure via log files
nova
OpenStack Nova host data access through resize/migration
nova
OpenStack Nova host data access through resize/migration
web-feet/coastercms
Coaster CMS Stored Cross-site Scripting vulnerability
web-feet/coastercms
Coaster CMS Stored Cross-site Scripting vulnerability
elefant/cms
Elefant CMS Code Execution Vulnerability
topthink/framework
ThinkPHP SQL injection vulnerability
topthink/framework
ThinkPHP SQL injection vulnerability
quickapps/cms
QuickAppsCMS Cross-Site Request Forgery (CSRF)
quickapps/cms
QuickAppsCMS Cross-Site Request Forgery (CSRF)
alchemy_cms
Withdrawn Advisory: AlchemyCMS is vulnerable to stored XSS via the /admin/pictures image field
alchemy_cms
Withdrawn Advisory: AlchemyCMS is vulnerable to stored XSS via the /admin/pictures image field
org.apache.struts:struts2-core
Cross-site Scripting in Apache Struts
org.apache.struts:struts2-core
Cross-site Scripting in Apache Struts
org.apache.struts:struts2-core, org.apache.struts.xwork:xwork-core
Arbitrary code execution in Apache Struts 2
org.apache.struts:struts2-core/ org.apache.struts.xwork:xwork-core
Arbitrary code execution in Apache Struts 2
org.apache.struts:struts2-core
Cross-site Scripting in Apache Struts
org.apache.struts:struts2-core
Cross-site Scripting in Apache Struts
org.apache.struts:struts2-core, org.apache.struts.xwork:xwork-core
Arbitrary code execution in Apache Struts 2
org.apache.struts:struts2-core/ org.apache.struts.xwork:xwork-core
Arbitrary code execution in Apache Struts 2
mediawiki/core
Mediawiki tarball is missing .htaccess files
mediawiki/core
Mediawiki tarball is missing .htaccess files
org.apache.solr:solr-core, org.apache.solr:solr-core
Apache Solr insecure inter-node communication
org.apache.solr:solr-core/ org.apache.solr:solr-core
Apache Solr insecure inter-node communication
opencc
Open Chinese Convert subject to Denial of Service via Out-of-bounds Read
opencc
Open Chinese Convert subject to Denial of Service via Out-of-bounds Read
rubygems-update, org.jruby:jruby-stdlib
RubyGems Path Traversal vulnerability
rubygems-update/ org.jruby:jruby-stdlib
RubyGems Path Traversal vulnerability
tribalsystems/zenario
Zenario CMS vulnerable to CSRF
topthink/framework
ThinkPHP SQLi Vulnerability
topthink/framework
ThinkPHP SQLi Vulnerability
librenms/librenms
LibreNMS XSS Vulnerability
topthink/framework
ThinkPHP SQLi Vulnerability
org.apache.xmlrpc:xmlrpc
Apache XML-RPC XXE Vulnerability
org.apache.xmlrpc:xmlrpc
Apache XML-RPC XXE Vulnerability
org.apache.xmlrpc:xmlrpc
Apache XML-RPC vulnerable to Deserialization of Untrusted Data
org.apache.xmlrpc:xmlrpc
Apache XML-RPC vulnerable to Deserialization of Untrusted Data
ajenti
Ajenti Cross-site Scripting Via Filename
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Jenkins vulnerable to Cross-site Scripting
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Jenkins vulnerable to Cross-site Scripting
sabre/dav, sabre/dav, sabre/dav
SabreDAV Directory Traversal vulnerability
sabre/dav/ sabre/dav/ sabre/dav
SabreDAV Directory Traversal vulnerability
httplib2
httplib2 incorrectly checks SSL certificate
mantisbt/mantisbt
MantisBT allows XSS via Edit Filter page
mantisbt/mantisbt
MantisBT allows XSS via Edit Filter page
mantisbt/mantisbt
MantisBT allows XSS via the Manage Filter page
mantisbt/mantisbt
MantisBT allows XSS via the Manage Filter page
org.apache.struts:struts2-core, org.apache.struts.xwork:xwork-core
Apache Struts Code injection due to conversion error
org.apache.struts:struts2-core/ org.apache.struts.xwork:xwork-core
Apache Struts Code injection due to conversion error
baserproject/basercms
XSS in baserCMS before 4.1.4
org.apache.spark:spark-core_2.11, org.apache.spark:spark-core_2.10
Improper Input Validation in Apache Spark
org.apache.spark:spark-core_2.11/ org.apache.spark:spark-core_2.10
Improper Input Validation in Apache Spark
karo
karo Metacharacter Handling Remote Command Execution
karo
karo Metacharacter Handling Remote Command Execution
mercurial
Mercurial Out-of-bounds Read vulnerability
i18n
i18n Vulnerable to Denial of Service Attack
athlon1600/php-proxy
LFI in PHP-Proxy 5.1.0
fineuploader/php-traditional-server
FineUploader php-traditional-server unauthenticated arbitrary file upload vulnerability
fineuploader/php-traditional-server
FineUploader php-traditional-server unauthenticated arbitrary file upload vulnerability
athlon1600/php-proxy-app
Unauthenticated File Read in PHP Proxy
athlon1600/php-proxy-app
Unauthenticated File Read in PHP Proxy
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Jenkins Cross-site Scripting vulnerability
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Jenkins Cross-site Scripting vulnerability
kerberos, pykerberos
python-kerberos vulnerable to KDC spoofing attacks
kerberos/ pykerberos
python-kerberos vulnerable to KDC spoofing attacks
showdoc/showdoc
Showdoc Forced Browsing
showdoc/showdoc
Showdoc CSRF Vulnerability
athlon1600/php-proxy-app
XSS in PHP-Proxy-App through v3.0
athlon1600/php-proxy-app
XSS in PHP-Proxy-App through v3.0
org.grails.plugins:asset-pipeline
Asset Pipeline plugin for Grails vulnerable to Path Traversal
org.grails.plugins:asset-pipeline
Asset Pipeline plugin for Grails vulnerable to Path Traversal
umbraco
Umbraco CMS vulnerable to stored XSS
