Open Source Vulnerabilities
puppet
Puppet does not properly restrict access to node resources
puppet
Puppet does not properly restrict access to node resources
puppet, puppet
Puppet uses predictable filenames, allowing arbitrary file overwrite
puppet/ puppet
Puppet uses predictable filenames, allowing arbitrary file overwrite
puppet, puppet
Puppet arbitrary file overwrite
puppet, puppet
Puppet allows local users to modify the permissions of arbitrary files
puppet/ puppet
Puppet allows local users to modify the permissions of arbitrary files
facter
Puppet Labs Facter allows local users to obtain sensitive Amazon EC2 IAM instance metadata
facter
Puppet Labs Facter allows local users to obtain sensitive Amazon EC2 IAM instance metadata
puppetlabs-rabbitmq
puppetlabs-rabbitmq allows local users to obtain sensitive information
puppetlabs-rabbitmq
puppetlabs-rabbitmq allows local users to obtain sensitive information
puppet, puppet
Puppet Denial of Service and Arbitrary File Write
puppet/ puppet
Puppet Denial of Service and Arbitrary File Write
puppet, puppet
Puppet Arbitrary Command Execution
puppet, puppet
Puppet uses predictable filenames, allowing arbitrary file overwrite
puppet/ puppet
Puppet uses predictable filenames, allowing arbitrary file overwrite
puppet, puppet
Puppet Privilege Escallation
laravel/framework, laravel/framework
Laravel Framework RCE Vulnerability
laravel/framework/ laravel/framework
Laravel Framework RCE Vulnerability
org.springframework:spring-core, org.springframework:spring-core
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
org.springframework:spring-core/ org.springframework:spring-core
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
dweeves/magmi
MAGMI plugin for Magento Unsafe File Upload
dweeves/magmi
MAGMI plugin for Magento Unsafe File Upload
zendframework/zendframework1, zendframework/zendopenid, zendframework/zendrest, zendframework/zendservice-audioscrobbler, zendframework/zendservice-nirvanix, zendframework/zendservice-slideshare, zendframework/zendservice-technorati, zendframework/zendservice-windowsazure, zendframework/zendservice-amazon, zendframework/zendservice-api
Several Zend Products Vulnerable to XXE and XEE attacks
zendframework/zendframework1/ zendframework/zendopenid/ zendframework/zendrest/ zendframework/zendservice-audioscrobbler/ zendframework/zendservice-nirvanix/ zendframework/zendservice-slideshare/ zendframework/zendservice-technorati/ zendframework/zendservice-windowsazure/ zendframework/zendservice-amazon/ zendframework/zendservice-api
Several Zend Products Vulnerable to XXE and XEE attacks
zendframework/zendframework1, zendframework/zendopenid, zendframework/zendrest, zendframework/zendservice-audioscrobbler, zendframework/zendservice-nirvanix, zendframework/zendservice-slideshare, zendframework/zendservice-technorati, zendframework/zendservice-windowsazure, zendframework/zendservice-amazon, zendframework/zendservice-api
Several Zend Products Vulnerable to XXE and XEE attacks
zendframework/zendframework1/ zendframework/zendopenid/ zendframework/zendrest/ zendframework/zendservice-audioscrobbler/ zendframework/zendservice-nirvanix/ zendframework/zendservice-slideshare/ zendframework/zendservice-technorati/ zendframework/zendservice-windowsazure/ zendframework/zendservice-amazon/ zendframework/zendservice-api
Several Zend Products Vulnerable to XXE and XEE attacks
zendframework/zendframework1, zendframework/zendopenid, zendframework/zendrest, zendframework/zendservice-audioscrobbler, zendframework/zendservice-nirvanix, zendframework/zendservice-slideshare, zendframework/zendservice-technorati, zendframework/zendservice-windowsazure, zendframework/zendservice-amazon, zendframework/zendservice-api
Several Zend Products Vulnerable to XXE and XEE attacks
zendframework/zendframework1/ zendframework/zendopenid/ zendframework/zendrest/ zendframework/zendservice-audioscrobbler/ zendframework/zendservice-nirvanix/ zendframework/zendservice-slideshare/ zendframework/zendservice-technorati/ zendframework/zendservice-windowsazure/ zendframework/zendservice-amazon/ zendframework/zendservice-api
Several Zend Products Vulnerable to XXE and XEE attacks
drupal/core, ckeditor-dev, drupal/core, drupal/drupal, drupal/drupal
Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS)
drupal/core/ ckeditor-dev/ drupal/core/ drupal/drupal/ drupal/drupal
Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS)
org.apache.ws.security:wss4j, org.apache.wss4j:wss4j-ws-security-dom
Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
org.apache.ws.security:wss4j/ org.apache.wss4j:wss4j-ws-security-dom
Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
org.simpleframework:simple-xml
SimpleXML has XML External Entity (XXE) vulnerability
org.simpleframework:simple-xml
SimpleXML has XML External Entity (XXE) vulnerability
moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle
Moodle SSRF Vulnerability
moodle/moodle/ moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle SSRF Vulnerability
centreon/centreon
Centreon Cross-site Scripting Vulnerability
centreon/centreon
Centreon Cross-site Scripting Vulnerability
centreon/centreon, centreon/centreon
Centreon SQL Injection
centreon/centreon/ centreon/centreon
Centreon SQL Injection
centreon/centreon, centreon/centreon
Centreon SQL Injection
centreon/centreon/ centreon/centreon
Centreon SQL Injection
centreon/centreon
Centreon XSS Vulnerability
centreon/centreon, centreon/centreon
Centreon allows SNMP trap SQL Injection
centreon/centreon/ centreon/centreon
Centreon allows SNMP trap SQL Injection
centreon/centreon
Centreon XSS Vulnerability
centreon/centreon
Centreon Command Injection
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
github.com/git-lfs/git-lfs
GitHub Git LFS Arbitrary command execution vulnerability
github.com/git-lfs/git-lfs
GitHub Git LFS Arbitrary command execution vulnerability
getkirby/cms, getkirby/cms, getkirby/cms
Kirby XSS Vulnerability
getkirby/cms/ getkirby/cms/ getkirby/cms
Kirby XSS Vulnerability
keycloak-httpd-client-install
keycloak-httpd-client-install symlink attack vulnerability
keycloak-httpd-client-install
keycloak-httpd-client-install symlink attack vulnerability
keycloak-httpd-client-install
keycloak-httpd-client-install Insecure Secrets
keycloak-httpd-client-install
keycloak-httpd-client-install Insecure Secrets
activerecord
Active Record component in Ruby on Rails has a data-type injection vulnerability
activerecord
Active Record component in Ruby on Rails has a data-type injection vulnerability
authlogic
Authlogic Information Exposure vulnerability
org.apache.struts:struts2-core
ClassLoader manipulation in Apache Struts
org.apache.struts:struts2-core
ClassLoader manipulation in Apache Struts
org.apache.struts:struts2-core
Improper Control of Generation of Code in Apache Struts
org.apache.struts:struts2-core
Improper Control of Generation of Code in Apache Struts
org.apache.struts:struts2-core, org.apache.struts.xwork:xwork-core
ClassLoader manipulation in Apache Struts
org.apache.struts:struts2-core/ org.apache.struts.xwork:xwork-core
ClassLoader manipulation in Apache Struts
org.apache.struts:struts2-core
ClassLoader manipulation in Apache Struts
org.apache.struts:struts2-core
ClassLoader manipulation in Apache Struts
org.apache.struts:struts2-core, org.apache.struts.xwork:xwork-core
Arbitrary code execution in Apache Struts
org.apache.struts:struts2-core/ org.apache.struts.xwork:xwork-core
Arbitrary code execution in Apache Struts
org.apache.struts:struts2-core, org.apache.struts:struts2-core, org.apache.struts:struts2-core
Apache Struts RCE Vulnerability
org.apache.struts:struts2-core/ org.apache.struts:struts2-core/ org.apache.struts:struts2-core
Apache Struts RCE Vulnerability
org.apache.struts:struts2-core
ClassLoader manipulation in Apache Struts
org.apache.struts:struts2-core
ClassLoader manipulation in Apache Struts
org.apache.struts:struts2-core, org.apache.struts:struts2-core, org.apache.struts:struts2-core
Apache Struts vulnerable to arbitrary remote code execution due to improper input validation
org.apache.struts:struts2-core/ org.apache.struts:struts2-core/ org.apache.struts:struts2-core
Apache Struts vulnerable to arbitrary remote code execution due to improper input validation
org.apache.struts:struts2-convention-plugin, org.apache.struts:struts2-convention-plugin
Path Traversal in Apache Struts
org.apache.struts:struts2-convention-plugin/ org.apache.struts:struts2-convention-plugin
Path Traversal in Apache Struts
org.apache.struts:struts2-core, org.apache.struts:struts2-rest-plugin
Arbitrary code execution in Apache Struts 2
org.apache.struts:struts2-core/ org.apache.struts:struts2-rest-plugin
Arbitrary code execution in Apache Struts 2
org.jenkins-ci.plugins:jobConfigHistory
Jenkins Job Config History Plugin reflected XSS vulnerability
org.jenkins-ci.plugins:jobConfigHistory
Jenkins Job Config History Plugin reflected XSS vulnerability
org.apache.struts:struts2-core, org.apache.struts:struts2-core
Apache Struts RCE Vulnerability
org.apache.struts:struts2-core/ org.apache.struts:struts2-core
Apache Struts RCE Vulnerability
CoreFtp
CoreFTP Directory Traversal
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in OpenClinica
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in OpenClinica
org.apache.santuario:xmlsec, org.apache.santuario:xmlsec
Apache XML Security For Java vulnerable to Infinite Loop
org.apache.santuario:xmlsec/ org.apache.santuario:xmlsec
Apache XML Security For Java vulnerable to Infinite Loop
org.apache.tomcat:tomcat, org.apache.tomcat:tomcat
Improper socket reuse in Apache Tomcat
org.apache.tomcat:tomcat/ org.apache.tomcat:tomcat
Improper socket reuse in Apache Tomcat
