Open Source Vulnerabilities
numpy
Numpy missing input validation
aodh
Openstack Aodh can be used to launder Keystone trusts
aodh
Openstack Aodh can be used to launder Keystone trusts
tripleo-heat-templates
Openstack tripleo-heat-templates unauthenticated file access
tripleo-heat-templates
Openstack tripleo-heat-templates unauthenticated file access
Microsoft.AspNetCore.Server.WebListener, Microsoft.AspNetCore.Server.WebListener, Microsoft.Net.Http.Server, Microsoft.Net.Http.Server, Microsoft.AspNetCore.Server.HttpSys
Denial of service in ASP.NET Core
Microsoft.AspNetCore.Server.WebListener/ Microsoft.AspNetCore.Server.WebListener/ Microsoft.Net.Http.Server/ Microsoft.Net.Http.Server/ Microsoft.AspNetCore.Server.HttpSys
Denial of service in ASP.NET Core
Microsoft.ChakraCore
ChakraCore vulnerable to privilege escalation
Microsoft.ChakraCore
ChakraCore vulnerable to privilege escalation
supervisor, supervisor, supervisor, supervisor
Incorrect Default Permissions in Supervisor
supervisor/ supervisor/ supervisor/ supervisor
Incorrect Default Permissions in Supervisor
pyjwt
PyJWT vulnerable to key confusion attacks
codiad/codiad
Codiad Vulnerable to Shell Command Injection
codiad/codiad
Codiad Vulnerable to Shell Command Injection
contao/contao, contao/core-bundle, contao/core
Contao Core directory traversal vulnerability
contao/contao/ contao/core-bundle/ contao/core
Contao Core directory traversal vulnerability
baserproject/basercms, baserproject/basercms
Arbitrary file delete in baserCMS
baserproject/basercms/ baserproject/basercms
Arbitrary file delete in baserCMS
puppet, puppet
Tarball permission preservation in puppet
electron
Electron vulnerable to URL spoofing via PDFium
plone, plone
Plone Unauthorized Access Vulnerability
org.jvnet.hudson.plugins:speaks
Arbitrary code execution vulnerability in Jenkins Speaks! Plugin
org.jvnet.hudson.plugins:speaks
Arbitrary code execution vulnerability in Jenkins Speaks! Plugin
org.jenkins-ci.plugins:build-publisher
Jenkins Build-Publisher plugin has Insufficiently Protected Credentials
org.jenkins-ci.plugins:build-publisher
Jenkins Build-Publisher plugin has Insufficiently Protected Credentials
fs-git
fs-git command injection vulnerability
org.opendaylight.controller:releasepom
OpenDaylight Controller DoS
org.opendaylight.controller:releasepom
OpenDaylight Controller DoS
org.opendaylight.controller:releasepom
OpenDaylight NULL Pointer Dereference
org.opendaylight.controller:releasepom
OpenDaylight NULL Pointer Dereference
alchemist.vim
alchemist.vim vulnerable to remote code execution
alchemist.vim
alchemist.vim vulnerable to remote code execution
org.jvnet.hudson.plugins:ssh, org.jenkins-ci.plugins:ssh
Jenkins SSH Plugin user passwords for encrypted SSH keys stored in plaintext
org.jvnet.hudson.plugins:ssh/ org.jenkins-ci.plugins:ssh
Jenkins SSH Plugin user passwords for encrypted SSH keys stored in plaintext
pidusage
PIDUsage Enables OS Command Injection
org.opencastproject:opencast-kernel
Opencast has Incorrect Permission Assignment
org.opencastproject:opencast-kernel
Opencast has Incorrect Permission Assignment
org.jenkins-ci.plugins:script-security
Sandbox bypass in Jenkins Script Security Plugin sandbox bypass
org.jenkins-ci.plugins:script-security
Sandbox bypass in Jenkins Script Security Plugin sandbox bypass
io.jenkins.blueocean:blueocean
Improper Authentication in Jenkins Blue Ocean Plugin
io.jenkins.blueocean:blueocean
Improper Authentication in Jenkins Blue Ocean Plugin
mercurial
Mercurial is vulnerable to shell injection attack
mercurial
Mercurial is vulnerable to shell injection attack
org.jenkins-ci.plugins:config-file-provider
Improper Privilege Management in Jenkins Config File Provider Plugin
org.jenkins-ci.plugins:config-file-provider
Improper Privilege Management in Jenkins Config File Provider Plugin
org.jenkins-ci.plugins:parameterized-trigger
Parameterized Trigger Plugin fails to check Item/Build permission
org.jenkins-ci.plugins:parameterized-trigger
Parameterized Trigger Plugin fails to check Item/Build permission
io.jenkins.blueocean:blueocean
Improper Authentication in Jenkins Blue Ocean Plugin
io.jenkins.blueocean:blueocean
Improper Authentication in Jenkins Blue Ocean Plugin
org.jenkins-ci.plugins.workflow:workflow-cps
Arbitrary code execution due to incomplete sandbox protection in Jenkins Pipeline
org.jenkins-ci.plugins.workflow:workflow-cps
Arbitrary code execution due to incomplete sandbox protection in Jenkins Pipeline
mautic/core
Sensitive Cookie Without HttpOnly and Secure Flag
mautic/core
Sensitive Cookie Without HttpOnly and Secure Flag
org.jenkins-ci.plugins:pipeline-build-step
Jenkins Build Step Plugin fails to check Item/Build permission
org.jenkins-ci.plugins:pipeline-build-step
Jenkins Build Step Plugin fails to check Item/Build permission
org.jenkins-ci.plugins:script-security
Unsafe methods in the default list of approved signatures in Jenkins Script Security Plugin
org.jenkins-ci.plugins:script-security
Unsafe methods in the default list of approved signatures in Jenkins Script Security Plugin
trytond, trytond, trytond, trytond, trytond, trytond, trytond
Tryton Information Disclosure Vulnerability
trytond/ trytond/ trytond/ trytond/ trytond/ trytond/ trytond
Tryton Information Disclosure Vulnerability
anchorcms/anchor-cms
Anchor CMS Logs Credentials
yab/quarx
Yab Quarx persistent cross-site scripting vulnerability
yab/quarx
Yab Quarx persistent cross-site scripting vulnerability
org.jboss.ws:jbossws-common
JBossWS vulnerable to uncontrolled recursion
org.jboss.ws:jbossws-common
JBossWS vulnerable to uncontrolled recursion
org.infinispan:infinispan-core
Infinispan: Deserialization of untrusted data in the Hot Rod Java client via automatic byte-array deserialization
org.infinispan:infinispan-core
Infinispan: Deserialization of untrusted data in the Hot Rod Java client via automatic byte-array deserialization
logstash-core
Logstash Logs Sensitive Information
cobbler
Cobbler Arbitrary File Read
org.wildfly:wildfly-undertow
Red Hat Wildfly DoS
rubygems-update
RubyGems vulnerable to Deserialization of Untrusted Data
rubygems-update
RubyGems vulnerable to Deserialization of Untrusted Data
rubygems-update
RubyGems may allow a maliciously crafted gem to overwrite files
rubygems-update
RubyGems may allow a maliciously crafted gem to overwrite files
rubygems-update
RubyGems has Origin Validation Error vulnerability
rubygems-update
RubyGems has Origin Validation Error vulnerability
rubygems-update
RubyGems Code Injection vulnerability
koji
Koji blacklisted paths workaround
bodhi
Bodhi Cross-site Scripting Vulnerability
k8s.io/kubernetes, k8s.io/kubernetes, k8s.io/kubernetes
Kubernetes arbitrary file overwrite
k8s.io/kubernetes/ k8s.io/kubernetes/ k8s.io/kubernetes
Kubernetes arbitrary file overwrite
org.keycloak:keycloak-parent
Keycloak Reflected XSS
org.keycloak:keycloak-parent
Keycloak CSRF Vulnerability
io.undertow:undertow-core, io.undertow:undertow-core, io.undertow:undertow-core
Undertow Request Smuggling vulnerability
io.undertow:undertow-core/ io.undertow:undertow-core/ io.undertow:undertow-core
Undertow Request Smuggling vulnerability
