Open Source Vulnerabilities
io.netty:netty-handler, io.netty:netty-handler
Loop with Unreachable Exit Condition in Netty
io.netty:netty-handler/ io.netty:netty-handler
Loop with Unreachable Exit Condition in Netty
org.igniterealtime.smack:smack-core
Smack allows the bypass of TLS protections
org.igniterealtime.smack:smack-core
Smack allows the bypass of TLS protections
horizon
Horizon-Orchestration Cross-site scripting (XSS) vulnerability through resource name
horizon
Horizon-Orchestration Cross-site scripting (XSS) vulnerability through resource name
org.apache.activemq:activemq-openwire-generator, org.apache.activemq:activemq-parent, org.apache.activemq:activemq-parent
ActiveMQ's OpenWire protocol exposes certain system details as plain text
org.apache.activemq:activemq-openwire-generator/ org.apache.activemq:activemq-parent/ org.apache.activemq:activemq-parent
ActiveMQ's OpenWire protocol exposes certain system details as plain text
horizon
OpenStack Horizon Cross-site scripting (XSS) vulnerability
horizon
OpenStack Horizon Cross-site scripting (XSS) vulnerability
horizon
OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability in the Host Aggregates interface
horizon
OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability in the Host Aggregates interface
pip
Improper Link Resolution Before File Access in pip
pip
pip lack of randomness in build directory
pip
Improper Input Validation in pip
django-crm
MicroPyramid Django-CRM CSRF
requests
Python Requests Session Fixation
jqueryfiletree
jqueryFileTree vulnerable to Directory Traversal
jqueryfiletree
jqueryFileTree vulnerable to Directory Traversal
dapphp/securimage
Securimage HTML Injection
codiad/codiad
Codiad remote code execution vulnerability
codiad/codiad
Codiad remote code execution vulnerability
org.apache.knox:gateway-provider-identity-assertion-common
Apache Knox allows impersonation of users
org.apache.knox:gateway-provider-identity-assertion-common
Apache Knox allows impersonation of users
org.apache.sling:org.apache.sling.api, org.apache.sling:org.apache.sling.servlets.post
Improper Neutralization of Input During Web Page Generation in Apache Sling
org.apache.sling:org.apache.sling.api/ org.apache.sling:org.apache.sling.servlets.post
Improper Neutralization of Input During Web Page Generation in Apache Sling
aoe/restler, luracast/restler
Luracast Restler directory traversal vulnerability
aoe/restler/ luracast/restler
Luracast Restler directory traversal vulnerability
commons-httpclient:commons-httpclient
Improper Certificate Validation in Apache Commons HttpClient
commons-httpclient:commons-httpclient
Improper Certificate Validation in Apache Commons HttpClient
mixlib-archive
mixlib-archive Path Traversal vulnerability
mixlib-archive
mixlib-archive Path Traversal vulnerability
org.cloudfoundry.identity:cloudfoundry-identity-server
Pivotal Cloud Foundry UAA XSS on UAA OpenID Connect check session iframe endpoint
org.cloudfoundry.identity:cloudfoundry-identity-server
Pivotal Cloud Foundry UAA XSS on UAA OpenID Connect check session iframe endpoint
intelliants/subrion
Subrion CMS RCE Vulnerability
org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server, org.cloudfoundry.identity:cloudfoundry-identity-server
Cloud Foundry UAA Denial of Service through client token revocation endpoint
org.cloudfoundry.identity:cloudfoundry-identity-server/ org.cloudfoundry.identity:cloudfoundry-identity-server/ org.cloudfoundry.identity:cloudfoundry-identity-server
Cloud Foundry UAA Denial of Service through client token revocation endpoint
k8s.io/kubernetes
Kubernetes in OpenShift3 Access Control Misconfiguration
k8s.io/kubernetes
Kubernetes in OpenShift3 Access Control Misconfiguration
org.springframework.social:spring-social-core
springframework-social Cross-Site Request Forgery vulnerability
org.springframework.social:spring-social-core
springframework-social Cross-Site Request Forgery vulnerability
com.jcraft:jsch
Improper Limitation of a Pathname to a Restricted Directory in JCraft JSch
com.jcraft:jsch
Improper Limitation of a Pathname to a Restricted Directory in JCraft JSch
urllib3
Improper Neutralization of CRLF Sequences in urllib3 library for Python
urllib3
Improper Neutralization of CRLF Sequences in urllib3 library for Python
org.apache.cxf:cxf-rt-frontend-jaxrs, org.apache.cxf:cxf-rt-frontend-jaxrs, org.apache.cxf:cxf-rt-frontend-jaxrs
Improper Input Validation in Apache CXF
org.apache.cxf:cxf-rt-frontend-jaxrs/ org.apache.cxf:cxf-rt-frontend-jaxrs/ org.apache.cxf:cxf-rt-frontend-jaxrs
Improper Input Validation in Apache CXF
org.apache.cxf:cxf, org.apache.cxf:cxf, org.apache.cxf:cxf
XML Signature/Encryption Not Validated in Apache CXF
org.apache.cxf:cxf/ org.apache.cxf:cxf/ org.apache.cxf:cxf
XML Signature/Encryption Not Validated in Apache CXF
org.apache.cxf:cxf, org.apache.cxf:cxf
Improper Authentication in Apache CXF
org.apache.cxf:cxf/ org.apache.cxf:cxf
Improper Authentication in Apache CXF
org.apache.cxf:cxf, org.apache.cxf:cxf, org.apache.cxf:cxf
Improper Authentication in Apache CXF
org.apache.cxf:cxf/ org.apache.cxf:cxf/ org.apache.cxf:cxf
Improper Authentication in Apache CXF
org.apache.cxf:cxf, org.apache.cxf:cxf, org.apache.cxf:cxf
Remote web-service operation execution in Apache CXF
org.apache.cxf:cxf/ org.apache.cxf:cxf/ org.apache.cxf:cxf
Remote web-service operation execution in Apache CXF
org.apache.cxf:cxf-rt-transports-http, org.apache.cxf:cxf-rt-transports-http, org.apache.cxf:cxf-rt-transports-http
Inadequate Encryption Strength in Apache CXF
org.apache.cxf:cxf-rt-transports-http/ org.apache.cxf:cxf-rt-transports-http/ org.apache.cxf:cxf-rt-transports-http
Inadequate Encryption Strength in Apache CXF
org.apache.cxf.karaf:apache-cxf, org.apache.cxf.karaf:apache-cxf
Covert Timing Channel in Apache CXF
org.apache.cxf.karaf:apache-cxf/ org.apache.cxf.karaf:apache-cxf
Covert Timing Channel in Apache CXF
org.apache.cxf:cxf, org.apache.cxf:cxf, org.apache.cxf:cxf
Improper Authentication in Apache CXF
org.apache.cxf:cxf/ org.apache.cxf:cxf/ org.apache.cxf:cxf
Improper Authentication in Apache CXF
org.apache.cxf:cxf-rt-frontend-jaxrs, org.apache.cxf:cxf-rt-frontend-jaxrs, org.apache.cxf:cxf-rt-frontend-jaxrs
Missing XML Validation in Apache CXF
org.apache.cxf:cxf-rt-frontend-jaxrs/ org.apache.cxf:cxf-rt-frontend-jaxrs/ org.apache.cxf:cxf-rt-frontend-jaxrs
Missing XML Validation in Apache CXF
org.apache.cxf:cxf-rt-rs-security-sso-saml, org.apache.cxf:cxf-rt-rs-security-sso-saml, org.apache.cxf:cxf-rt-rs-security-sso-saml
Improper Access Control in Apache CXF
org.apache.cxf:cxf-rt-rs-security-sso-saml/ org.apache.cxf:cxf-rt-rs-security-sso-saml/ org.apache.cxf:cxf-rt-rs-security-sso-saml
Improper Access Control in Apache CXF
org.apache.cxf:cxf-rt-ws-security, org.apache.cxf:cxf-rt-ws-security
Improper Input Validation in Apache CXF
org.apache.cxf:cxf-rt-ws-security/ org.apache.cxf:cxf-rt-ws-security
Improper Input Validation in Apache CXF
org.apache.cxf:cxf-core, org.apache.cxf:cxf-core
Uncontrolled Resource Consumption in Apache CXF
org.apache.cxf:cxf-core/ org.apache.cxf:cxf-core
Uncontrolled Resource Consumption in Apache CXF
org.apache.cxf:cxf-core, org.apache.cxf:cxf-core
Uncontrolled Resource Consumption in Apache CXF
org.apache.cxf:cxf-core/ org.apache.cxf:cxf-core
Uncontrolled Resource Consumption in Apache CXF
org.apache.cxf:cxf-core, org.apache.cxf:cxf-core, org.apache.cxf:cxf-core
Improper Input Validation in Apache CXF
org.apache.cxf:cxf-core/ org.apache.cxf:cxf-core/ org.apache.cxf:cxf-core
Improper Input Validation in Apache CXF
org.apache.ws.security:wss4j, org.apache.wss4j:wss4j-ws-security-dom
Improper Authentication in Apache WSS4J
org.apache.ws.security:wss4j/ org.apache.wss4j:wss4j-ws-security-dom
Improper Authentication in Apache WSS4J
org.apache.cxf:cxf-rt-frontend-jaxrs, org.apache.cxf:cxf-rt-frontend-jaxrs, org.apache.cxf:cxf-rt-frontend-jaxrs
Loop with Unreachable Exit Condition in Apache CXF
org.apache.cxf:cxf-rt-frontend-jaxrs/ org.apache.cxf:cxf-rt-frontend-jaxrs/ org.apache.cxf:cxf-rt-frontend-jaxrs
Loop with Unreachable Exit Condition in Apache CXF
org.apache.cxf:cxf-core, org.apache.cxf:cxf-core
Cleartext Transmission of Sensitive Information in Apache CXF
org.apache.cxf:cxf-core/ org.apache.cxf:cxf-core
Cleartext Transmission of Sensitive Information in Apache CXF
org.apache.cxf:cxf-core, org.apache.cxf:cxf-core
Improper Neutralization of Input During Web Page Generation in Apache CXF
org.apache.cxf:cxf-core/ org.apache.cxf:cxf-core
Improper Neutralization of Input During Web Page Generation in Apache CXF
org.apache.cxf:cxf-core, org.apache.cxf:cxf-core
Improper Restriction of XML External Entity Reference in Apache CXF JAX-RS
org.apache.cxf:cxf-core/ org.apache.cxf:cxf-core
Improper Restriction of XML External Entity Reference in Apache CXF JAX-RS
org.apache.cxf.fediz:fediz-oidc
Cross-Site Request Forgery in Apache CXF Fediz
org.apache.cxf.fediz:fediz-oidc
Cross-Site Request Forgery in Apache CXF Fediz
org.apache.cxf:cxf-core, org.apache.cxf:cxf-core
Improper Certificate Validation in Apache CXF
org.apache.cxf:cxf-core/ org.apache.cxf:cxf-core
Improper Certificate Validation in Apache CXF
org.apache.cxf:cxf-core, org.apache.cxf:cxf-core
Session Fixation in Apache CXF
org.apache.cxf:cxf-core/ org.apache.cxf:cxf-core
Session Fixation in Apache CXF
github.com/apache/trafficcontrol, github.com/apache/trafficcontrol, github.com/apache/trafficcontrol, github.com/apache/trafficcontrol, github.com/apache/trafficcontrol
Apache Traffic Control vulnerable to Slowloris-style Denial of Service attack
github.com/apache/trafficcontrol/ github.com/apache/trafficcontrol/ github.com/apache/trafficcontrol/ github.com/apache/trafficcontrol/ github.com/apache/trafficcontrol
Apache Traffic Control vulnerable to Slowloris-style Denial of Service attack
org.apache.hadoop:hadoop-common, org.apache.hadoop:hadoop-common
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
org.apache.hadoop:hadoop-common/ org.apache.hadoop:hadoop-common
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
