Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CVE-2022-20629
    No fix available
    Packages

    Summary

    Published
    3 May 2022
    CVE-2022-20628
    No fix available
    Packages

    Summary

    Published
    3 May 2022
    CVE-2022-20627
    No fix available
    Packages

    Summary

    Published
    3 May 2022
    GHSA-jmhj-vh4q-hhmq
    Fix available
    Packages

    tkvideoplayer

    Summary

    tkvideo has a memory issue in playing videos

    Published
    3 May 2022
    GHSA-3p86-xgrq-m6p6
    Fix available
    Packages

    org.apache.tomcat:tomcat, org.apache.tomcat:tomcat, org.apache.tomcat:tomcat

    Summary

    Improper Neutralization of Input During Web Page Generation in Apache Tomcat

    Published
    3 May 2022
    Packages

    libxml2, libxml2, libxml2

    Summary

    Published
    3 May 2022
    Packages

    libxml2, libxml2, libxml2, libxml2, libxml2, libxml2, libxml2, libxml2, libxml2, libxml2, libxml2, libxml2, libxml2

    Summary

    Published
    3 May 2022
    AZL-9617
    Fix available
    Packages

    libxslt

    Summary

    CVE-2022-29824 affecting package libxslt for versions less than 1.1.34-7

    Published
    3 May 2022
    AZL-9616
    Fix available
    Packages

    libxml2

    Summary

    CVE-2022-29824 affecting package libxml2 for versions less than 2.9.14-1

    Published
    3 May 2022
    Packages

    libxml2, libxml2, libxml2, libxml2, libxml2

    Summary

    Published
    3 May 2022
    GHSA-j5cc-3h6r-jqh4
    No fix available
    Packages

    zope

    Summary

    Zope DocumentTemplate package allows unauthenticated write

    Published
    3 May 2022
    CVE-2022-28118
    No fix available
    Packages

    Summary

    Published
    3 May 2022
    GHSA-7pfc-cx3m-v22x
    Fix available
    Packages

    s-cart/core, s-cart/s-cart

    Summary

    SCart is vulnerable to cross-site scripting (XSS)

    Published
    3 May 2022
    GHSA-773h-w45w-f2f9
    Fix available
    Packages

    libxmljs

    Summary

    Denial of service vulnerability exists in libxmljs

    Published
    3 May 2022
    GHSA-3x62-x456-q2vm
    Fix available
    Packages

    git-pull-or-clone

    Summary

    OS Command Injection in git-pull-or-clone

    Published
    3 May 2022
    GHSA-3xgx-r9j4-qw9w
    Fix available
    Packages

    dexie, dexie

    Summary

    Prototype Pollution in Dexie

    Published
    3 May 2022
    GHSA-77m7-9wvw-87fx
    No fix available
    Packages

    jailed

    Summary

    Privilege Issues in jailed

    Published
    3 May 2022
    GHSA-f55g-x8qq-2569
    Fix available
    Packages

    csv-safe

    Summary

    CSV-Safe improperly filters special characters potentially leading to CSV injection

    Published
    3 May 2022
    GHSA-f9p3-h6cg-2cjr
    Fix available
    Packages

    luyadev/yii-helpers

    Summary

    Improper neutralization of formula elements in yii-helpers

    Published
    3 May 2022
    GHSA-vh38-ghx6-vmvg
    No fix available
    Packages

    Masuit.Tools.Core

    Summary

    Code Injection in Masuit.Tools.Core

    Published
    3 May 2022
    GHSA-23wx-cgxq-vpwx
    Fix available
    Packages

    dset, org.webjars.npm:dset

    Summary

    Prototype Pollution in dset

    Published
    3 May 2022
    GHSA-7jvx-f994-rfw2
    No fix available
    Packages

    materialize-css

    Summary

    materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input

    Published
    3 May 2022
    GHSA-m2h2-264f-f486
    No fix available
    Packages

    angular

    Summary

    angular vulnerable to regular expression denial of service (ReDoS)

    Published
    3 May 2022
    GHSA-5hjh-c26m-xw8w
    Fix available
    Packages

    github.com/hoppscotch/proxyscotch

    Summary

    ProxyScotch is vulnerable to a server-side Request Forgery (SSRF)

    Published
    3 May 2022
    GHSA-4jrv-ppp4-jm57
    Fix available
    Packages

    com.google.code.gson:gson

    Summary

    Deserialization of Untrusted Data in Gson

    Published
    3 May 2022
    GHSA-w39x-chvm-pj3c
    No fix available
    Packages

    com.bstek.ureport:ureport2-console

    Summary

    Deserialization of Untrusted Data in com.bstek.ureport:ureport2-console

    Published
    3 May 2022
    GHSA-9hr3-j9mc-xmq2
    Fix available
    Packages

    com.alibaba.oneagent:one-java-agent-plugin

    Summary

    Path Traversal in com.alibaba.oneagent:one-java-agent-plugin

    Published
    3 May 2022
    GHSA-p3pg-64pv-v7jg
    No fix available
    Packages

    jsgui-lang-essentials

    Summary

    Prototype Pollution in jsgui-lang-essentials

    Published
    3 May 2022
    GHSA-rr33-j5p5-ppf8
    No fix available
    Packages

    org.geoserver:gs-main, org.geoserver:gs-main

    Summary

    GeoServer allows SSRF via the option for setting a proxy host

    Published
    3 May 2022
    GHSA-9vh6-qfv6-vcqp
    Fix available
    Packages

    snipe/snipe-it

    Summary

    snipe-IT vulnerable to host header injection

    Published
    3 May 2022
    GHSA-qp49-3pvw-x4m5
    Fix available
    Packages

    sinatra

    Summary

    sinatra does not validate expanded path matches

    Published
    3 May 2022
    GHSA-jfph-3hpg-2f65
    Fix available
    Packages

    shopxo/shopxo

    Summary

    Incorrect Permission Assignment for Critical Resource in ShopXO

    Published
    3 May 2022
    DSA-5128-1
    Fix available
    Packages

    openjdk-17

    Summary

    openjdk-17 - security update

    Published
    3 May 2022
    DLA-2992-1
    Fix available
    Packages

    openvpn

    Summary

    openvpn - security update

    Published
    3 May 2022
    DLA-2991-1
    Fix available
    Packages

    twisted

    Summary

    twisted - security update

    Published
    3 May 2022
    Packages

    openssl, edk2, openssl, openssl, openssl

    Summary

    Published
    3 May 2022
    Packages

    edk2, openssl

    Summary

    Published
    3 May 2022
    Packages

    openssl

    Summary

    Published
    3 May 2022
    Packages

    openssl, openssl, edk2, openssl, openssl, openssl, openssl1.0, openssl, openssl, openssl, openssl, openssl, nodejs, openssl

    Summary

    Published
    3 May 2022
    CVE-2022-29824
    Fix available
    Packages

    Summary

    Published
    3 May 2022
    CVE-2022-24974
    No fix available
    Packages

    Summary

    Published
    2 May 2022
    CVE-2021-4138
    Fix available
    Packages

    Summary

    Published
    2 May 2022
    CVE-2021-42532
    No fix available
    Packages

    Summary

    Published
    2 May 2022
    Packages

    exempi, exempi, exempi

    Summary

    Published
    2 May 2022
    CVE-2021-42531
    No fix available
    Packages

    Summary

    Published
    2 May 2022
    Packages

    exempi, exempi, exempi

    Summary

    Published
    2 May 2022
    CVE-2021-42530
    No fix available
    Packages

    Summary

    Published
    2 May 2022
    Packages

    exempi, exempi, exempi

    Summary

    Published
    2 May 2022
    CVE-2021-42529
    No fix available
    Packages

    Summary

    Published
    2 May 2022
    Packages

    exempi, exempi, exempi

    Summary

    Published
    2 May 2022