Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CVE-2022-21144
    Fix available
    Packages

    Summary

    Denial of Service (DoS)

    Published
    1 May 2022
    CVE-2022-21230
    No fix available
    Packages

    Summary

    Information Exposure

    Published
    1 May 2022
    CVE-2022-24437
    Fix available
    Packages

    Summary

    Command Injection

    Published
    1 May 2022
    CVE-2022-25850
    Fix available
    Packages

    Summary

    Server-side Request Forgery (SSRF)

    Published
    1 May 2022
    CVE-2022-28481
    Fix available
    Packages

    Summary

    Published
    1 May 2022
    CVE-2022-23061
    Fix available
    Packages

    Summary

    Shopizer - IDOR delete superadmin

    Published
    1 May 2022
    CVE-2022-23060
    Fix available
    Packages

    Summary

    Shopizer - Stored XSS in Manage Files

    Published
    1 May 2022
    CVE-2022-1544
    Fix available
    Packages

    Summary

    Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in luyadev/yii-helpers

    Published
    1 May 2022
    GHSA-h5jm-jjgx-q2wf
    Fix available
    Packages

    org.xwiki.platform:xwiki-platform-oldcore

    Summary

    XWiki Remote Code Execution

    Published
    1 May 2022
    GHSA-v7cq-pq7v-mh5v
    Fix available
    Packages

    org.apache.derby:derby

    Summary

    Apache Derby SQL Injection

    Published
    1 May 2022
    GHSA-jpqr-vh55-xqxf
    No fix available
    Packages

    org.apache.tomcat:tomcat

    Summary

    Apache Tomcat Buffer Over-Read

    Published
    1 May 2022
    GHSA-p57v-p3fx-qgwm
    Fix available
    Packages

    org.apache.tomcat:tomcat, org.apache.tomcat:tomcat

    Summary

    Apache Tomcat XSS Vulnerability

    Published
    1 May 2022
    GHSA-pm78-wxxf-fw98
    Fix available
    Packages

    org.apache.tomcat:tomcat, org.apache.tomcat:tomcat, org.apache.tomcat:tomcat, org.apache.tomcat:tomcat

    Summary

    Cross-site scripting in Apache Tomcat

    Published
    1 May 2022
    GHSA-jg2x-r643-w2ch
    Fix available
    Packages

    org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server

    Summary

    Jetty Uses Predictable Session Identifiers

    Published
    1 May 2022
    GHSA-2q26-r8c4-jfx5
    Fix available
    Packages

    trac

    Summary

    Edgewall Trac Cross-site request forgery (CSRF) vulnerability

    Published
    1 May 2022
    GHSA-rw73-xmpv-j5x2
    Fix available
    Packages

    cakephp/cakephp

    Summary

    CakePHP directory traversal vulnerability allows remote attackers to read arbitrary files

    Published
    1 May 2022
    GHSA-h9w8-4376-j344
    Fix available
    Packages

    moodle/moodle

    Summary

    Moodle does not properly validate module instance id

    Published
    1 May 2022
    GHSA-hm8g-jxjj-gfm3
    Fix available
    Packages

    zope2, zope2

    Summary

    Zope allows remote attackers to read arbitrary files

    Published
    1 May 2022
    GHSA-r7j4-82xw-8m9p
    Fix available
    Packages

    plone

    Summary

    Plone allows a user to masquerade as a group

    Published
    1 May 2022
    GHSA-5hch-v5pq-x4qp
    Fix available
    Packages

    plone

    Summary

    Plone allows anonymous users to reset any users password through the web via Password Reset Tool

    Published
    1 May 2022
    GHSA-vc29-mvwv-wpcq
    Fix available
    Packages

    cakephp/cakephp

    Summary

    Cross-site scripting (XSS) vulnerability in CakePHP

    Published
    1 May 2022
    GHSA-c5vw-342h-x5rx
    Fix available
    Packages

    org.opencms:opencms-core

    Summary

    Alkacon OpenCms Exposes JSP Source Code

    Published
    1 May 2022
    GHSA-v3c3-qr6m-8m7m
    Fix available
    Packages

    org.opencms:opencms-core

    Summary

    Alkacon OpenCMS Improper Access Control via system/workplace/views/admin/admin-main.jsp

    Published
    1 May 2022
    GHSA-64hc-4jx3-62jp
    Fix available
    Packages

    org.opencms:opencms-core

    Summary

    Alkacon OpenCMS Absolute Path Traversal via pathname in filePath parameter

    Published
    1 May 2022
    GHSA-gj9c-69cm-7c37
    Fix available
    Packages

    org.opencms:opencms-core

    Summary

    Alkacon OpenCms XSS via unsanitized message body

    Published
    1 May 2022
    GHSA-wfj7-mhr5-pcwq
    Fix available
    Packages

    org.apache.tomcat:tomcat

    Summary

    Apache Tomcat Reveals Directories

    Published
    1 May 2022
    GHSA-r524-c2gf-5chr
    Fix available
    Packages

    trac

    Summary

    Trac reStructuredText breach of privacy and denial of service vulnerability

    Published
    1 May 2022
    GHSA-jcjp-qqpq-pc54
    Fix available
    Packages

    zope2, zope2, zope2

    Summary

    Zope allows local users to read arbitrary files

    Published
    1 May 2022
    GHSA-2wxv-3g4v-p76p
    Fix available
    Packages

    phpsysinfo/phpsysinfo

    Summary

    phpSysInfo allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence

    Published
    1 May 2022
    GHSA-mq4x-8whh-jx73
    Fix available
    Packages

    org.mortbay.jetty:jetty

    Summary

    Improper Input Validation in Mortbay Jetty

    Published
    1 May 2022
    GHSA-qmgj-5h75-jr67
    No fix available
    Packages

    org.mortbay.jetty:jetty

    Summary

    Jetty Directory Traversal Vulnerability

    Published
    1 May 2022
    GHSA-pmfx-p95x-cg4p
    Fix available
    Packages

    org.opencms:opencms-core

    Summary

    Alkacon OpenCms XSS via query parameter in a search action

    Published
    1 May 2022
    GHSA-f836-7jqw-3684
    No fix available
    Packages

    extractor

    Summary

    Libextractor multiple heap-based buffer overflows

    Published
    1 May 2022
    GHSA-jcwh-rj6j-vm75
    Fix available
    Packages

    plone, plone, plone

    Summary

    Plone allows remote users to modify arbitrary portraits

    Published
    1 May 2022
    GHSA-7qwv-cwgj-c8rj
    Fix available
    Packages

    struts:struts

    Summary

    Improper Input Validation in Apache Struts

    Published
    1 May 2022
    GHSA-p3vw-fvwx-qcv5
    Fix available
    Packages

    struts:struts

    Summary

    Cross-site scripting in Apache Struts

    Published
    1 May 2022
    GHSA-vf8g-mpmw-qv87
    Fix available
    Packages

    struts:struts

    Summary

    Apache Struts vulnerable to Improper Input Validation

    Published
    1 May 2022
    GHSA-f3xw-vgc7-f7h8
    Fix available
    Packages

    pear/archive_tar

    Summary

    PEAR::Archive_Tar Directory Traversal vulnerability

    Published
    1 May 2022
    GHSA-76rh-xv36-9mrc
    Fix available
    Packages

    pear/auth, pear/auth

    Summary

    PEAR::Auth potential authentication bypass vulnerability

    Published
    1 May 2022
    GHSA-vx77-5pf4-c9wr
    Fix available
    Packages

    cherrypy

    Summary

    CherryPy Directory traversal vulnerability

    Published
    1 May 2022
    GHSA-f9fr-w54q-772h
    Fix available
    Packages

    log4net

    Summary

    Apache log4net format string vulnerability causes DoS

    Published
    1 May 2022
    GHSA-2jxh-3cx8-xw65
    Fix available
    Packages

    geronimo:geronimo-console-standard

    Summary

    Apache Geronimo console 1.0 vulnerable to cross-site scripting

    Published
    1 May 2022
    GHSA-xj84-6q8f-qg2r
    Fix available
    Packages

    typo3/cms

    Summary

    TYPO3 Reveals Sensitive Information via Direct Request to `misc/phpcheck/`

    Published
    1 May 2022
    GHSA-rp7r-79rm-2758
    Fix available
    Packages

    org.apache.derby:derby

    Summary

    Apache Derby exposes user and password attributes

    Published
    1 May 2022
    GHSA-qrcx-p4rr-g48h
    No fix available
    Packages

    org.apache.tomcat:tomcat

    Summary

    Apache Tomcat allows remote attackers to read JSP source files

    Published
    1 May 2022
    GHSA-x89r-2wjq-mj7x
    No fix available
    Packages

    org.apache.tomcat:tomcat

    Summary

    Apache Tomcat Discloses MS-DOS Pathname

    Published
    1 May 2022
    GHSA-6vhp-hp77-6w52
    Fix available
    Packages

    trac

    Summary

    Trac HTML WikiProcessor cross-site scripting (XSS) vulnerability

    Published
    1 May 2022
    GHSA-g4fc-j79q-gjrh
    Fix available
    Packages

    org.opencms:opencms-core

    Summary

    Alkacon OpenCms XSS via username during login

    Published
    1 May 2022
    GHSA-9cjh-qmvx-436c
    No fix available
    Packages

    org.apache.struts:struts-core

    Summary

    Apache Struts Cross-site scripting Vulnerability

    Published
    1 May 2022
    GHSA-cwq3-qp8v-w8q3
    Fix available
    Packages

    org.mortbay.jetty:jetty

    Summary

    Mortbay Jetty Discloses JSP Source Code

    Published
    1 May 2022