Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CVE-2021-41994
    No fix available
    Packages

    Summary

    Published
    30 Apr 2022
    CVE-2021-41993
    No fix available
    Packages

    Summary

    Published
    30 Apr 2022
    CVE-2021-41992
    No fix available
    Packages

    Summary

    Published
    30 Apr 2022
    GHSA-pqr5-9v2j-44xg
    No fix available
    Packages

    org.apache.tomcat:tomcat

    Summary

    Apache Tomcat DoS via Malicious Get Request

    Published
    30 Apr 2022
    GHSA-m8w6-7rh6-4xj6
    Fix available
    Packages

    org.apache.tomcat:tomcat

    Summary

    Apache Tomcat Leaks Information via Error Message

    Published
    30 Apr 2022
    GHSA-r6cf-cr44-m8rr
    No fix available
    Packages

    org.apache.tomcat:tomcat

    Summary

    Apache Tomcat Leaks Pathname Information via Error Message

    Published
    30 Apr 2022
    GHSA-8g4f-fh7f-4fwh
    Fix available
    Packages

    org.apache.tomcat:tomcat, org.apache.tomcat:tomcat

    Summary

    Apache Tomcat Default Installation Reveals Sensitive Information

    Published
    30 Apr 2022
    GHSA-86fp-jgwm-wgj5
    Fix available
    Packages

    org.apache.tomcat:tomcat

    Summary

    Apache Tomcat XSS Vulnerability

    Published
    30 Apr 2022
    GHSA-5mq8-h82p-wjf2
    Fix available
    Packages

    org.mortbay.jetty:jetty

    Summary

    Jetty Javascript Inclusion Vulnerability

    Published
    30 Apr 2022
    GHSA-8v5p-2cpv-c2x6
    Fix available
    Packages

    org.apache.tomcat:tomcat

    Summary

    Apache Tomcat Source Code Disclosure

    Published
    30 Apr 2022
    GHSA-jxcv-v856-j5vg
    Fix available
    Packages

    org.apache.tomcat:tomcat, org.apache.tomcat:tomcat

    Summary

    Apache Tomcat Source Code Disclosure

    Published
    30 Apr 2022
    GHSA-xmf4-j3j7-xj7q
    Fix available
    Packages

    org.apache.tomcat:tomcat

    Summary

    Apache Tomcat DoS Via Requests Including Null Characters

    Published
    30 Apr 2022
    GHSA-vwrc-g9q6-f675
    Fix available
    Packages

    zope, zope

    Summary

    Zope Server vulnerable to DoS via header injection

    Published
    30 Apr 2022
    GHSA-7944-h5rw-qmjx
    Fix available
    Packages

    zope

    Summary

    ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions

    Published
    30 Apr 2022
    GHSA-p543-jg43-9pm5
    Fix available
    Packages

    org.apache.tomcat:tomcat

    Summary

    Apache Tomcat may be started without proper security settings

    Published
    30 Apr 2022
    GHSA-c3rp-4cjh-cp38
    Fix available
    Packages

    zope, zope

    Summary

    Zope does not properly verify the access for objects with proxy roles

    Published
    30 Apr 2022
    GHSA-2w2w-cv3h-rr38
    Fix available
    Packages

    org.apache.tomcat:tomcat

    Summary

    Apache Tomcat Reveals Path through Long URL

    Published
    30 Apr 2022
    GHSA-58hj-575g-5j25
    No fix available
    Packages

    org.apache.tomcat:tomcat

    Summary

    Apache Tomcat allows webmasters to insert xss into error messages

    Published
    30 Apr 2022
    GHSA-x445-mmpw-7r4f
    Fix available
    Packages

    org.apache.tomcat:tomcat-servlet-api

    Summary

    Apache Tomcat Allows Source Disclosure

    Published
    30 Apr 2022
    GHSA-4gr9-99j3-vqxv
    No fix available
    Packages

    org.apache.tomcat:tomcat

    Summary

    Apache Tomcat Directory Traversal

    Published
    30 Apr 2022
    GHSA-h2xh-jvpf-xq42
    No fix available
    Packages

    zope

    Summary

    Zope does not properly perform security registration for legacy names

    Published
    30 Apr 2022
    GHSA-7whr-j8vf-r4wj
    No fix available
    Packages

    zope

    Summary

    Zope allows attackers to modify raw image and file data

    Published
    30 Apr 2022
    GHSA-qg4g-6jcq-rw93
    No fix available
    Packages

    org.apache.tomcat:tomcat

    Summary

    Jakarta Apache Tomcat Reveals Physical Paths

    Published
    30 Apr 2022
    GHSA-9cmq-pj6p-hgwf
    Fix available
    Packages

    zope

    Summary

    Zope does not properly restrict access to the getRoles method

    Published
    30 Apr 2022
    GHSA-wcwp-r3fj-mm3p
    No fix available
    Packages

    zope

    Summary

    Zope DTML implementation Improper Authentication

    Published
    30 Apr 2022
    CVE-2022-28323
    No fix available
    Packages

    Summary

    Published
    30 Apr 2022
    CVE-2022-29265
    No fix available
    Packages

    Summary

    Improper Restriction of XML External Entity References in Multiple Components

    Published
    30 Apr 2022
    OSV-2022-385
    No fix available
    Packages

    xmlpull

    Summary

    Uncaught exception in jaz.Zer.<clinit>

    Published
    30 Apr 2022
    GHSA-9hgc-wpc5-v8p9
    Fix available
    Packages

    remdex/livehelperchat

    Summary

    An attacker can execute malicious javascript in Live Helper Chat

    Published
    30 Apr 2022
    GHSA-6q9g-3vfq-q2qj
    Fix available
    Packages

    moodle/moodle, moodle/moodle, moodle/moodle

    Summary

    Improper Authentication in moodle

    Published
    30 Apr 2022
    GHSA-jv64-2m3x-6v4q
    No fix available
    Packages

    intelliants/subrion

    Summary

    Subrion CMS Cross-site Scripting (XSS) vulnerability in the `contact us` plugin

    Published
    30 Apr 2022
    GHSA-66vw-v2x9-hw75
    Fix available
    Packages

    github.com/containers/podman/v3, github.com/containers/psgo

    Summary

    Podman publishes a malicious image to public registries

    Published
    30 Apr 2022
    GHSA-c5hf-mc85-2hx4
    Fix available
    Packages

    moodle/moodle, moodle/moodle, moodle/moodle

    Summary

    Missing authorization in Moodle

    Published
    30 Apr 2022
    GHSA-pxpf-v376-7xx5
    Fix available
    Packages

    @yaireo/tagify

    Summary

    tagify can pass a malicious placeholder to initiate the cross-site scripting (XSS) payload

    Published
    30 Apr 2022
    GHSA-vmp5-c5hp-6c65
    Fix available
    Packages

    github.com/woodpecker-ci/woodpecker

    Summary

    Woodpecker allows cross-site scripting (XSS) via build logs

    Published
    30 Apr 2022
    OSV-2022-383
    Fix available
    Packages

    radare2

    Summary

    Heap-use-after-free in r_asm_free

    Published
    30 Apr 2022
    DLA-2987-1
    Fix available
    Packages

    libarchive

    Summary

    libarchive - security update

    Published
    30 Apr 2022
    Packages

    glewlwyd, glewlwyd

    Summary

    Published
    29 Apr 2022
    UBUNTU-CVE-2022-29967
    No fix available
    Packages

    glewlwyd, glewlwyd, glewlwyd

    Summary

    Published
    29 Apr 2022
    CVE-2022-29967
    Fix available
    Packages

    Summary

    Published
    29 Apr 2022
    CVE-2022-28198
    No fix available
    Packages

    Summary

    Published
    29 Apr 2022
    CVE-2022-29947
    Fix available
    Packages

    Summary

    Published
    29 Apr 2022
    CVE-2022-25854
    Fix available
    Packages

    Summary

    Cross-site Scripting (XSS)

    Published
    29 Apr 2022
    CVE-2022-1543
    Fix available
    Packages

    Summary

    Improper handling of Length parameter in erudika/scoold

    Published
    29 Apr 2022
    CVE-2022-29937
    No fix available
    Packages

    Summary

    Published
    29 Apr 2022
    CVE-2022-29936
    No fix available
    Packages

    Summary

    Published
    29 Apr 2022
    CVE-2022-29935
    No fix available
    Packages

    Summary

    Published
    29 Apr 2022
    CVE-2022-29934
    No fix available
    Packages

    Summary

    Published
    29 Apr 2022
    CVE-2022-29451
    No fix available
    Packages

    Summary

    Published
    29 Apr 2022
    CVE-2022-29414
    No fix available
    Packages

    Summary

    Published
    29 Apr 2022