Open Source Vulnerabilities
net.mingsoft:ms-mcms
Arbitrary file upload in Mingsoft MCMS
net.mingsoft:ms-mcms
Arbitrary file upload in Mingsoft MCMS
ghostscript
Heap-use-after-free in pdfi_cspace_free_callback
snipe/snipe-it
Incorrect Default Permissions and Improper Access Control in snipe-it
snipe/snipe-it
Incorrect Default Permissions and Improper Access Control in snipe-it
OrchardCore
orchardcore is vulnerable to Cross-site Scripting
OrchardCore
orchardcore is vulnerable to Cross-site Scripting
nanoid
Exposure of Sensitive Information to an Unauthorized Actor in nanoid
nanoid
Exposure of Sensitive Information to an Unauthorized Actor in nanoid
dolibarr/dolibarr
SQL Injection in dolibarr
node-fetch, node-fetch
node-fetch forwards secure headers to untrusted sites
node-fetch/ node-fetch
node-fetch forwards secure headers to untrusted sites
calibreweb
calibre-web is vulnerable to Cross-site Scripting
calibreweb
calibre-web is vulnerable to Cross-site Scripting
bytefury/crater
crater is vulnerable to Unrestricted Upload of File with Dangerous Type
bytefury/crater
crater is vulnerable to Unrestricted Upload of File with Dangerous Type
bytefury/crater
Unrestricted Upload of File with Dangerous Type in Crater
bytefury/crater
Unrestricted Upload of File with Dangerous Type in Crater
epubjs
Cross-site Scripting in epubjs
org.apache.knox:gateway-service-knoxsso
Cross-site Scripting in Apache Knox SSO
org.apache.knox:gateway-service-knoxsso
Cross-site Scripting in Apache Knox SSO
pimcore/pimcore
pimcore is vulnerable to Cross-site Scripting
pimcore/pimcore
pimcore is vulnerable to Cross-site Scripting
pimcore/pimcore
pimcore is vulnerable to SQL Injection
remdex/livehelperchat
livehelperchat is vulnerable to Cross-site Scripting
remdex/livehelperchat
livehelperchat is vulnerable to Cross-site Scripting
pimcore/pimcore
pimcore is vulnerable to Cross-site Scripting
pimcore/pimcore
pimcore is vulnerable to Cross-site Scripting
icecoder/icecoder
icecoder is vulnerable to Cross-site Scripting
icecoder/icecoder
icecoder is vulnerable to Cross-site Scripting
calibreweb
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
calibreweb
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
calibreweb
calibre-web is vulnerable to Business Logic Errors
calibreweb
calibre-web is vulnerable to Business Logic Errors
wagtail
Comment reply notifications sent to incorrect users
wagtail
Comment reply notifications sent to incorrect users
gradio
Files on the host computer can be accessed from the Gradio interface
gradio
Files on the host computer can be accessed from the Gradio interface
edu.stanford.nlp:stanford-corenlp
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
edu.stanford.nlp:stanford-corenlp
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
colors
Infinite Loop in colors.js
de.tum.in.ase:artemis-java-test-sandbox
Trust Boundary Violation due to Incomplete Blacklist in Test Failure Processing in Ares
de.tum.in.ase:artemis-java-test-sandbox
Trust Boundary Violation due to Incomplete Blacklist in Test Failure Processing in Ares
io.jenkins:configuration-as-code, io.jenkins:configuration-as-code, io.jenkins:configuration-as-code, io.jenkins:configuration-as-code
Observable Discrepancy and Observable Timing Discrepancy in Jenkins Configuration as Code Plugin
io.jenkins:configuration-as-code/ io.jenkins:configuration-as-code/ io.jenkins:configuration-as-code/ io.jenkins:configuration-as-code
Observable Discrepancy and Observable Timing Discrepancy in Jenkins Configuration as Code Plugin
io.jenkins.plugins:warnings-ng, io.jenkins.plugins:warnings-ng, io.jenkins.plugins:warnings-ng, io.jenkins.plugins:warnings-ng
Path Traversal in Jenkins Warnings Next Generation Plugin
io.jenkins.plugins:warnings-ng/ io.jenkins.plugins:warnings-ng/ io.jenkins.plugins:warnings-ng/ io.jenkins.plugins:warnings-ng
Path Traversal in Jenkins Warnings Next Generation Plugin
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Cross-Site Request Forgery in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Cross-Site Request Forgery in Jenkins
shelljs
Improper Privilege Management in shelljs
remdex/livehelperchat
User enumeration in livehelperchat
org.apache.james:james-server
Path traversal in Apache James
org.apache.james:james-server
Path traversal in Apache James
node-forge
Open Redirect in node-forge
PeterO.Cbor
Denial of service in CBOR library
Umbraco.Cms.Core
Umbraco Persistent Password Reset Poison
Umbraco.Cms.Core
Umbraco ApplicationURL Overwrite
pimcore/pimcore
Unrestricted Upload of File with Dangerous Type in pimcore
pimcore/pimcore
Unrestricted Upload of File with Dangerous Type in pimcore
codechecker
Cross-site Scripting in Ericsson CodeChecker
pimcore/pimcore
Cross-site Scripting in pimcore
spipu/html2pdf
Cross-site Scripting in HTML2PDF
ujson
UltraJSON vulnerable to Out-of-bounds Write
log4j:log4j, org.zenframework.z8.dependencies.commons:log4j-1.2.17
Deserialization of Untrusted Data in Log4j 1.x
log4j:log4j/ org.zenframework.z8.dependencies.commons:log4j-1.2.17
Deserialization of Untrusted Data in Log4j 1.x
log4j:log4j, org.zenframework.z8.dependencies.commons:log4j-1.2.17
SQL Injection in Log4j 1.2.x
log4j:log4j/ org.zenframework.z8.dependencies.commons:log4j-1.2.17
SQL Injection in Log4j 1.2.x
livehelperchat/livehelperchat
Cross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat
livehelperchat/livehelperchat
Cross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat
com.hazelcast.jet:hazelcast-jet, com.hazelcast:hazelcast, com.hazelcast:hazelcast, com.hazelcast:hazelcast, com.hazelcast:hazelcast
Security Advisory for "Log4Shell"
com.hazelcast.jet:hazelcast-jet/ com.hazelcast:hazelcast/ com.hazelcast:hazelcast/ com.hazelcast:hazelcast/ com.hazelcast:hazelcast
Security Advisory for "Log4Shell"
ezsystems/ezpublish-kernel
IBX-1392: Image filenames sanitization
ezsystems/ezpublish-kernel
IBX-1392: Image filenames sanitization
cgi, cgi, cgi
Cookie Prefix Spoofing in CGI::Cookie.parse
com.upokecenter:cbor
Denial of service in CBOR library
onionshare-cli
Out-of-bounds Read in Onionshare
onionshare-cli
Denial of Service in Onionshare
