Open Source Vulnerabilities
org.apache.portals.pluto:pluto-portal
Cross-site Scripting in Apache Pluto
org.apache.portals.pluto:pluto-portal
Cross-site Scripting in Apache Pluto
org.apache.portals.pluto:pluto-portal
Cross-site Scripting in Apache Pluto
org.apache.portals.pluto:pluto-portal
Cross-site Scripting in Apache Pluto
org.apache.portals.pluto:pluto-portal
Cross-site Scripting in Apache Pluto
org.apache.portals.pluto:pluto-portal
Cross-site Scripting in Apache Pluto
scratch-svg-renderer
Cross-site Scripting in Scratch-Svg-Renderer
scratch-svg-renderer
Cross-site Scripting in Scratch-Svg-Renderer
org.apache.kylin:kylin, org.apache.kylin:kylin
In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin.
org.apache.kylin:kylin/ org.apache.kylin:kylin
In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin.
org.apache.kylin:kylin, org.apache.kylin:kylin
Use of Hard-coded Credentials in Apache Kylin
org.apache.kylin:kylin/ org.apache.kylin:kylin
Use of Hard-coded Credentials in Apache Kylin
org.apache.kylin:kylin
SQL Injection in Apache Kylin
org.apache.kylin:kylin
Server-Side Request Forgery in Apache Kylin
org.apache.kylin:kylin
Server-Side Request Forgery in Apache Kylin
org.apache.kylin:kylin, org.apache.kylin:kylin
Kylin can receive user input and load any class through Class.forName(...).
org.apache.kylin:kylin/ org.apache.kylin:kylin
Kylin can receive user input and load any class through Class.forName(...).
org.apache.kylin:kylin
Command Injection in Apache Kylin
org.apache.james:james-server
Infinite Loop in Apache James
org.apache.james:james-server
Infinite Loop in Apache James
org.apache.james:james-server
Command Injection in Apache James
org.apache.james:james-server
Command Injection in Apache James
org.apache.james:james-server
Denial of Service in Apache James
org.apache.james:james-server
Denial of Service in Apache James
Apache.Avro
Allocation of Resources Without Limits or Throttling in Apache Avro
Apache.Avro
Allocation of Resources Without Limits or Throttling in Apache Avro
org.pac4j:pac4j-oidc, org.pac4j:pac4j-oidc
Pac4j token validation bypass if OpenID Connect provider supports none algorithm
org.pac4j:pac4j-oidc/ org.pac4j:pac4j-oidc
Pac4j token validation bypass if OpenID Connect provider supports none algorithm
ssddanbrown/bookstack
bookstack is vulnerable to Improper Access Control
ssddanbrown/bookstack
bookstack is vulnerable to Improper Access Control
bottelet/flarepoint
Cross-site Scripting in DayByDay CRM
bottelet/flarepoint
Missing Authorization in DayByDay CRM
bottelet/flarepoint
Missing Authorization in DayByDay CRM
bottelet/flarepoint
Weak Password Requirements in Daybyday CRM
bottelet/flarepoint
Weak Password Requirements in Daybyday CRM
bottelet/flarepoint
Missing Authorization in DayByDay CRM
@soketi/soketi
Denial of Service in soketi
node-forge
Prototype Pollution in node-forge debug API.
node-forge
Prototype Pollution in node-forge util.setPath API
node-forge
Prototype Pollution in node-forge util.setPath API
node-forge
URL parsing in node-forge could lead to undesired behavior.
node-forge
URL parsing in node-forge could lead to undesired behavior.
k8s.io/kubernetes
kubectl ANSI escape characters not filtered
k8s.io/kubernetes
kubectl ANSI escape characters not filtered
roundcube, roundcube
roundcube - security update
ghostscript, ghostscript
ghostscript - security update
com.google.protobuf:protobuf-java, google-protobuf, com.google.protobuf:protobuf-java, com.google.protobuf:protobuf-java, com.google.protobuf:protobuf-kotlin, com.google.protobuf:protobuf-kotlin
A potential Denial of Service issue in protobuf-java
com.google.protobuf:protobuf-java/ google-protobuf/ com.google.protobuf:protobuf-java/ com.google.protobuf:protobuf-java/ com.google.protobuf:protobuf-kotlin/ com.google.protobuf:protobuf-kotlin
A potential Denial of Service issue in protobuf-java
stdlib
Cleartext transmission of credentials in net/smtp
Improper Access Control in chocobozzz/peertube
python-lxml, python-lxml, python-lxml
python-lxml security update
python-lxml/ python-lxml/ python-lxml
python-lxml security update
resteasy, resteasy, resteasy
resteasy security update
kernel, kernel, kernel
kernel security update
numpy, numpy, numpy
numpy security update
openjpeg2, openjpeg2, openjpeg2
openjpeg2 security update
Server-Side Request Forgery (SSRF) in chocobozzz/peertube
