Open Source Vulnerabilities
postcss, postcss
Regular Expression Denial of Service in postcss
postcss/ postcss
Regular Expression Denial of Service in postcss
diskusage-ng
OS Command Injection in diskusage-ng
node-mpv
OS Command Injection in node-mpv
kubernetes, kubernetes, kubernetes
kubernetes, kubernetes, kubernetes
numpy
NumPy Buffer Overflow (Disputed)
ghostscript
UNKNOWN READ in gx_restrict_Pattern
apache-httpd
Heap-buffer-overflow in ap_is_chunked
cvxopt
Incorrect Comparison in cvxopt
gaoming13/wechat-php-sdk
Wechat-php-sdk is affected by a Cross Site Scripting vulnerability.
gaoming13/wechat-php-sdk
Wechat-php-sdk is affected by a Cross Site Scripting vulnerability.
zstd
Global-buffer-overflow in ZSTD_compressBlock_opt0
org.apache.parquet:parquet, org.apache.parquet:parquet
Improper Input Validation in Parquet-MR
org.apache.parquet:parquet/ org.apache.parquet:parquet
Improper Input Validation in Parquet-MR
pytorch-lightning
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
pytorch-lightning
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
com.h2database:h2
RCE in H2 Console
pocketmine/pocketmine-mp, pocketmine/pocketmine-mp
Uncapped length of skin data fields submitted by players
pocketmine/pocketmine-mp/ pocketmine/pocketmine-mp
Uncapped length of skin data fields submitted by players
pocketmine/pocketmine-mp, pocketmine/pocketmine-mp
Book page text, count, and author/title length is not limited in PocketMine-MP
pocketmine/pocketmine-mp/ pocketmine/pocketmine-mp
Book page text, count, and author/title length is not limited in PocketMine-MP
shopware/shopware
Open redirect in shopware
shopware/shopware
Insufficient Session Expiration in shopware
shopware/shopware
Insufficient Session Expiration in shopware
gerapy
An authenticated user can execute arbitrary command in Gerapy
gerapy
An authenticated user can execute arbitrary command in Gerapy
org.typelevel:jawn-parser_0.25, org.typelevel:jawn-parserg, org.typelevel:jawn-parser_0.27, org.typelevel:jawn-parser_2.10, org.typelevel:jawn-parser_2.11, org.typelevel:jawn-parser_2.12, org.typelevel:jawn-parser_2.13, org.typelevel:jawn-parser_2.13.0-M5, org.typelevel:jawn-parser_2.13.0-RC1, org.typelevel:jawn-parser_2.13.0-RC2, org.typelevel:jawn-parser_2.13.0-RC3, org.typelevel:jawn-parser_3, org.typelevel:jawn-parser_3.0.0-M1, org.typelevel:jawn-parser_3.0.0-M2, org.typelevel:jawn-parser_3.0.0-M3, org.typelevel:jawn-parser_3.0.0-RC1, org.typelevel:jawn-parser_3.0.0-RC2, org.typelevel:jawn-parser_3.0.0-RC3
Hash collision in typelevel jawn
org.typelevel:jawn-parser_0.25/ org.typelevel:jawn-parserg/ org.typelevel:jawn-parser_0.27/ org.typelevel:jawn-parser_2.10/ org.typelevel:jawn-parser_2.11/ org.typelevel:jawn-parser_2.12/ org.typelevel:jawn-parser_2.13/ org.typelevel:jawn-parser_2.13.0-M5/ org.typelevel:jawn-parser_2.13.0-RC1/ org.typelevel:jawn-parser_2.13.0-RC2/ org.typelevel:jawn-parser_2.13.0-RC3/ org.typelevel:jawn-parser_3/ org.typelevel:jawn-parser_3.0.0-M1/ org.typelevel:jawn-parser_3.0.0-M2/ org.typelevel:jawn-parser_3.0.0-M3/ org.typelevel:jawn-parser_3.0.0-RC1/ org.typelevel:jawn-parser_3.0.0-RC2/ org.typelevel:jawn-parser_3.0.0-RC3
Hash collision in typelevel jawn
latte/latte, latte/latte, latte/latte
Sandbox bypass in Latte templates
latte/latte/ latte/latte/ latte/latte
Sandbox bypass in Latte templates
wordpress, wordpress, wordpress
wordpress, wordpress, wordpress
wordpress, wordpress, wordpress
wordpress, wordpress, wordpress
laravel/framework
OS Command Injection in Laravel Framework
laravel/framework
OS Command Injection in Laravel Framework
Authenticated Object Injection in Multisites in WordPress
codeigniter4/framework
Deserialization of Untrusted Data in Codeigniter4
codeigniter4/framework
Deserialization of Untrusted Data in Codeigniter4
jquery.terminal
jquery.terminal self XSS on user input
drupal/drupal, drupal/drupal, drupal/drupal, drupal/core, drupal/core, drupal/core
Arbitrary PHP code execution in Drupal
drupal/drupal/ drupal/drupal/ drupal/drupal/ drupal/core/ drupal/core/ drupal/core
Arbitrary PHP code execution in Drupal
@uppy/companion
uppy's companion module is vulnerable to Server-Side Request Forgery (SSRF)
@uppy/companion
uppy's companion module is vulnerable to Server-Side Request Forgery (SSRF)
org.apache.geode:geode-core, org.apache.geode:geode-core
Insertion of Sensitive Information into Log File in Apache Geode
org.apache.geode:geode-core/ org.apache.geode:geode-core
Insertion of Sensitive Information into Log File in Apache Geode
showdoc/showdoc
showdoc is vulnerable to Generation of Error Message Containing Sensitive Information
showdoc/showdoc
showdoc is vulnerable to Generation of Error Message Containing Sensitive Information
userfrosting/userfrosting
Injection in UserFrosting
celery
OS Command Injection in celery
