Open Source Vulnerabilities
pywps
XML External Entity Injection in PyWPS
billz/raspap-webgui
Command Injection in RaspAP 2.6.6
billz/raspap-webgui
raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions.
billz/raspap-webgui
raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions.
transpile
Uncontrolled Resource Consumption in transpile
transpile
Uncontrolled Resource Consumption in transpile
pac-resolver, degenerator
Code Injection in pac-resolver
startserver
Directory Traversal in startserver
mootools
Prototype Pollution in mootools
joplin
Cross-site Request Forgery (CSRF) in joplin
dolibarr/dolibarr
Weak Password Recovery Mechanism for Forgotten Password
dolibarr/dolibarr
Weak Password Recovery Mechanism for Forgotten Password
@diez/generation
Command injection in @diez/generation
showdoc/showdoc
Use of Cryptographically Weak Pseudo-Random Number Generator in showdoc
showdoc/showdoc
Use of Cryptographically Weak Pseudo-Random Number Generator in showdoc
org.http4s:http4s-server_2.13.0-M5, org.http4s:http4s-server_3, org.http4s:http4s-server_3, org.http4s:http4s-server_2.10, org.http4s:http4s-server_2.11, org.http4s:http4s-server_2.12, org.http4s:http4s-server_2.12, org.http4s:http4s-server_2.12, org.http4s:http4s-server_2.13, org.http4s:http4s-server_2.13, org.http4s:http4s-server_2.13
Default CORS config allows any origin with credentials
org.http4s:http4s-server_2.13.0-M5/ org.http4s:http4s-server_3/ org.http4s:http4s-server_3/ org.http4s:http4s-server_2.10/ org.http4s:http4s-server_2.11/ org.http4s:http4s-server_2.12/ org.http4s:http4s-server_2.12/ org.http4s:http4s-server_2.12/ org.http4s:http4s-server_2.13/ org.http4s:http4s-server_2.13/ org.http4s:http4s-server_2.13
Default CORS config allows any origin with credentials
parse-server
Parse Server crashes with query parameter
file, file, file, file, file, file, file, file, python-magic, file, file, file, file, file, file
Security update for file
file/ file/ file/ file/ file/ file/ file/ file/ python-magic/ file/ file/ file/ file/ file/ file
Security update for file
ffmpeg, ffmpeg, ffmpeg, ffmpeg, ffmpeg, ffmpeg, ffmpeg, ffmpeg, ffmpeg, ffmpeg, ffmpeg, ffmpeg, ffmpeg
Security update for ffmpeg
ffmpeg/ ffmpeg/ ffmpeg/ ffmpeg/ ffmpeg/ ffmpeg/ ffmpeg/ ffmpeg/ ffmpeg/ ffmpeg/ ffmpeg/ ffmpeg/ ffmpeg
Security update for ffmpeg
rubygem-addressable
Security update for rubygem-addressable
rubygem-addressable
Security update for rubygem-addressable
rubygem-addressable
Security update for rubygem-addressable
rubygem-addressable
Security update for rubygem-addressable
php72, php72
Security update for php72
xen, xen, xen, xen, xen, xen, xen, xen, xen
Security update for xen
xen/ xen/ xen/ xen/ xen/ xen/ xen/ xen/ xen
Security update for xen
xen, xen, xen
Security update for xen
xen, xen, xen
Security update for xen
xerces-c, xerces-c, xerces-c, xerces-c, xerces-c, xerces-c, xerces-c, xerces-c, xerces-c, xerces-c, xerces-c, xerces-c, xerces-c
Security update for xerces-c
xerces-c/ xerces-c/ xerces-c/ xerces-c/ xerces-c/ xerces-c/ xerces-c/ xerces-c/ xerces-c/ xerces-c/ xerces-c/ xerces-c/ xerces-c
Security update for xerces-c
ffmpeg
Security update for ffmpeg
ffmpeg, ffmpeg, ffmpeg, ffmpeg, ffmpeg, ffmpeg
Security update for ffmpeg
ffmpeg/ ffmpeg/ ffmpeg/ ffmpeg/ ffmpeg/ ffmpeg
Security update for ffmpeg
apache2, apache2, apache2
Security update for apache2
libesmtp, libesmtp, libesmtp, libesmtp, libesmtp, libesmtp, libesmtp, libesmtp, libesmtp, libesmtp, libesmtp, libesmtp, libesmtp, libesmtp
Security update for libesmtp
libesmtp/ libesmtp/ libesmtp/ libesmtp/ libesmtp/ libesmtp/ libesmtp/ libesmtp/ libesmtp/ libesmtp/ libesmtp/ libesmtp/ libesmtp/ libesmtp
Security update for libesmtp
gstreamer-plugins-good, gstreamer-plugins-good
Security update for gstreamer-plugins-good
gstreamer-plugins-good/ gstreamer-plugins-good
Security update for gstreamer-plugins-good
