Open Source Vulnerabilities
cyclonedds, cyclonedds, cyclonedds, cyclonedds
cyclonedds, cyclonedds, cyclonedds, cyclonedds
shopware/core, shopware/platform
Cross-Site Scripting via SVG media files
shopware/core/ shopware/platform
Cross-Site Scripting via SVG media files
shopware/platform, shopware/core
Authenticated server-side request forgery in file upload via URL.
shopware/platform/ shopware/core
Authenticated server-side request forgery in file upload via URL.
org.jsoup:jsoup
Uncaught Exception in jsoup
ced
Improper Handling of Unexpected Data Type in ced
ckeditor4
Fake objects feature vulnerability allowing to execute JavaScript code using malformed HTML.
ckeditor4
Fake objects feature vulnerability allowing to execute JavaScript code using malformed HTML.
pimcore/pimcore
CKEditor 4 vulnerabilities in versions <4.16.1
pimcore/pimcore
CKEditor 4 vulnerabilities in versions <4.16.1
parse-server
parse-server new anonymous user session acts as if it's created with password
parse-server
parse-server new anonymous user session acts as if it's created with password
github.com/argoproj/argo-workflows/v3, github.com/argoproj/argo-workflows/v3
Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client`
github.com/argoproj/argo-workflows/v3/ github.com/argoproj/argo-workflows/v3
Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client`
github.com/argoproj/argo-workflows/v3, github.com/argoproj/argo-workflows/v3
Argo Server TLS requests could be forged by attacker with network access
github.com/argoproj/argo-workflows/v3/ github.com/argoproj/argo-workflows/v3
Argo Server TLS requests could be forged by attacker with network access
contao/core-bundle, contao/core-bundle, contao/core-bundle, contao/contao, contao/contao, contao/contao
Privilege escalation via form generator
contao/core-bundle/ contao/core-bundle/ contao/core-bundle/ contao/contao/ contao/contao/ contao/contao
Privilege escalation via form generator
contao/core-bundle, contao/core-bundle, contao/core-bundle, contao/contao, contao/contao, contao/contao
PHP file inclusion via insert tags
contao/core-bundle/ contao/core-bundle/ contao/core-bundle/ contao/contao/ contao/contao/ contao/contao
PHP file inclusion via insert tags
ckeditor4
Clipboard feature vulnerability allowing to inject arbitrary HTML into the editor using paste functionality
ckeditor4
Clipboard feature vulnerability allowing to inject arbitrary HTML into the editor using paste functionality
ckeditor4
Widget feature vulnerability allowing to execute JavaScript code using undo functionality
ckeditor4
Widget feature vulnerability allowing to execute JavaScript code using undo functionality
notebook, notebook
Special Element Injection in notebook
jupyterlab, jupyterlab, jupyterlab, jupyterlab, jupyterlab, notebook, notebook
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
jupyterlab/ jupyterlab/ jupyterlab/ jupyterlab/ jupyterlab/ notebook/ notebook
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
libxstream-java, libxstream-java, libxstream-java
libxstream-java, libxstream-java, libxstream-java
libxstream-java, libxstream-java, libxstream-java
libxstream-java, libxstream-java
libxstream-java, libxstream-java
libxstream-java, libxstream-java
libxstream-java, libxstream-java, libxstream-java
libxstream-java, libxstream-java, libxstream-java
