Open Source Vulnerabilities
projen, projen
Rebuild-bot workflow may allow unauthorised repository modifications
projen/ projen
Rebuild-bot workflow may allow unauthorised repository modifications
nats
Client TLS credentials sent raw to server in npm package nats
nats
Client TLS credentials sent raw to server in npm package nats
org.eclipse.jetty:jetty-deploy, org.eclipse.jetty:jetty-deploy, org.eclipse.jetty:jetty-deploy
Directory exposure in jetty
org.eclipse.jetty:jetty-deploy/ org.eclipse.jetty:jetty-deploy/ org.eclipse.jetty:jetty-deploy
Directory exposure in jetty
org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server
Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resources
org.eclipse.jetty:jetty-server/ org.eclipse.jetty:jetty-server/ org.eclipse.jetty:jetty-server
Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resources
org.eclipse.jetty:jetty-webapp
Authorization Before Parsing and Canonicalization in jetty
org.eclipse.jetty:jetty-webapp
Authorization Before Parsing and Canonicalization in jetty
systeminformation
Command Injection Vulnerability in systeminformation
systeminformation
Command Injection Vulnerability in systeminformation
node-etsy-client
ApiKey secret could be revelated on network issue
node-etsy-client
ApiKey secret could be revelated on network issue
django-registration
Potential sensitive information disclosed in error reports
django-registration
Potential sensitive information disclosed in error reports
@ckeditor/ckeditor5-engine, @ckeditor/ckeditor5-font, @ckeditor/ckeditor5-image, @ckeditor/ckeditor5-list, @ckeditor/ckeditor5-markdown-gfm, @ckeditor/ckeditor5-media-embed, @ckeditor/ckeditor5-paste-from-office, @ckeditor/ckeditor5-widget
Regular expression Denial of Service in multiple packages
@ckeditor/ckeditor5-engine/ @ckeditor/ckeditor5-font/ @ckeditor/ckeditor5-image/ @ckeditor/ckeditor5-list/ @ckeditor/ckeditor5-markdown-gfm/ @ckeditor/ckeditor5-media-embed/ @ckeditor/ckeditor5-paste-from-office/ @ckeditor/ckeditor5-widget
Regular expression Denial of Service in multiple packages
@prisma/sdk
Command injection vulnerability in @prisma/sdk in getPackedPackage function
@prisma/sdk
Command injection vulnerability in @prisma/sdk in getPackedPackage function
portprocesses
Arbitrary Command Injection in portprocesses
prestashop/ps_emailsubscription
Potential XSS injection in the newsletter conditions field
prestashop/ps_emailsubscription
Potential XSS injection in the newsletter conditions field
isolated-vm
Misuse of `Reference` and other transferable APIs may lead to access to nodejs isolate
isolated-vm
Misuse of `Reference` and other transferable APIs may lead to access to nodejs isolate
@thi.ng/egf
[thi.ng/egf] Potential arbitrary code execution of `#gpg`-tagged property values
@thi.ng/egf
[thi.ng/egf] Potential arbitrary code execution of `#gpg`-tagged property values
tech.pegasys.discovery:discovery
Discovery uses the same AES/GCM Nonce throughout the session
tech.pegasys.discovery:discovery
Discovery uses the same AES/GCM Nonce throughout the session
mautic/core
Mautic vulnerable to secret data exfiltration via symfony parameters
mautic/core
Mautic vulnerable to secret data exfiltration via symfony parameters
gssproxy, gssproxy
Security update for gssproxy
gssproxy
Security update for gssproxy
libnet-netmask-perl, libnet-netmask-perl, libnet-netmask-perl
libnet-netmask-perl/ libnet-netmask-perl/ libnet-netmask-perl
libnet-netmask-perl, libnetwork-ipv4addr-perl, libnet-netmask-perl, libnetwork-ipv4addr-perl, libnet-netmask-perl, libnetwork-ipv4addr-perl, libnetwork-ipv4addr-perl, libnetwork-ipv4addr-perl, libnetwork-ipv4addr-perl, libnetwork-ipv4addr-perl
libnet-netmask-perl/ libnetwork-ipv4addr-perl/ libnet-netmask-perl/ libnetwork-ipv4addr-perl/ libnet-netmask-perl/ libnetwork-ipv4addr-perl/ libnetwork-ipv4addr-perl/ libnetwork-ipv4addr-perl/ libnetwork-ipv4addr-perl/ libnetwork-ipv4addr-perl
seafile-client, seafile-client, seafile-client, seafile-client, seafile-client, seafile-client
seafile-client/ seafile-client/ seafile-client/ seafile-client/ seafile-client/ seafile-client
xen, xen, xen
Security update for xen
xen, xen, xen
Security update for xen
php-phpseclib, php-phpseclib, php-phpseclib, php-phpseclib3, php-phpseclib3, php-phpseclib3, phpseclib, phpseclib
php-phpseclib/ php-phpseclib/ php-phpseclib/ php-phpseclib3/ php-phpseclib3/ php-phpseclib3/ phpseclib/ phpseclib
python-django, python-django, python-django
NetworkManager-libnm-devel
NetworkManager bug fix and enhancement update
NetworkManager-libnm-devel
NetworkManager bug fix and enhancement update
kernel-abi-whitelists, kernel-tools-libs-devel
Important: kernel security, bug fix, and enhancement update
kernel-abi-whitelists/ kernel-tools-libs-devel
Important: kernel security, bug fix, and enhancement update
zlib-static
zlib bug fix and enhancement update
file-devel
file bug fix and enhancement update
sanlock-devel
sanlock bug fix and enhancement update
pacemaker, pacemaker-cli, pacemaker-cts, pacemaker-doc, pacemaker-libs-devel, pacemaker-nagios-plugins-metadata, pacemaker-remote
pacemaker bug fix and enhancement update
pacemaker/ pacemaker-cli/ pacemaker-cts/ pacemaker-doc/ pacemaker-libs-devel/ pacemaker-nagios-plugins-metadata/ pacemaker-remote
pacemaker bug fix and enhancement update
