Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories

Loading...
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTc2d3EteHc0aC1mOHdq
activerecord vulnerable to SQL Injection
Ecosystems: rubygems
Packages: activerecord
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWptZ3ctNnZqZy1qandn
actionpack Improper Input Validation vulnerability
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg3N3gtbTVxOC1jMjlo
Rack vulnerable to REDoS
Ecosystems: rubygems
Packages: rack
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWM0M3YtaHJtZy01NnI0
Cocaine Gem OS Command Injection vulnerability
Ecosystems: rubygems
Packages: cocaine
Source: GitHub Advisory Database
Published: about 6 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc4OW0tM3dqdy1oODU3
Puppet vulnerable to Path Traversal
Ecosystems: rubygems
Packages: puppet
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA0NjMtNjM5ci1xOWc5
Dragonfly Code Injection vulnerability
Ecosystems: rubygems
Packages: dragonfly
Source: GitHub Advisory Database
Published: about 6 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXh4dnctNDVycC0zbWoy
Deserialization Code Execution in js-yaml
Ecosystems: npm
Packages: js-yaml
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTloeDktdzJqNi1ydzc2
Script Injection in Show In Browser gem
Ecosystems: rubygems
Packages: show_in_browser
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWY3cDUtdzJjci03Y3A3
Puppet Improper Input Validation vulnerability
Ecosystems: rubygems
Packages: puppet
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXcyNDgteHIzNy1qeDht
fastreader Gem for Ruby URI Handling Arbitrary Command Injection
Ecosystems: rubygems
Packages: fastreader
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWdoMnctajdjeC0yNjY0
Active Record contains SQL Injection
Ecosystems: rubygems
Packages: activerecord
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJmbWYtcng4dy05MzV3
Sounder Contains Arbitrary Command Execution Vulnerability
Ecosystems: rubygems
Packages: sounder
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpnNG0tcTZ3OC12cmpw
rgpg Code Injection vulnerability
Ecosystems: rubygems
Packages: rgpg
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXYycjktYzg0ai12N3ht
RDoc contains XSS vulnerability
Ecosystems: rubygems
Packages: rdoc
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWh4eDYtcDI0di13Zzhj
Curl Gem insufficient URL escaping command injection
Ecosystems: rubygems
Packages: curl
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNqNDMtOWgzdy12OTc2
Puppet allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service
Ecosystems: rubygems
Packages: puppet
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWp4eDgtdjgzdi1yaHcz
Spree Improper Input Validation vulnerability
Ecosystems: rubygems
Packages: spree
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo4MzgtdmZwcS1mbWYy
actionpack Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXc2cmMtcTM4Ny12cGdx
insecure temporary directory usage in passenger
Ecosystems: rubygems
Packages: passenger
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTdnNjUtZ2hyZy1ocGY1
actionpack Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlxajctanZnNC1xcjJ4
Phusion Passenger Denial of Service
Ecosystems: rubygems
Packages: passenger
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWp4aHctbWc4bS0ycGo4
Devise does not properly perform type conversion when performing database queries
Ecosystems: rubygems
Packages: devise
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTdmcWotY2c3OS1mMnB2
Thumbshooter vulnerable to Code Injection
Ecosystems: rubygems
Packages: thumbshooter
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1weGYtZ2N3Mi1wdzVx
actionpack Improper Input Validation vulnerability
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Published: about 6 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTk5Y2gtOG12cC1nN201
md2pdf allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename
Ecosystems: rubygems
Packages: md2pdf
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFyZ2YtanFxbS14N3h2
Code injection in dragonfly gem
Ecosystems: rubygems
Packages: fog-dragonfly, dragonfly
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFxeHAteHA5di12dng2
jquery-ui Tooltip widget vulnerable to XSS
Ecosystems: nuget, maven, rubygems, npm
Packages: jQuery.UI.Combined, org.webjars.npm:jquery-ui, jquery-ui-rails, jquery-ui
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXBjaGMtOTQ5Zi01M201
Improper Input Validation in multi_xml
Ecosystems: rubygems
Packages: multi_xml
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE0NHItZjJobS12NzZ2
Pupper does not properly restrict characters in Common Name field of Certificate Signing Request
Ecosystems: rubygems
Packages: puppet
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE2Y3ctMjU1My03ODM3
newrelic_rpm Gem Discloses Sensitive Information
Ecosystems: rubygems
Packages: newrelic_rpm
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTU3NHEtZnhmai13djZo
Puppet Improper Input Validation vulnerability
Ecosystems: rubygems
Packages: puppet
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTNweGgtaDhody1tajh3
Rack rubygems receiving excessively long lines triggers out-of-memory error
Ecosystems: rubygems
Packages: rack
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTloMzYtNGpmMi1oeDUz
extlib does not properly restrict casts of string values
Ecosystems: rubygems
Packages: extlib
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTNjcnItOXZtZy04NjR2
Active Record Improper Input Validation
Ecosystems: rubygems
Packages: activerecord
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTg1cjctdzVtdi1jODQ5
Rack Vulnerable to Path Traversal
Ecosystems: rubygems
Packages: rack
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTQ5MzYtcmoyNS02d202
nori contains Improper Input Validation
Ecosystems: rubygems
Packages: nori
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE3NTktaHd2Yy1tM2pn
actionpack Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWdyNDQtN2dyYy0zN3Zx
ActiveRecord vulnerable to modification of protected model attributes
Ecosystems: rubygems
Packages: activerecord
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhncjItdjk0bS1yYzln
activesupport in Rails vulnerable to incorrect data conversion
Ecosystems: rubygems
Packages: activesupport
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTY5OW0tbWNqbS05Y3c4
actionpack vulnerable to Cross-site Scripting
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZjOHAtcXBodi02Njh2
Denial of service in ruby-openid
Ecosystems: rubygems
Packages: ruby-openid
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTk4bWYtOGY1Ny02NHFm
actionpack Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg4MzUtNzVody1wajg5
activesupport Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: activesupport
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW03ZnEtY2Y4cS0zNXE3
crack does not properly restrict casts of string values
Ecosystems: rubygems
Packages: crack
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWcyNjYtM2NyaC1oN2dq
ldoce Gem Arbitrary Command Execution
Ecosystems: rubygems
Packages: ldoce
Source: GitHub Advisory Database
Published: about 6 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZoajktY2pqaC0yN3Zt
Active Record contains deserialization of arbitrary YAML
Ecosystems: rubygems
Packages: activerecord
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXIyM2ctM3F3NC1nZmgy
RedCloth Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: redcloth
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA2NzMtaGpmMi1wd2Zy
Shell command injection in command_wrap
Ecosystems: rubygems
Packages: command_wrap
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1neDMtMjdoci1tZmdw
HTTParty does not restrict casts of string values
Ecosystems: rubygems
Packages: httparty
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZnbXgtOGg5My0yNmZo
omniauth-oauth2 Cross-Site Request Forgery vulnerability
Ecosystems: rubygems
Packages: omniauth-oauth2
Source: GitHub Advisory Database
Published: about 6 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThqeGotOXI1Zi13M20y
Puppet allows local users to obtain sensitive configuration information
Ecosystems: rubygems
Packages: puppet
Source: GitHub Advisory Database
Published: about 6 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTc4ajMtN3dwbS1xaHZw
Shell Metacharacter Injection in kelredd-pruview
Ecosystems: rubygems
Packages: kelredd-pruview
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJwcmotZzZ4Yy1wNWdx
Wicked gem contains Path traversal vulnerability
Ecosystems: rubygems
Packages: wicked
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJnNW0tM2ZxcC02cHg4
actionmailer email address processing causes Denial of service
Ecosystems: rubygems
Packages: actionmailer
Source: GitHub Advisory Database
Published: about 6 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW02ZjctNDZody1ncmNq
Creme Fraiche contains OS Command Injection
Ecosystems: rubygems
Packages: cremefraiche
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXI1aGMtOXh4NS05N3J3
i18n gem Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: i18n
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTljMmotNTkzcS0zZzgy
activesupport Improper Input Validation vulnerability
Ecosystems: rubygems
Packages: activesupport
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg0NTctY3c0aC1ocTVm
JSON gem has Improper Input Validation vulnerability
Ecosystems: rubygems
Packages: json
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNmMzYtOTg1Zy12NzNj
omniauth-facebook Cross-Site Request Forgery vulnerability
Ecosystems: rubygems
Packages: omniauth-facebook
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWdwcHAtNXhjNS13ZnB4
Active Record allows bypassing of database-query restrictions
Ecosystems: rubygems
Packages: activerecord
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXc3NTQtZ3E4ci1wZjVm
MiniMagick Gem for Ruby URI Handling Arbitrary Command Injection
Ecosystems: rubygems
Packages: mini_magick
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTMzcHAtMzc2My1tcmZw
sprockets vulnerable to Path Traversal
Ecosystems: rubygems
Packages: sprockets
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXY2MzMteDV2di1ocXdj
Cross-Site Scripting in serve-index
Ecosystems: npm
Packages: serve-index
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTIyOXItcHFwNi04dzZn
sprout Arbitrary Code Execution vulnerability
Ecosystems: rubygems
Packages: sprout
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTdjZ3AtYzNnNy1xdnJ3
actionpack Improper Input Validation vulnerability
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpncWYtaHdjNS1oaDM3
Root Path Disclosure in send
Ecosystems: npm
Packages: send
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTNmeDUtZnd2ci14cmpn
Regular Expression Denial of Service in ms
Ecosystems: npm
Packages: ms
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg1Nm0tdnd4Yy0zcXB3
Directory traversal vulnerability in actionpack
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhycjYtM3BjNC1tNDQ3
Active Record Improper Access Control
Ecosystems: rubygems
Packages: activerecord
Source: GitHub Advisory Database
Published: about 6 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTczcXctd3c2Mi1tNTR4
colorscore Command Injection vulnerability
Ecosystems: rubygems
Packages: colorscore
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXd3NzktOHh3di05MzJ4
rbovirt uses the rest-client gem with SSL verification disabled
Ecosystems: rubygems
Packages: rbovirt
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTloNmctZ3A5NS14M3E1
actionpack is vulnerable to denial of service because of a wildcard controller route
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZ4dnAtNHh3Yy1qcHA2
activesupport Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: activesupport
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhnbXcteDg2NS1oZjl4
Arabic Prawn allows remote attackers to execute arbitrary commands via shell metacharacters
Ecosystems: rubygems
Packages: arabic-prawn
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTI5Z3ItdzU3Zi1ycGZ3
actionpack vulnerable to Path Traversal
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE4NmYtZm1xZi1xcmY2
Mail Gem CRLF Injection vulnerability
Ecosystems: rubygems
Packages: mail
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXdwdzctd3hqbS1jdzhy
actionpack allows bypass of database-query restrictions
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA2NW0tcXI1eC1ycnFx
Webbynode Code Injection vulnerability
Ecosystems: rubygems
Packages: webbynode
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXh3cjMtZm1nai1tbWZy
Exposure of Sensitive Information in bio-basespace-sdk
Ecosystems: rubygems
Packages: bio-basespace-sdk
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTR3aGMtcHA0eC05cGYz
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Ecosystems: rubygems
Packages: jquery-ujs, jquery-rails
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlyZjUtam02Zi0yZm1t
Active Record subject to strong parameters protection bypass
Ecosystems: rubygems
Packages: activerecord
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXI4ZmgtaHEycC03cWhx
Active Record contains SQL Injection via improper range quoting
Ecosystems: rubygems
Packages: activerecord
Source: GitHub Advisory Database
Published: about 6 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA2OTItN21tMy0zZnhn
actionpack is vulnerable to remote bypass authentication
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Published: about 6 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE1cHEtcGdydi1maDg5
dns-sync command injection vulnerability
Ecosystems: npm
Packages: dns-sync
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZoNXEtOTZocC05amdt
actionpack vulnerable to Cross-site Scripting
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg2ZmctZjQ1bS1qZjVx
Regular Expression Denial of Service in semver
Ecosystems: npm
Packages: semver
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTk5NTktYzZxNi02cXAz
Moderate severity vulnerability that affects validator
Ecosystems: npm
Packages: validator
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXYzcnItY3BoOS0yZzJx
rack-ssl Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: rack-ssl
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJncjQtOWpoNS1qNGo2
Rack vulnerable to Denial of Service via large parameter depth request
Ecosystems: rubygems
Packages: rack
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTg0ZnEtNjYyNi13NWZn
CORS Token Disclosure in crumb
Ecosystems: npm
Packages: crumb
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXczN2MtcTY1My1xZzk1
actionpack Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZ4ODUtajVqMi0yN2p4
actionpack Path Traversal vulnerability
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1od3AtcWhwYy1oM2pt
SQL Injection in Active Record
Ecosystems: rubygems
Packages: activerecord
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTU3MjYtZzZyOS01ZjIy
Potential for Script Injection in syntax-error
Ecosystems: npm
Packages: syntax-error
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpqdjctcXB4My1oNjJx
Denial-of-Service Memory Exhaustion in qs
Ecosystems: npm
Packages: qs
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWM5YzUtOWZwci1tODgy
sentry-raven allows remote attackers to cause a denial of service via a large exponent value in a scientific number
Ecosystems: rubygems
Packages: sentry-raven
Source: GitHub Advisory Database
Published: about 6 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW14OWYtdzhxcS1xNWpm
rest-client allows local users to obtain sensitive information by reading the log
Ecosystems: rubygems
Packages: rest-client
Source: GitHub Advisory Database
Published: about 6 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNxcjctNzhwai0zZzdq
File Descriptor Leak Can Cause DoS Vulnerability in hapi
Ecosystems: npm
Packages: hapi
Source: GitHub Advisory Database
Published: about 6 years ago
Low
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTk1OWotNWc5di0zZnBx
Paratrooper-newrelic Exposes of Sensitive Information to an Unauthorized Actor
Ecosystems: rubygems
Packages: paratrooper-newrelic
Source: GitHub Advisory Database
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZ4cDQtMjVxcC04NnFo
Moderate severity vulnerability that affects ember
Ecosystems: npm
Packages: ember
Source: GitHub Advisory Database
Published: about 6 years ago
Filter by Package
tensorflow 433 tensorflow-cpu 387 tensorflow-gpu 384 Microsoft.ChakraCore 247 org.jenkins-ci.main:jenkins-core 170 pimcore/pimcore 118 moodle/moodle 116 magento/community-edition 113 org.apache.tomcat:tomcat 106 microweber/microweber 86 django 78 com.fasterxml.jackson.core:jackson-databind 70 thorsten/phpmyfaq 68 apache-airflow 65 actionpack 63 github.com/usememos/memos 59 dolibarr/dolibarr 53 ansible 53 typo3/cms-core 50 librenms/librenms 48 org.apache.struts:struts2-core 48 org.keycloak:keycloak-core 45 shopware/platform 43 phpmyadmin/phpmyadmin 43 rdiffweb 42 showdoc/showdoc 40 Pillow 40 nokogiri 40 baserproject/basercms 39 concrete5/concrete5 39 com.thoughtworks.xstream:xstream 37 symfony/symfony 37 plone 36 github.com/answerdev/answer 34 matrix-synapse 34 craftcms/cms 34 typo3/cms 33 snipe/snipe-it 32 shopware/core 32 Plone 32 net.mingsoft:ms-mcms 32 apache-superset 32 opencv-contrib-python 30 opencv-python 30 k8s.io/kubernetes 30 org.elasticsearch:elasticsearch 29 org.xwiki.platform:xwiki-platform-oldcore 29 intelliants/subrion 29 com.liferay.portal:release.portal.bom 27 froxlor/froxlor 27 parse-server 27 io.undertow:undertow-core 26 shopware/shopware 26 openssl-src 26 electron 25 rubygems-update 25 org.keycloak:keycloak-parent 25 github.com/argoproj/argo-cd 25 gogs.io/gogs 25 github.com/mattermost/mattermost-server/v6 24 activerecord 24 vyper 23 org.springframework:spring-core 23 github.com/hashicorp/nomad 22 prestashop/prestashop 22 org.jenkins-ci.plugins:script-security 22 github.com/hashicorp/consul 22 org.apache.nifi:nifi 22 org.eclipse.jetty:jetty-server 22 org.apache.tomcat.embed:tomcat-embed-core 22 silverstripe/framework 22 remdex/livehelperchat 22 nilsteampassnet/teampass 22 github.com/hashicorp/vault 21 org.apache.openmeetings:openmeetings-parent 21 org.apache.solr:solr-core 21 centreon/centreon 21 pocketmine/pocketmine-mp 21 org.springframework.security:spring-security-core 21 grumpydictator/firefly-iii 20 drupal/core 20 rack 20 @openzeppelin/contracts-upgradeable 19 DotNetNuke.Core 19 github.com/ethereum/go-ethereum 19 tribalsystems/zenario 18 mautic/core 18 getkirby/cms 18 @openzeppelin/contracts 18 github.com/rancher/rancher 18 org.apache.activemq:activemq-client 18 com.vaadin:vaadin-bom 18 org.xwiki.platform:xwiki-platform-web-templates 17 org.bouncycastle:bcprov-jdk14 17 org.apache.geode:geode-core 17 sequelize 17 cakephp/cakephp 17 getgrav/grav 17 marked 16 Django 16 golang.org/x/net 16 Microsoft.AspNetCore.App.Runtime.win-x64 16 Microsoft.AspNetCore.App.Runtime.win-x86 16 yetiforce/yetiforce-crm 16 cockpit-hq/cockpit 16 francoisjacquet/rosariosis 16 puppet 16 github.com/grafana/grafana 16 rusqlite 16 github.com/argoproj/argo-cd/v2 15 langchain 15 org.bouncycastle:bcprov-jdk15 15 Microsoft.AspNetCore.App.Runtime.win-arm 15 org.apache.jspwiki:jspwiki-main 15 forkcms/forkcms 15 activesupport 15 github.com/goharbor/harbor 15 helm.sh/helm/v3 15 publify_core 14 wasmtime 14 github.com/docker/docker 14 github.com/cilium/cilium 14 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 14 Microsoft.AspNetCore.App.Runtime.linux-x64 14 Microsoft.AspNetCore.App.Runtime.osx-x64 14 Microsoft.AspNetCore.App.Runtime.linux-arm 14 Microsoft.AspNetCore.App.Runtime.linux-arm64 14 modoboa 14 swagger-ui 14 org.xwiki.platform:xwiki-platform-web 14 actionview 14 org.keycloak:keycloak-services 14 org.apache.dubbo:dubbo 14 github.com/nats-io/nats-server/v2 14 ezsystems/ezpublish-kernel 13 org.apache.hadoop:hadoop-main 13 notebook 13 Microsoft.AspNetCore.App.Runtime.win-arm64 13 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 13 tinymce 13 passenger 13 handlebars 13 code.gitea.io/gitea 13 openmage/magento-lts 13 next 13 org.apache.cxf:cxf 13 pyftpdlib 13 strapi 13 wallabag/wallabag 13 cobbler 13 nova 13 pillow 13 lavalite/cms 12 onionshare-cli 12 rails-html-sanitizer 12 phpmailer/phpmailer 12 com.vaadin:flow-server 12 ckb 12 impresscms/impresscms 12 vm2 12 directus 12 github.com/containerd/containerd 11 feehi/feehicms 11 contao/core-bundle 11 org.jenkins-ci.plugins:git 11 jquery-rails 11 mlflow 11 feehi/cms 11 org.apache.hadoop:hadoop-common 11 ghost 11 github.com/opencontainers/runc 11 cryptography 11 Microsoft.NETCore.App.Runtime.win-x86 11 Microsoft.NETCore.App.Runtime.win-x64 11 Microsoft.NETCore.App.Runtime.win-arm64 11 fat_free_crm 11 twisted 11 nodebb 11 topthink/framework 11 org.apache.inlong:manager-pojo 11 calibreweb 11 org.jeecgframework.boot:jeecg-boot-parent 11 elefant/cms 11 ckeditor4 11 org.apache.jspwiki:jspwiki-war 11 org.apache.tika:tika-core 11 org.apache.ranger:ranger 11 keystone 11 urllib3 11 github.com/cloudflare/cfrpki 11 org.jenkins-ci.plugins.workflow:workflow-cps 10 github.com/go-gitea/gitea 10 jquery 10 org.apache.camel:camel-core 10 Microsoft.NETCore.App 10 admidio/admidio 10 Microsoft.AspNetCore.All 10 OctoPrint 10 org.apache.inlong:manager-service 10 laravel/framework 10 angular 10 salt 10 org.apache.cxf:cxf-core 10 rails 10 org.jenkins-ci.plugins.workflow:workflow-cps-global-lib 10 october/system 10 smarty/smarty 10 io.netty:netty 10 org.jboss.netty:netty 10 puma 10 silverstripe/cms 10 org.jenkins-ci.plugins:electricflow 9 com.xuxueli:xxl-job 9 github.com/sylabs/singularity 9 org.opennms:opennms 9 ssddanbrown/bookstack 9 ezsystems/ezplatform-kernel 9 funadmin/funadmin 9 org.apache.commons:commons-compress 9 studio-42/elfinder 9 com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer 9 org.igniterealtime.openfire:parent 9 kiwitcms 9 october/cms 9 org.apache.tapestry:tapestry-core 9 opencv-python-headless 9 org.craftercms:crafter-studio 9 opencv-contrib-python-headless 9 sylius/sylius 9 Microsoft.AspNetCore.App.Runtime.linux-musl-arm 9 alextselegidis/easyappointments 9 org.apache.xmlgraphics:batik 9 org.mortbay.jetty:jetty 9 io.jenkins:configuration-as-code 9 pyload-ng 9 next-auth 9 org.opencrx:opencrx-core-models 9 org.apache.hive:hive 9 Microsoft.NetCore.App.Runtime.win-arm64 9 Microsoft.NetCore.App.Runtime.win-x64 9 Microsoft.NetCore.App.Runtime.win-x86 9 Microsoft.NetCore.App.Runtime.win-arm 9 org.webjars.npm:jquery 9 concrete5/core 9 istio.io/istio 9 kevinpapst/kimai2 9 org.apache.james:james-server 9 waitress 9 glance 9 codeigniter4/framework 9 validator 9 ethyca-fides 9 wagtail 9 serve 9 github.com/openfga/openfga 9 org.jenkins-ci.plugins:email-ext 8 Zope 8 org.apache.zeppelin:zeppelin 8 Flask-AppBuilder 8 github.com/mattermost/mattermost/server/v8 8 org.springframework:spring-webmvc 8 github.com/traefik/traefik/v2 8 jQuery 8 org.jeecgframework.boot:jeecg-boot-common 8 systeminformation 8 org.apache.santuario:xmlsec 8 io.jenkins.blueocean:blueocean 8 Microsoft.NETCore.App.Runtime.linux-musl-arm64 8 Microsoft.NETCore.App.Runtime.linux-musl-x64 8 Microsoft.NETCore.App.Runtime.linux-x64 8 Microsoft.NETCore.App.Runtime.linux-arm64 8 Microsoft.NETCore.App.Runtime.linux-arm 8 Microsoft.AspNetCore.App 8 dompdf/dompdf 8 aiohttp 8 url-parse 8 matrix-js-sdk 8 steal 8 deno 8 urijs 8 joplin 8 numpy 8 org.apache.shiro:shiro-core 8 @strapi/strapi 8 github.com/kubeedge/kubeedge 8 npm 8 mysql:mysql-connector-java 8 simplesamlphp/simplesamlphp 8 wwbn/avideo 8 org.apache.tomcat:tomcat-catalina 8 org.apache.pdfbox:pdfbox 8 jquery-ui-rails 8 jQuery.UI.Combined 8 org.webjars.npm:jquery-ui 8 jquery-ui 8 facturascripts/facturascripts 8 october/october 8 org.apache.hive:hive-exec 8 org.yaml:snakeyaml 8 golang.org/x/crypto 8