Browse Security Advisories
Security Advisories
High
15 minutes ago
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
pypi
flyto-core
High
16 minutes ago
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
pypi
flyto-core
Critical
16 minutes ago
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
pypi
flyto-core
High
16 minutes ago
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
pypi
flyto-core
High
17 minutes ago
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
pypi
flyto-core
Critical
17 minutes ago
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
pypi
flyto-core
Moderate
17 minutes ago
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
pypi
linuxfabrik-lib
High
20 minutes ago
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
rubygems
mcp
Moderate
20 minutes ago
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
rubygems
mcp
Moderate
22 minutes ago
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
rubygems
mcp
Moderate
22 minutes ago
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
rubygems
mcp
Moderate
32 minutes ago
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
go
github.com/OliveTin/OliveTin
Moderate
38 minutes ago
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
go
github.com/OliveTin/OliveTin
High
39 minutes ago
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
go
github.com/OliveTin/OliveTin
Moderate
about 22 hours ago
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
maven
io.opentelemetry.javaagent:opentelemetry-javaagent
Moderate
about 22 hours ago
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
maven
io.opentelemetry.javaagent:opentelemetry-javaagent
Low
about 22 hours ago
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
rubygems
activerecord-tenanted
High
about 22 hours ago
netfoil: Incorrect block responses could lead to localhost traffic
go
github.com/tinfoil-factory/netfoil
Critical
about 22 hours ago
Logging operator has Fluentd configuration injection that allows remote code execution
go
github.com/kube-logging/logging-operator
High
about 22 hours ago
ZITADEL Users Can Self-Verify Email/Phone via API
go
github.com/zitadel/zitadel
High
about 22 hours ago
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
pypi
proot-distro
High
about 23 hours ago
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
pypi
proot-distro
Low
about 23 hours ago
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
packagist
alextselegidis/easyappointments
Low
about 23 hours ago
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
packagist
alextselegidis/easyappointments
Moderate
about 23 hours ago
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
packagist
alextselegidis/easyappointments
Low
about 23 hours ago
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
packagist
alextselegidis/easyappointments
Low
about 23 hours ago
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
packagist
alextselegidis/easyappointments
High
about 23 hours ago
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
packagist
alextselegidis/easyappointments
Moderate
about 23 hours ago
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
pypi
matrix-commander
High
about 23 hours ago
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
npm
@aws/agentcore
Critical
about 23 hours ago
prebid-server's request forgery vulnerability allows for possible host environment data extraction
go
github.com/prebid/prebid-server, github.com/prebid/prebid-server/v2, github.com/prebid/prebid-server/v3, github.com/prebid/prebid-server/v4
High
about 23 hours ago
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
maven
io.quarkus:quarkus-vertx-http
Low
about 23 hours ago
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
npm
@dynatrace-oss/dynatrace-mcp-server
Moderate
about 23 hours ago
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
pypi
penelope-shell-handler
Moderate
about 24 hours ago
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
hex
req
High
about 24 hours ago
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
hex
req
Moderate
about 24 hours ago
veraPDF Parser DoS via PostScript Type 1 Font Programs
maven
org.verapdf:parser
Moderate
about 24 hours ago
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
maven
org.verapdf:validation-model-jakarta, org.verapdf:validation-model
High
about 24 hours ago
veraPDF Validation XXE via Rich Text
maven
org.verapdf:validation-model-jakarta, org.verapdf:validation-model
High
about 24 hours ago
veraPDF Validation XXE via XFA
maven
org.verapdf:validation-model-jakarta, org.verapdf:validation-model
High
1 day ago
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
npm
swagger-typescript-api
High
1 day ago
swagger-typescript-api vulnerable to code injection via unescaped enum string values
npm
swagger-typescript-api
High
1 day ago
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
npm
swagger-typescript-api
Moderate
1 day ago
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
npm
swagger-typescript-api
High
1 day ago
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
npm
swagger-typescript-api
High
1 day ago
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
npm
swagger-typescript-api
Moderate
1 day ago
goshs has ACL Bypass & Path Traversal
go
goshs.de/goshs, github.com/patrickhener/goshs, goshs.de/goshs/v2, github.com/patrickhener/goshs/v2
Moderate
1 day ago
Pagy I18n locale option is not validated before being used in a file path
rubygems
pagy
Moderate
1 day ago
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
cargo
skilo
High
1 day ago
Style Dictionary - Prototype Pollution in convertTokenData utility function
npm
style-dictionary
High
1 day ago
openhole-server vulnerable to path traversal via URL-decoded request path
go
github.com/bablilayoub/openhole
Critical
1 day ago
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
npm
@hypequery/clickhouse
High
1 day ago
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
go
github.com/gotd/td
Moderate
1 day ago
goshs has a Path Traversal issue
go
github.com/patrickhener/goshs/v2, goshs.de/goshs/v2, github.com/patrickhener/goshs, goshs.de/goshs
Critical
1 day ago
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
go
github.com/patrickhener/goshs, goshs.de/goshs, github.com/patrickhener/goshs/v2, goshs.de/goshs/v2
High
1 day ago
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
go
goshs.de/goshs/v2, goshs.de/goshs, github.com/patrickhener/goshs/v2, github.com/patrickhener/goshs
Critical
1 day ago
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
go
goshs.de/goshs/v2, github.com/patrickhener/goshs/v2
High
1 day ago
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
pypi
datamodel-code-generator
High
1 day ago
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
pypi
datamodel-code-generator
High
1 day ago
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
pypi
datamodel-code-generator
High
1 day ago
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
pypi
datamodel-code-generator
High
1 day ago
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
pypi
datamodel-code-generator
High
1 day ago
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
pypi
datamodel-code-generator
High
1 day ago
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
pypi
datamodel-code-generator
High
1 day ago
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
pypi
datamodel-code-generator
High
1 day ago
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
pypi
datamodel-code-generator
Low
1 day ago
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
pypi
datamodel-code-generator
High
1 day ago
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
pypi
datamodel-code-generator
High
1 day ago
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
pypi
datamodel-code-generator
High
2 days ago
Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability
nuget
System.Security.Cryptography.Xml
Moderate
2 days ago
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
npm
@nocobase/plugin-collection-sql
Moderate
2 days ago
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
go
github.com/azukaar/cosmos-server
Moderate
2 days ago
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
go
github.com/azukaar/cosmos-server
Low
2 days ago
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
go
github.com/fission/fission
High
2 days ago
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory
go
github.com/fission/fission
Moderate
2 days ago
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks
go
github.com/fission/fission
High
2 days ago
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
go
github.com/fission/fission
High
2 days ago
SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)
nuget
SIPSorcery
Critical
2 days ago
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
packagist
poweradmin/poweradmin
High
2 days ago
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
npm, pypi, maven
qti-neon, com.quietterminal:qti-neon
High
2 days ago
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
rubygems
oauth2
High
2 days ago
OAuth: Cross-origin token-request redirects can expose signed request metadata
rubygems
oauth
Low
2 days ago
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
rubygems
sqlite3, sqlite3-ruby
Low
2 days ago
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
rubygems
sqlite3, sqlite3-ruby
Moderate
2 days ago
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
go
github.com/gopacket/gopacket
Moderate
2 days ago
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
go
github.com/gopacket/gopacket
Moderate
2 days ago
nono-cli'scregistry pack verification can fail open when provenance metadata is absent
cargo
nono-cli
High
2 days ago
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
go, packagist
github.com/pterodactyl/wings, pterodactyl/panel
Moderate
2 days ago
@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
npm
@novu/application-generic
High
2 days ago
Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
packagist
pterodactyl/panel
High
2 days ago
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
maven
com.cedarpolicy:cedar-java
High
2 days ago
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
go
github.com/github/github-mcp-server
Critical
2 days ago
lettre has TLS hostname verification disabled when using Boring TLS backend
cargo
lettre
Filter by Severity
Filter by Source
Filter by Ecosystem
maven
7,903
npm
7,174
packagist
6,743
pypi
6,660
go
5,041
nuget
4,374
cargo
1,586
rubygems
1,086
cpan
960
hex
204
actions
57
swift
52
pub
10
Filter by Package
openclaw
591
moodle/moodle
437
tensorflow
430
tensorflow-cpu
407
tensorflow-gpu
400
magento/community-edition
323
org.jenkins-ci.main:jenkins-core
252
Microsoft.ChakraCore
247
github.com/mattermost/mattermost/server/v8
198
github.com/mattermost/mattermost-server
178
typo3/cms
163
Magick.NET-Q16-HDRI-AnyCPU
162
Magick.NET-Q16-AnyCPU
162
com.liferay.portal:release.portal.bom
159
magento/project-community-edition
157
Magick.NET-Q16-HDRI-OpenMP-arm64
155
Magick.NET-Q16-HDRI-x86
154
Magick.NET-Q16-HDRI-x64
152
Magick.NET-Q16-OpenMP-arm64
150
Magick.NET-Q16-HDRI-arm64
148
org.apache.tomcat:tomcat
147
Magick.NET-Q16-OpenMP-x64
145
wwbn/avideo
144
Magick.NET-Q16-arm64
143
Magick.NET-Q8-AnyCPU
141
Magick.NET-Q16-x86
141
n8n
139
Magick.NET-Q8-x86
136
Magick.NET-Q8-OpenMP-arm64
135
Magick.NET-Q16-x64
135
Magick.NET-Q8-arm64
134
pimcore/pimcore
132
Magick.NET-Q8-OpenMP-x64
131
open-webui
130
apache-airflow
127
dolibarr/dolibarr
126
Magick.NET-Q8-x64
126
Django
123
typo3/cms-core
120
concrete5/concrete5
120
com.liferay.portal:release.dxp.bom
118
parse-server
116
craftcms/cms
116
drupal/core
107
phpmyadmin/phpmyadmin
107
thorsten/phpmyfaq
105
microweber/microweber
105
librenms/librenms
100
org.keycloak:keycloak-services
97
code.gitea.io/gitea
94
silverstripe/framework
91
symfony/symfony
89
Magick.NET-Q16-HDRI-OpenMP-x64
88
flowise
86
com.fasterxml.jackson.core:jackson-databind
79
mlflow
78
github.com/usememos/memos
75
gogs.io/gogs
75
mantisbt/mantisbt
74
shopware/platform
74
drupal/drupal
73
Plone
71
getgrav/grav
69
salt
67
apache-superset
66
ansible
65
next
64
shopware/core
64
github.com/grafana/grafana
62
github.com/rancher/rancher
61
Magick.NET-Q16-OpenMP-x86
60
vllm
59
actionpack
59
picklescan
59
directus
58
org.apache.struts:struts2-core
58
github.com/siyuan-note/siyuan/kernel
58
mautic/core
57
snipe/snipe-it
57
org.apache.tomcat.embed:tomcat-embed-core
56
baserproject/basercms
56
nokogiri
56
github.com/hashicorp/vault
55
froxlor/froxlor
55
nocodb
54
surrealdb
52
org.keycloak:keycloak-core
50
admidio/admidio
50
rack
50
nova
49
gradio
49
pyload-ng
48
perl
48
electron
47
getkirby/cms
47
org.xwiki.platform:xwiki-platform-oldcore
46
matrix-synapse
45
github.com/traefik/traefik/v2
44
org.elasticsearch:elasticsearch
44
aiohttp
44
vyper
44
hono
43
vm2
43
axios
43
rdiffweb
43
k8s.io/kubernetes
42
pillow
42
nilsteampassnet/teampass
42
showdoc/showdoc
42
DBD-SQLite
42
phpmyfaq/phpmyfaq
41
intelliants/subrion
41
github.com/filebrowser/filebrowser/v2
41
@budibase/server
40
github.com/traefik/traefik/v3
40
github.com/mattermost/mattermost-server/v6
39
github.com/zitadel/zitadel
39
net.mingsoft:ms-mcms
39
wasmtime
39
io.undertow:undertow-core
39
praisonai
39
keystone
38
github.com/cilium/cilium
37
pypdf
37
MT
37
PraisonAI
37
com.thoughtworks.xstream:xstream
37
statamic/cms
37
github.com/argoproj/argo-cd/v2
36
com.jfinal:jfinal
36
deno
36
DotNetNuke.Core
36
ci4-cms-erp/ci4ms
36
moin
35
org.apache.tomcat:tomcat-catalina
35
github.com/hashicorp/nomad
34
shopware/shopware
34
org.jenkins-ci.plugins:script-security
34
github.com/answerdev/answer
34
Pillow
33
kimai/kimai
33
code.vikunja.io/api
33
praisonaiagents
33
zendframework/zendframework1
32
langflow
32
github.com/hashicorp/consul
32
django
32
github.com/argoproj/argo-cd
32
github.com/docker/docker
32
org.opencms:opencms-core
31
opencv-python
31
opencv-contrib-python
31
contao/core-bundle
31
org.apache.solr:solr-core
31
prestashop/prestashop
31
yeswiki/yeswiki
31
pocketmine/pocketmine-mp
30
org.springframework.security:spring-security-core
30
undici
30
org.eclipse.jetty:jetty-server
29
litellm
29
@anthropic-ai/claude-code
28
phpoffice/phpspreadsheet
28
mediawiki/core
28
pnpm
28
github.com/nats-io/nats-server/v2
27
plone
27
centreon/centreon
27
zebrad
27
github.com/fleetdm/fleet/v4
27
dompurify
27
github.com/openbao/openbao
26
org.apache.tomcat:tomcat-coyote
26
facturascripts/facturascripts
26
github.com/ethereum/go-ethereum
26
funadmin/funadmin
26
golang.org/x/crypto
26
pgadmin4
26
github.com/openfga/openfga
26
github.com/coder/coder/v2
26
cockpit-hq/cockpit
26
org.keycloak:keycloak-parent
26
openmage/magento-lts
26
openssl-src
25
astro
25
laravel/framework
25
org.apache.openmeetings:openmeetings-parent
25
grumpydictator/firefly-iii
25
rubygems-update
25
ghost
25
Microsoft.NetCore.App.Runtime.win-arm
24
Microsoft.NetCore.App.Runtime.win-x64
24
github.com/traefik/traefik
24
twig/twig
24
typo3/cms-backend
24
Microsoft.NetCore.App.Runtime.win-arm64
24
openbabel
24
Microsoft.NetCore.App.Runtime.win-x86
24
github.com/goharbor/harbor
23
simplesamlphp/simplesamlphp
23
Filter by Repository
https://github.com/tensorflow/tensorflow
433
https://github.com/moodle/moodle
250
https://github.com/xwiki/xwiki-platform
222
https://github.com/chakra-core/ChakraCore
214
https://github.com/jenkinsci/jenkins
178
https://github.com/liferay/liferay-portal
170
https://github.com/django/django
121
https://github.com/apache/tomcat
118
https://github.com/jquery/jquery
118
https://github.com/pimcore/pimcore
116
https://github.com/apache/airflow
105
https://github.com/TYPO3/typo3
93
https://github.com/keycloak/keycloak
90
https://github.com/microweber/microweber
90
https://github.com/librenms/librenms
77
https://github.com/FasterXML/jackson-databind
70
https://github.com/rails/rails
70
https://github.com/thorsten/phpmyfaq
69
https://github.com/silverstripe/silverstripe-framework
68
https://github.com/usememos/memos
68
https://github.com/kubernetes/kubernetes
66
https://github.com/symfony/symfony
64
https://github.com/Dolibarr/dolibarr
60
https://github.com/ansible/ansible
59
https://github.com/mattermost/mattermost
59
https://github.com/python-pillow/Pillow
52
https://github.com/spring-projects/spring-framework
51
https://github.com/argoproj/argo-cd
50
https://github.com/grafana/grafana
47
https://github.com/apache/struts
47
https://github.com/rancher/rancher
46
https://github.com/mautic/mautic
46
https://github.com/phpmyadmin/phpmyadmin
45
https://github.com/vyperlang/vyper
44
https://github.com/concretecms/concretecms
44
https://github.com/saltstack/salt
42
https://github.com/shopware/platform
42
https://github.com/mantisbt/mantisbt
42
https://github.com/ikus060/rdiffweb
42
https://github.com/directus/directus
41
https://github.com/craftcms/cms
41
https://github.com/shopware/shopware
40
https://github.com/mmaitre314/picklescan
39
https://github.com/star7th/showdoc
39
https://github.com/gradio-app/gradio
38
https://github.com/magento/magento2
38
https://github.com/dotnet/runtime
38
https://github.com/openstack/nova
38
https://github.com/x-stream/xstream
37
https://github.com/plone/Products.CMFPlone
37
https://github.com/erlang/otp
37
https://github.com/octobercms/october
36
https://github.com/mlflow/mlflow
36
https://github.com/umbraco/Umbraco-CMS
35
https://github.com/sparklemotion/nokogiri
35
https://github.com/parse-community/parse-server
34
https://github.com/answerdev/answer
34
https://github.com/apache/activemq
34
https://github.com/matrix-org/synapse
32
https://github.com/opencv/opencv
32
https://github.com/go-gitea/gitea
32
https://github.com/apache/inlong
31
https://github.com/cilium/cilium
31
https://github.com/PaddlePaddle/Paddle
31
https://github.com/snipe/snipe-it
30
https://github.com/contao/contao
30
https://github.com/rack/rack
29
https://github.com/CVEProject/cvelist
28
https://github.com/strapi/strapi
28
https://github.com/FlowiseAI/Flowise
28
https://github.com/electron/electron
28
https://github.com/openstack/keystone
28
https://github.com/gogs/gogs
28
https://github.com/netty/netty
27
https://github.com/Perl/perl5
26
https://github.com/github/advisory-database
26
https://github.com/baserproject/basercms
26
https://github.com/geoserver/geoserver
26
https://github.com/apache/nifi
26
https://github.com/zitadel/zitadel
26
https://github.com/froxlor/froxlor
26
https://github.com/pmmp/PocketMine-MP
25
https://github.com/surrealdb/surrealdb
25
https://github.com/bcgit/bc-java
25
https://github.com/denoland/deno
25
https://github.com/vercel/next.js
25
https://github.com/vllm-project/vllm
25
https://github.com/langchain-ai/langchain
25
https://github.com/traefik/traefik
25
https://github.com/pyload/pyload
24
https://github.com/apache/cxf
24
https://github.com/getgrav/grav
24
https://github.com/hashicorp/consul
24
https://github.com/run-llama/llama_index
24
https://github.com/nilsteampassnet/TeamPass
23
https://github.com/moby/moby
23
https://github.com/TYPO3/TYPO3.CMS
23
https://github.com/livehelperchat/livehelperchat
23
https://github.com/dnnsoftware/Dnn.Platform
23
https://github.com/bytecodealliance/wasmtime
23
https://github.com/PrestaShop/PrestaShop
23
https://github.com/firefly-iii/firefly-iii
23
https://github.com/eclipse/jetty.project
23
https://github.com/nervosnetwork/ckb
22
https://github.com/helm/helm
22
https://github.com/PHPOffice/PhpSpreadsheet
22
https://github.com/jenkinsci/script-security-plugin
22
https://github.com/getkirby/kirby
22
https://github.com/OpenZeppelin/openzeppelin-contracts
21
https://github.com/hashicorp/vault
21
https://github.com/laravel/framework
21
https://github.com/goharbor/harbor
21
https://github.com/undertow-io/undertow
21
https://github.com/funadmin/funadmin
20
https://github.com/OpenNMS/opennms
20
https://github.com/ethyca/fides
20
https://github.com/opencast/opencast
20
https://github.com/jeecgboot/jeecg-boot
20
https://github.com/cloudfoundry/uaa
19
https://github.com/backstage/backstage
19
https://github.com/alkacon/opencms-core
19
https://github.com/simplesamlphp/simplesamlphp
19
https://github.com/intelliants/subrion
19
https://github.com/containerd/containerd
19
https://github.com/huggingface/transformers
19
https://github.com/nilsteampassnet/teampass
19
https://github.com/TYPO3-CMS/core
19
https://github.com/apache/camel
18
https://github.com/OpenMage/magento-lts
18
https://github.com/rubygems/rubygems
18
https://github.com/opencontainers/runc
18
https://github.com/vaadin/platform
18
https://github.com/mindsdb/mindsdb
17
https://github.com/apache/kylin
17
https://github.com/openfga/openfga
17
https://github.com/vantage6/vantage6
17
https://github.com/liufee/cms
17
https://github.com/ethereum/go-ethereum
17
https://github.com/twbs/bootstrap
16
https://github.com/rusqlite/rusqlite
16
https://github.com/hashicorp/nomad
16
https://github.com/vitejs/vite
16
https://github.com/tinymce/tinymce
16
https://github.com/sequelize/sequelize
16
https://github.com/pyca/cryptography
16
https://github.com/forkcms/forkcms
16
https://github.com/quarkusio/quarkus
16
https://github.com/yetiforcecompany/yetiforcecrm
16
https://github.com/etcd-io/etcd
16
https://github.com/dotnet/aspnetcore
16
https://github.com/MobSF/Mobile-Security-Framework-MobSF
15
https://github.com/sqlite/sqlite
15
https://github.com/PHPMailer/PHPMailer
15
https://github.com/dompdf/dompdf
15
https://github.com/containers/podman
15
https://github.com/decidim/decidim
15
https://github.com/spring-projects/spring-security
15
https://github.com/cobbler/cobbler
15
https://github.com/puppetlabs/puppet
15
https://github.com/centreon/centreon
15
https://github.com/nodejs/undici
15
https://github.com/ckeditor/ckeditor4
15
https://github.com/zendframework/zendframework
15
https://github.com/OPCFoundation/UA-.NETStandard
15
https://github.com/xuxueli/xxl-job
15
https://github.com/thorsten/phpMyFAQ
15
https://github.com/drupal/core
15
https://github.com/aio-libs/aiohttp
15
https://github.com/cockpit-hq/cockpit
14
https://github.com/Graylog2/graylog2-server
14
https://github.com/janeczku/calibre-web
14
https://github.com/publify/publify
14
https://github.com/cosmos/cosmos-sdk
14
https://github.com/apache/superset
14
https://github.com/golang/go
14
https://github.com/ming-soft/MCMS
14
https://github.com/pgadmin-org/pgadmin4
14
https://github.com/ImageMagick/ImageMagick
14
https://github.com/TryGhost/Ghost
14
https://github.com/pimcore/admin-ui-classic-bundle
14
https://github.com/twisted/twisted
14
https://github.com/mojolicious/mojo
14
https://github.com/apache/zeppelin
14
https://github.com/dpgaspar/Flask-AppBuilder
14
https://github.com/rails/rails-html-sanitizer
14
https://github.com/urllib3/urllib3
14
https://github.com/h2oai/h2o-3
13
https://github.com/OctoPrint/OctoPrint
13
https://github.com/laurent22/joplin
13
https://sourceforge.net/projects/sourceforge.net
13
https://github.com/modoboa/modoboa
13
https://github.com/apache/dolphinscheduler
13
https://github.com/dromara/hutool
13
https://github.com/zenml-io/zenml
13
https://github.com/openbao/openbao
13
https://github.com/perl5-dbi/dbi
13
https://github.com/OpenRefine/OpenRefine
13
https://github.com/1Panel-dev/1Panel
13
https://github.com/swagger-api/swagger-ui
13