An open API service providing security vulnerability metadata for many open source software ecosystems.

Browse Security Advisories

Moderate
1 day ago

Opencast still publishes global system account credentials GSA_kwCzR0hTQS1qNjNoLWhtZ3cteDRqN84ABKiM

maven org.opencastproject:opencast-publication-service-oaipmh-remote, org.opencastproject:opencast-kernel, org.opencastproject:opencast-ingest-service-impl, org.opencastproject:opencast-common
High
1 day ago

HAX CMS API Lacks Authorization Checks GSA_kwCzR0hTQS05anI5LThmZjMtbTg5NM4ABKiL

packagist, npm elmsln/haxcms, @haxtheweb/haxcms-nodejs
Critical
2 days ago

Node-SAML SAML Authentication Bypass GSA_kwCzR0hTQS1tODM3LWcyNjgtbW12N84ABKey

npm @node-saml/node-saml, node-saml
High
4 days ago

ImageMagick has XMP profile write that triggers hang due to unbounded loop GSA_kwCzR0hTQS12bWhoLThyeHEtZnA5Z84ABKdQ

nuget Magick.NET-Q16-HDRI-OpenMP-arm64, Magick.NET-Q16-HDRI-OpenMP-x64, Magick.NET-Q16-HDRI-x86, Magick.NET-Q16-HDRI-arm64, Magick.NET-Q16-HDRI-x64, Magick.NET-Q16-OpenMP-x86, Magick.NET-Q16-OpenMP-arm64, Magick.NET-Q16-OpenMP-x64, Magick.NET-Q16-x86, Magick.NET-Q16-arm64, Magick.NET-Q16-x64, Magick.NET-Q8-OpenMP-arm64, Magick.NET-Q8-OpenMP-x64, Magick.NET-Q8-x86, Magick.NET-Q8-arm64, Magick.NET-Q8-x64, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-AnyCPU, Magick.NET-Q8-AnyCPU
Moderate
6 days ago

HAX CMS application pages vulnerable to clickjacking GSA_kwCzR0hTQS01NHZ3LWY0eGYtZjkyas4ABKWO

packagist, npm elmsln/haxcms, @haxtheweb/haxcms-nodejs
Critical
6 days ago

nova-tiptap has Unauthenticated Arbitrary File Upload Vulnerability GSA_kwCzR0hTQS05NmMyLWg2NjctOWZ4cM4ABKWD

packagist manogi/nova-tiptap, marshmallow/nova-tiptap
High
8 days ago

eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall have embedded malicious code GSA_kwCzR0hTQS1mMjloLXB4dngtZjMzNc4ABKTG

npm got-fetch, napi-postinstall, @pkgr/core, synckit, eslint-plugin-prettier, eslint-config-prettier
Moderate
9 days ago

Mattermost Path Traversal vulnerability GSA_kwCzR0hTQS13dncyLTNqaDQtNGMzOc4ABKRq

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
9 days ago

Mattermost has Insufficiently Protected Credentials GSA_kwCzR0hTQS00ZndqLTg1OTUtd3AyNc4ABKRo

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
9 days ago

Mattermost Missing Authentication for Critical Function GSA_kwCzR0hTQS03aDM0LTljaHItNThxaM4ABKRa

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
11 days ago

vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes GSA_kwCzR0hTQS14OHFwLXdxcW0tNTdwaM4ABKPO

npm petite-vue-i18n, @intlify/vue-i18n-core, @intlify/core-base, @intlify/core, vue-i18n
Moderate
11 days ago

Eclipse GlassFish is vulnerable to Reflected XSS attacks through its Administration Console GSA_kwCzR0hTQS12cXJtLTgzZzYtcGZ2NM4ABKND

maven org.glassfish.main.admingui:console-cluster-plugin, org.glassfish.main.admingui:console-common
Critical
13 days ago

XWiki Rendering is vulnerable to RCE attacks when processing nested macros GSA_kwCzR0hTQS0zMm1mLTU3aDItNjR4Oc4ABKHo

maven org.xwiki.rendering:xwiki-rendering-transformation-macro
High
13 days ago

Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build GSA_kwCzR0hTQS00NGMzLTM4aDgtOWZoOc4ABKGw

maven org.apache.jackrabbit:jackrabbit-core, org.apache.jackrabbit:jackrabbit-spi-commons
High
15 days ago

Apache Zeppelin exposes server resources to unauthenticated attackers GSA_kwCzR0hTQS03cGdmLXBweHctODYyNM4ABKE_

maven org.apache.zeppelin:zeppelin-server, org.apache.zeppelin:zeppelin-interpreter

Filter by Severity

Filter by Ecosystem

Filter by Package

tensorflow 433 tensorflow-gpu 427 tensorflow-cpu 423 moodle/moodle 418 magento/community-edition 300 Microsoft.ChakraCore 247 org.jenkins-ci.main:jenkins-core 239 typo3/cms 190 org.apache.tomcat:tomcat 138 pimcore/pimcore 120 dolibarr/dolibarr 116 github.com/mattermost/mattermost/server/v8 115 typo3/cms-core 111 phpmyadmin/phpmyadmin 107 Django 107 drupal/core 103 com.liferay.portal:release.portal.bom 100 magento/project-community-edition 100 microweber/microweber 99 silverstripe/framework 92 com.liferay.portal:release.dxp.bom 91 apache-airflow 85 drupal/drupal 83 librenms/librenms 82 thorsten/phpmyfaq 73 Plone 72 symfony/symfony 69 com.fasterxml.jackson.core:jackson-databind 69 concrete5/concrete5 65 salt 65 github.com/usememos/memos 65 ansible 63 actionpack 61 org.apache.struts:struts2-core 57 shopware/platform 57 apache-superset 57 github.com/grafana/grafana 56 mlflow 53 craftcms/cms 51 org.keycloak:keycloak-core 50 nova 48 baserproject/basercms 47 nokogiri 46 django 46 org.apache.tomcat.embed:tomcat-embed-core 46 shopware/core 45 gradio 44 mautic/core 44 github.com/rancher/rancher 44 vyper 44 matrix-synapse 42 rdiffweb 42 nilsteampassnet/teampass 42 mantisbt/mantisbt 41 org.elasticsearch:elasticsearch 41 showdoc/showdoc 41 plone 41 org.xwiki.platform:xwiki-platform-oldcore 41 k8s.io/kubernetes 41 org.keycloak:keycloak-services 41 froxlor/froxlor 40 github.com/hashicorp/vault 40 intelliants/subrion 39 github.com/mattermost/mattermost-server/v6 39 directus 38 com.thoughtworks.xstream:xstream 37 com.jfinal:jfinal 36 snipe/snipe-it 36 net.mingsoft:ms-mcms 36 moin 35 org.jenkins-ci.plugins:script-security 34 zendframework/zendframework1 34 io.undertow:undertow-core 34 github.com/answerdev/answer 34 parse-server 33 keystone 32 gogs.io/gogs 32 github.com/cilium/cilium 31 opencv-python 31 Pillow 31 github.com/argoproj/argo-cd/v2 31 github.com/argoproj/argo-cd 31 opencv-contrib-python 31 github.com/hashicorp/nomad 31 shopware/shopware 30 getgrav/grav 30 github.com/docker/docker 29 rack 29 github.com/hashicorp/consul 29 github.com/mattermost/mattermost-server 29 electron 28 mediawiki/core 28 org.apache.solr:solr-core 28 centreon/centreon 27 org.opencms:opencms-core 27 pillow 26 org.springframework.security:spring-security-core 26 next 26 openssl-src 26 prestashop/prestashop 26 rubygems-update 25 open-webui 25 org.eclipse.jetty:jetty-server 25 contao/core-bundle 25 github.com/traefik/traefik/v2 24 magento/core 24 getkirby/cms 24 surrealdb 24 org.keycloak:keycloak-parent 24 pocketmine/pocketmine-mp 24 phpoffice/phpexcel 23 puppet 23 simplesamlphp/simplesamlphp 23 vllm 23 grumpydictator/firefly-iii 23 laravel/framework 23 zendframework/zendframework 23 remdex/livehelperchat 23 org.apache.openmeetings:openmeetings-parent 22 tribalsystems/zenario 22 org.bouncycastle:bcprov-jdk14 22 @openzeppelin/contracts-upgradeable 22 Microsoft.AspNetCore.App.Runtime.win-x64 22 DotNetNuke.Core 22 Microsoft.AspNetCore.App.Runtime.win-x86 22 ckb 22 github.com/goharbor/harbor 21 activerecord 21 org.apache.tomcat:tomcat-catalina 21 glance 21 org.apache.nifi:nifi 21 Microsoft.AspNetCore.App.Runtime.win-arm 21 phpoffice/phpspreadsheet 21 github.com/ethereum/go-ethereum 21 @openzeppelin/contracts 21 aim 20 funadmin/funadmin 20 org.cloudfoundry.identity:cloudfoundry-identity-server 20 langchain 20 golang.org/x/net 20 cockpit-hq/cockpit 20 wasmtime 20 code.gitea.io/gitea 20 Microsoft.AspNetCore.App.Runtime.osx-x64 19 Microsoft.AspNetCore.App.Runtime.linux-arm 19 github.com/zitadel/zitadel 19 org.xwiki.platform:xwiki-platform-web-templates 19 Microsoft.AspNetCore.App.Runtime.win-arm64 19 pyload-ng 19 org.apache.tomcat:tomcat-coyote 19 deno 19 Microsoft.AspNetCore.App.Runtime.linux-arm64 19 helm.sh/helm/v3 19 Microsoft.AspNetCore.App.Runtime.linux-x64 19 neutron 19 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 19 mindsdb 18 contao/contao 18 mercurial 18 topthink/framework 18 genix/cms 18 cobbler 18 com.vaadin:vaadin-bom 18 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 18 forkcms/forkcms 18 francoisjacquet/rosariosis 17 org.springframework:spring-core 17 cakephp/cakephp 17 opencart/opencart 17 notebook 17 cryptography 17 ezsystems/ezpublish-kernel 17 typo3/cms-backend 17 OctoPrint 17 openmage/magento-lts 17 org.apache.geode:geode-core 17 org.apache.inlong:manager-pojo 17 symfony/security 17 yetiforce/yetiforce-crm 17 github.com/traefik/traefik/v3 16 org.apache.dubbo:dubbo 16 lollms 16 tinymce 16 phpbb/phpbb 16 ethyca-fides 16 github.com/openfga/openfga 16 org.apache.activemq:activemq-client 16 org.bouncycastle:bcprov-jdk15 16 october/system 16 org.apache.jspwiki:jspwiki-main 16 calibreweb 16 org.apache.ranger:ranger 16 Microsoft.NetCore.App.Runtime.win-x86 16 Microsoft.NetCore.App.Runtime.win-x64 16 rusqlite 16 Microsoft.NetCore.App.Runtime.win-arm64 16 Microsoft.NetCore.App.Runtime.win-arm 16 PaddlePaddle 16 paddlepaddle 16 sequelize 16

Filter by Repository

https://github.com/tensorflow/tensorflow 433 https://github.com/moodle/moodle 243 https://github.com/xwiki/xwiki-platform 215 https://github.com/chakra-core/ChakraCore 214 https://github.com/jenkinsci/jenkins 178 https://github.com/pimcore/pimcore 116 https://github.com/django/django 116 https://github.com/apache/tomcat 112 https://github.com/apache/airflow 104 https://github.com/TYPO3/typo3 94 https://github.com/microweber/microweber 90 https://github.com/keycloak/keycloak 84 https://github.com/librenms/librenms 73 https://github.com/FasterXML/jackson-databind 70 https://github.com/thorsten/phpmyfaq 69 https://github.com/silverstripe/silverstripe-framework 68 https://github.com/rails/rails 68 https://github.com/usememos/memos 65 https://github.com/kubernetes/kubernetes 64 https://github.com/symfony/symfony 64 https://github.com/Dolibarr/dolibarr 60 https://github.com/ansible/ansible 59 https://github.com/python-pillow/Pillow 52 https://github.com/spring-projects/spring-framework 50 https://github.com/liferay/liferay-portal 47 https://github.com/apache/struts 47 https://github.com/grafana/grafana 47 https://github.com/phpmyadmin/phpmyadmin 45 https://github.com/argoproj/argo-cd 45 https://github.com/vyperlang/vyper 44 https://github.com/shopware/platform 43 https://github.com/mautic/mautic 42 https://github.com/ikus060/rdiffweb 42 https://github.com/concretecms/concretecms 42 https://github.com/saltstack/salt 42 https://github.com/directus/directus 40 https://github.com/rancher/rancher 40 https://github.com/craftcms/cms 39 https://github.com/star7th/showdoc 39 https://github.com/magento/magento2 38 https://github.com/mantisbt/mantisbt 38 https://github.com/openstack/nova 38 https://github.com/gradio-app/gradio 38 https://github.com/dotnet/runtime 37 https://github.com/plone/Products.CMFPlone 37 https://github.com/x-stream/xstream 37 https://github.com/octobercms/october 36 https://github.com/mattermost/mattermost 35 https://github.com/sparklemotion/nokogiri 35 https://github.com/mlflow/mlflow 35 https://github.com/umbraco/Umbraco-CMS 34 https://github.com/apache/activemq 34 https://github.com/answerdev/answer 34 https://github.com/shopware/shopware 33 https://github.com/parse-community/parse-server 33 https://github.com/go-gitea/gitea 32 https://github.com/matrix-org/synapse 32 https://github.com/opencv/opencv 32 https://github.com/apache/inlong 31 https://github.com/cilium/cilium 31 https://github.com/PaddlePaddle/Paddle 31 https://github.com/snipe/snipe-it 30 https://github.com/CVEProject/cvelist 28 https://github.com/openstack/keystone 28 https://github.com/gogs/gogs 28 https://github.com/electron/electron 27 https://github.com/github/advisory-database 26 https://github.com/froxlor/froxlor 26 https://github.com/apache/nifi 26 https://github.com/geoserver/geoserver 26 https://github.com/baserproject/basercms 26 https://github.com/contao/contao 26 https://github.com/strapi/strapi 25 https://github.com/getgrav/grav 24 https://github.com/langchain-ai/langchain 24 https://github.com/pmmp/PocketMine-MP 24 https://github.com/traefik/traefik 24 https://github.com/surrealdb/surrealdb 24 https://github.com/apache/cxf 23 https://github.com/eclipse/jetty.project 23 https://github.com/TYPO3/TYPO3.CMS 23 https://github.com/rack/rack 23 https://github.com/livehelperchat/livehelperchat 23 https://github.com/netty/netty 23 https://github.com/firefly-iii/firefly-iii 23 https://github.com/nilsteampassnet/TeamPass 23 https://github.com/PrestaShop/PrestaShop 22 https://github.com/hashicorp/consul 22 https://github.com/zitadel/zitadel 22 https://github.com/bytecodealliance/wasmtime 22 https://github.com/jenkinsci/script-security-plugin 22 https://github.com/getkirby/kirby 22 https://github.com/denoland/deno 22 https://github.com/vercel/next.js 22 https://github.com/nervosnetwork/ckb 22 https://github.com/goharbor/harbor 21 https://github.com/PHPOffice/PhpSpreadsheet 21 https://github.com/OpenZeppelin/openzeppelin-contracts 21 https://github.com/moby/moby 21 https://github.com/laravel/framework 21 https://github.com/run-llama/llama_index 21 https://github.com/OpenNMS/opennms 20 https://github.com/vllm-project/vllm 20 https://github.com/jeecgboot/jeecg-boot 20 https://github.com/undertow-io/undertow 20 https://github.com/funadmin/funadmin 20 https://github.com/helm/helm 20 https://github.com/simplesamlphp/simplesamlphp 20 https://github.com/cloudfoundry/uaa 19 https://github.com/bcgit/bc-java 19 https://github.com/alkacon/opencms-core 19 https://github.com/nilsteampassnet/teampass 19 https://github.com/pyload/pyload 19 https://github.com/backstage/backstage 18 https://github.com/intelliants/subrion 18 https://github.com/hashicorp/vault 18 https://github.com/rubygems/rubygems 18 https://github.com/apache/camel 18 https://github.com/opencast/opencast 18 https://github.com/ethereum/go-ethereum 17 https://github.com/OpenMage/magento-lts 17 https://github.com/vantage6/vantage6 17 https://github.com/vaadin/platform 17 https://github.com/liufee/cms 17 https://github.com/containerd/containerd 17 https://github.com/mindsdb/mindsdb 17 https://github.com/quarkusio/quarkus 16 https://github.com/hashicorp/nomad 16 https://github.com/ethyca/fides 16 https://github.com/rusqlite/rusqlite 16 https://github.com/forkcms/forkcms 16 https://github.com/tinymce/tinymce 16 https://github.com/yetiforcecompany/yetiforcecrm 16 https://github.com/openfga/openfga 16 https://github.com/TYPO3-CMS/core 16 https://github.com/etcd-io/etcd 16 https://github.com/pyca/cryptography 16 https://github.com/sequelize/sequelize 16 https://github.com/ckeditor/ckeditor4 15 https://github.com/aio-libs/aiohttp 15 https://github.com/zendframework/zendframework 15 https://github.com/puppetlabs/puppet 15 https://github.com/dompdf/dompdf 15 https://github.com/OPCFoundation/UA-.NETStandard 15 https://github.com/huggingface/transformers 15 https://github.com/xuxueli/xxl-job 15 https://github.com/centreon/centreon 15 https://github.com/PHPMailer/PHPMailer 15 https://github.com/decidim/decidim 15 https://github.com/cobbler/cobbler 15 https://github.com/dotnet/aspnetcore 15 https://github.com/drupal/core 15 https://github.com/dnnsoftware/Dnn.Platform 15 https://github.com/nodejs/undici 15 https://github.com/pimcore/admin-ui-classic-bundle 14 https://github.com/apache/kylin 14 https://github.com/golang/go 14 https://github.com/Graylog2/graylog2-server 14 https://github.com/twisted/twisted 14 https://github.com/janeczku/calibre-web 14 https://github.com/apache/superset 14 https://github.com/publify/publify 14 https://github.com/thorsten/phpMyFAQ 14 https://github.com/urllib3/urllib3 14 https://github.com/cockpit-hq/cockpit 14 https://github.com/rails/rails-html-sanitizer 14 https://github.com/cosmos/cosmos-sdk 14 https://github.com/OpenRefine/OpenRefine 13 https://github.com/vitejs/vite 13 https://github.com/opencontainers/runc 13 https://github.com/apache/dolphinscheduler 13 https://github.com/FlowiseAI/Flowise 13 https://github.com/MobSF/Mobile-Security-Framework-MobSF 13 https://github.com/ming-soft/MCMS 13 https://github.com/dromara/hutool 13 https://github.com/modoboa/modoboa 13 https://github.com/TryGhost/Ghost 13 https://github.com/swagger-api/swagger-ui 13 https://github.com/dpgaspar/Flask-AppBuilder 13 https://github.com/containers/podman 13 https://github.com/laurent22/joplin 13 https://github.com/pgadmin-org/pgadmin4 13 https://github.com/spring-projects/spring-security 13 https://github.com/openstack/glance 12 https://github.com/wagtail/wagtail 12 https://github.com/NodeBB/NodeBB 12 https://github.com/getsentry/sentry 12 https://github.com/smarty-php/smarty 12 https://github.com/yiisoft/yii2 12 https://github.com/YesWiki/yeswiki 12 https://github.com/1Panel-dev/1Panel 12 https://github.com/nats-io/nats-server 12 https://github.com/DSpace/DSpace 12 https://github.com/centreon/centreon-archived 12 https://github.com/modxcms/revolution 12 https://github.com/puma/puma 12 https://github.com/patriksimek/vm2 12 https://sourceforge.net/projects/phpmyadmin.sourceforge.net 12 https://github.com/zenml-io/zenml 12