Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories
Loading...
Moderate
Ecosystems: maven
Packages: org.apache.myfaces.core:myfaces-impl
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
GSA_kwCzR0hTQS1namZ4LTl3eDMtajZyN84AAQUt
Apache MyFaces Vulnerable to Path TraversalEcosystems: maven
Packages: org.apache.myfaces.core:myfaces-impl
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
High
Ecosystems: go
Packages: github.com/nats-io/nats-server/v2
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 7 months ago
GSA_kwCzR0hTQS1mcjJnLTloam0td3IyM84AA2kD
NATS.io: Adding accounts for just the system account adds auth bypassEcosystems: go
Packages: github.com/nats-io/nats-server/v2
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 7 months ago
Moderate
Ecosystems: pypi
Packages: Plone
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 6 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXBjd20tOGpjMy1xeHZq
Plone Denial of Service vulnerabilityEcosystems: pypi
Packages: Plone
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 6 years ago
Moderate
Ecosystems: pypi
Packages: Plone
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
GSA_kwCzR0hTQS01NnAzLXJycDQtMmo4Ms4AAWK2
Plone Open Redirection vulnerability via next parameterEcosystems: pypi
Packages: Plone
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
Ecosystems: packagist
Packages: cakephp/cakephp
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 1 year ago
GSA_kwCzR0hTQS1qOXEyLWY5cTctamhncc4AAxG9
CakePHP SecurityComponent cross form submission issueEcosystems: packagist
Packages: cakephp/cakephp
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 1 year ago
Moderate
Ecosystems: rubygems
Packages: fat_free_crm
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS05Z2dwLTVyZjQteDdxOc4AAe1h
Fat Free CRM vulnerable to SQL InjectionEcosystems: rubygems
Packages: fat_free_crm
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
High
Ecosystems: packagist
Packages: cakephp/cakephp
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS1nMnZ4LTh2NDctNHZoaM4AAgCu
CakePHP allows remote attackers to modify internal Cake cache and execute arbitrary codeEcosystems: packagist
Packages: cakephp/cakephp
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Moderate
Ecosystems: rubygems
Packages: sup
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS01ZjJwLTZ2anYtMnEybc4AAe3F
Sup Code Injection vulnerabilityEcosystems: rubygems
Packages: sup
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Moderate
Ecosystems: maven
Packages: com.amazonaws:aws-encryption-sdk-java
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 3 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTU1eGgtNTNtNi05MzZy
Improper Verification of Cryptographic Signature in aws-encryption-sdk-javaEcosystems: maven
Packages: com.amazonaws:aws-encryption-sdk-java
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 3 years ago
High
Ecosystems: pypi
Packages: pillow
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 7 months ago
GSA_kwCzR0hTQS01NnB3LW1wajQtZnh3d84AA2QC
Bundled libwebp in Pillow vulnerableEcosystems: pypi
Packages: pillow
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 7 months ago
High
Ecosystems: cargo
Packages: ordnung
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTR3ajMtcDdoai1jdng4
Double free in ordnungEcosystems: cargo
Packages: ordnung
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
Moderate
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
GSA_kwCzR0hTQS02bXgzLTlxZmgtNzdnas4AA5qA
Mattermost denial of service through long emoji valueEcosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
Low
Ecosystems: npm
Packages: marked
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 3 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNoNTItdmdxMi05NDNm
Regular Expression Denial of Service in markedEcosystems: npm
Packages: marked
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 3 years ago
High
Ecosystems: npm
Packages: meshcentral
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 4 months ago
GSA_kwCzR0hTQS13cHh3LTV4Zm0teDIyds4AA47V
MeshCentral algorithm-downgrade issueEcosystems: npm
Packages: meshcentral
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 4 months ago
Moderate
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
GSA_kwCzR0hTQS1od2pmLTQ2NjctZ3F3eM4AA5qF
Mattermost allows attackers access to posts in channels they are not a member ofEcosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
Moderate
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
GSA_kwCzR0hTQS12bTltLTU3anItNHB4aM4AA5qH
Mattermost fails to limit the number of role namesEcosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
Moderate
Ecosystems: packagist
Packages: joomla/application
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
GSA_kwCzR0hTQS1oMjJxLWcyYzctMmp3as2lHg
Joomla! vulnerable to CRLF injectionEcosystems: packagist
Packages: joomla/application
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Critical
Ecosystems: pypi
Packages: DIRAC
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
GSA_kwCzR0hTQS01OXFqLWpjanYtNjYyas4AA5Kb
DIRAC's TokenManager does not check permissions on cached tokensEcosystems: pypi
Packages: DIRAC
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
Critical
Ecosystems: pypi
Packages: TurboGears
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 1 year ago
GSA_kwCzR0hTQS04cTM4LXc1Nm0tcXEyY84AAxa1
Header injection in TurboGearsEcosystems: pypi
Packages: TurboGears
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 1 year ago
High
Ecosystems: nuget
Packages: wix
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
GSA_kwCzR0hTQS03d2gyLXd4YzctOXBoNc4AA5Kc
WiX Toolset's .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privilegesEcosystems: nuget
Packages: wix
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
Moderate
Ecosystems: pypi
Packages: mako
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS03cTh4LTM4bWMtcDg0Zs4AAgJp
Mako contains Cross-site Scripting vulnerabilityEcosystems: pypi
Packages: mako
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Moderate
Ecosystems: maven
Packages: org.bitbucket.b_c:jose4j
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
GSA_kwCzR0hTQS02cXZ3LTI0OWotaDQ0Y84AA5mp
jose4j denial of service via specifically crafted JWEEcosystems: maven
Packages: org.bitbucket.b_c:jose4j
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
Moderate
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
GSA_kwCzR0hTQS1jNTdwLTN2MmctdzlyZ84AATyv
Insertion of Sensitive Information into Log File in Apache TomcatEcosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
Ecosystems: pypi
Packages: django-ajax-utilities
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 1 year ago
GSA_kwCzR0hTQS1wNGc5LWM5cXItd21nNc4AAyBc
Cross-site Scripting in django-ajax-utilitiesEcosystems: pypi
Packages: django-ajax-utilities
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 1 year ago
Low
Ecosystems: npm
Packages: es5-ext
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
GSA_kwCzR0hTQS00Z21qLTNwM2gtZ204aM4AA5gl
es5-ext vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`Ecosystems: npm
Packages: es5-ext
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
Moderate
Ecosystems: pypi
Packages: EVE-SRP
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 1 year ago
GSA_kwCzR0hTQS1meHF4LXhncXEtZ2Y0Ms4AAxbz
Exposure of Sensitive Information in EVE-SRPEcosystems: pypi
Packages: EVE-SRP
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 1 year ago
Moderate
Ecosystems: packagist
Packages: friendsofsymfony1/symfony1
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 months ago
GSA_kwCzR0hTQS1wdjlqLWM1M3EtaDQzM84AA6Oz
Gadget chain in Symfony 1 due to uncontrolled unserialized input in sfNamespacedParameterHolderEcosystems: packagist
Packages: friendsofsymfony1/symfony1
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 months ago
Critical
Ecosystems: packagist
Packages: slub/slub-events
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS01cHd3LTNtZmMtZzh2cs4AAiZr
slub_events for Typo3 Arbitrary File UploadEcosystems: packagist
Packages: slub/slub-events
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Low
Ecosystems: rubygems
Packages: rack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 1 year ago
GSA_kwCzR0hTQS1ycXYyLTI3NXgtMmpxNc4AAxDs
Denial of service via multipart parsing in RackEcosystems: rubygems
Packages: rack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 1 year ago
Moderate
Ecosystems: packagist
Packages: cakephp/cakephp
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
GSA_kwCzR0hTQS1ydzczLXhtcHYtajV4Ms2NbQ
CakePHP directory traversal vulnerability allows remote attackers to read arbitrary filesEcosystems: packagist
Packages: cakephp/cakephp
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
High
Ecosystems: go
Packages: github.com/microsoft/go-crypto-openssl/openssl, github.com/golang-fips/openssl/v2, github.com/microsoft/go-crypto-openssl, github.com/golang-fips/openssl/openssl, github.com/golang-fips/go
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 months ago
GSA_kwCzR0hTQS03OGh4LWdwNmctN21qNs4AA6LJ
Memory leaks in code encrypting and verifying RSA payloadsEcosystems: go
Packages: github.com/microsoft/go-crypto-openssl/openssl, github.com/golang-fips/openssl/v2, github.com/microsoft/go-crypto-openssl, github.com/golang-fips/openssl/openssl, github.com/golang-fips/go
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 months ago
Moderate
Ecosystems: packagist
Packages: shopware/core, shopware/platform
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 3 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWdwbWgtZzk0Zy1xcmhy
Internal hidden fields are visible on to many associations in admin apiEcosystems: packagist
Packages: shopware/core, shopware/platform
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 3 years ago
Moderate
Ecosystems: maven
Packages: org.opensaml:opensaml
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS1xd3dqLXFqM2YtOWh2N84AAfBG
Improper Authentication in OpenSAMLEcosystems: maven
Packages: org.opensaml:opensaml
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Moderate
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
GSA_kwCzR0hTQS05Z2dtLTc4OTcteDRtZ84AATyx
Improper Input Validation in Apache TomcatEcosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Critical
Ecosystems: go
Packages: github.com/jub0bs/fcors
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 12 days ago
GSA_kwCzR0hTQS12ODRoLTY1M3YtNHBxOc4AA7vR
Some CORS middleware allow untrusted originsEcosystems: go
Packages: github.com/jub0bs/fcors
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 12 days ago
Critical
Ecosystems: packagist
Packages: bbpress/bbpress
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS1td3hoLTZqOXYtNDVwaM4AAkzb
bbPress unauthenticated privilege-escalationEcosystems: packagist
Packages: bbpress/bbpress
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
High
Ecosystems: packagist
Packages: joomla/session
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS13d2ZoLTI4aHgtdzJyMs4AAdeo
Joomla! Framework Remote Code Injection VulnerabilityEcosystems: packagist
Packages: joomla/session
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Moderate
Ecosystems: pypi
Packages: nova
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
GSA_kwCzR0hTQS14OHhyLXJtOXItN212Zs4AAU0L
OpenStack Compute (Nova) has Insufficient Verification of Data AuthenticityEcosystems: pypi
Packages: nova
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
High
Ecosystems: packagist
Packages: dompdf/dompdf
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS00OHI5LTR2OTMteDR3aM4AAfr2
DOMPDF Remote File Inclusion VulnerabilityEcosystems: packagist
Packages: dompdf/dompdf
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Moderate
Ecosystems: pypi
Packages: pretix
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
GSA_kwCzR0hTQS02NzJyLTk3cjctdngycc4AA5gJ
pretix mishandles file validationEcosystems: pypi
Packages: pretix
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
Critical
Ecosystems: maven
Packages: org.openapitools:openapi-generator-online
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 3 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTIzeDQtbTg0Mi1mbXdm
Creation of Temporary File in Directory with Insecure Permissions in the OpenAPI-Generator online generatorEcosystems: maven
Packages: org.openapitools:openapi-generator-online
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 3 years ago
Critical
Ecosystems: cargo
Packages: bra
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo4cXEtNThjci04Y2M3
Out of bounds read in braEcosystems: cargo
Packages: bra
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
High
Ecosystems: packagist
Packages: blueimp/jquery-file-upload
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS13eGc2LWY3NzMtZzJmN84AAgWQ
jQuery File Upload Plugin Unrestricted file upload vulnerabilityEcosystems: packagist
Packages: blueimp/jquery-file-upload
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Critical
Ecosystems: pypi
Packages: ipsilon
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
GSA_kwCzR0hTQS0zNzZtLTNybTItOWptNs4AAXrC
Session Fixation in ipsilonEcosystems: pypi
Packages: ipsilon
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
Ecosystems: go
Packages: github.com/cloudflare/cfrpki
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
GSA_kwCzR0hTQS0zcHFoLXA3MmMtZmo4Nc0Xhw
Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpkiEcosystems: go
Packages: github.com/cloudflare/cfrpki
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
Moderate
Ecosystems: go
Packages: github.com/argoproj/argo-workflows
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 3 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJjN3AtZ212aC14Zngy
Attack on Kubernetes via Misconfigured Argo WorkflowsEcosystems: go
Packages: github.com/argoproj/argo-workflows
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 3 years ago
Moderate
Ecosystems: npm
Packages: deepmergefn
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 3 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZqNzItbXdyai1tMnhx
Prototype Pollution in deepmergefnEcosystems: npm
Packages: deepmergefn
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 3 years ago
Low
Ecosystems: npm
Packages: fast-xml-parser
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 11 months ago
GSA_kwCzR0hTQS1ncHY1LTd4M2ctZ2hqds4AAz4I
fast-xml-parser regex vulnerability patch could be improved from a safety perspectiveEcosystems: npm
Packages: fast-xml-parser
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 11 months ago
Low
Ecosystems: pypi
Packages: moin
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS1tOWo3LXhjajctNDJqOc4AAagr
MoinMoin Cross-site Scripting (XSS) vulnerabilityEcosystems: pypi
Packages: moin
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
High
Ecosystems: packagist
Packages: openmage/magento-lts
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhtOWYtdnhteC00bTU4
Data Flow Sanitation Issue FixEcosystems: packagist
Packages: openmage/magento-lts
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
Moderate
Ecosystems: maven
Packages: com.ning:async-http-client
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
GSA_kwCzR0hTQS01YzY2LTZoNmctNnE2bc3zxA
Insufficient Verification of Data Authenticity in Async Http ClientEcosystems: maven
Packages: com.ning:async-http-client
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
Ecosystems: cargo
Packages: rmpv
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1jcmYtN2hmOS1mNnE1
Unchecked vector pre-allocationEcosystems: cargo
Packages: rmpv
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
High
Ecosystems: cargo
Packages: parc
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXh3eGMtajk3ai04NGdm
Race condition in ParcEcosystems: cargo
Packages: parc
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
Moderate
Ecosystems: packagist
Packages: moodle/moodle
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 months ago
GSA_kwCzR0hTQS1mNm1oLTc5dmgtMmh2N84AA6Os
Cross-site Scripting in Moodle ChatEcosystems: packagist
Packages: moodle/moodle
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 months ago
High
Ecosystems: go
Packages: github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v6, github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v5, github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v4
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 7 months ago
GSA_kwCzR0hTQS13NnJwLXZ4ajItZmpocs4AA2us
Cosmos packet-forward-middleware vulnerable to chain-haltEcosystems: go
Packages: github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v6, github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v5, github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v4
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 7 months ago
High
Ecosystems: pypi
Packages: phoenix-ws
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS1jOGY3LXgyZzctN2Z4as4AArT5
Phoenix-ws source code and data in extensions folder is publicly availableEcosystems: pypi
Packages: phoenix-ws
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
High
Ecosystems: pypi
Packages: Plone
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS0zdjI4LTlqanAtNGc1d84AAahz
Plone Privilege Escalation VulnerabilityEcosystems: pypi
Packages: Plone
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Moderate
Ecosystems: pypi
Packages: moin
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS00NTJoLXJ4MjgtNDl3Oc4AAfXk
MoinMoin Cross-site scripting (XSS) vulnerabilityEcosystems: pypi
Packages: moin
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
High
Ecosystems: packagist
Packages: pimcore/pimcore
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS1nN3BqLTN2OTctM3Z4cM4AAems
Pimcore Vulnerable to PHP Object Injection AttacksEcosystems: packagist
Packages: pimcore/pimcore
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
High
Ecosystems: packagist
Packages: flarum/flarum
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS1nNnc1LTQzOW0tamh3ds4AAgjk
Flarum mishandles invalidation of user email tokensEcosystems: packagist
Packages: flarum/flarum
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Critical
Ecosystems: cargo
Packages: adtensor
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJnNG0tZ3d3NS03cDQ3
Free of uninitialized memory in adtensorEcosystems: cargo
Packages: adtensor
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
Moderate
Ecosystems: maven
Packages: com.shopizer:shopizer
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 3 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJjcDQtam0ydi1tcjNm
Cross-site scripting in ShopizerEcosystems: maven
Packages: com.shopizer:shopizer
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 3 years ago
Low
Ecosystems: go
Packages: github.com/cometbft/cometbft
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
GSA_kwCzR0hTQS01NTVwLW00djYtY3F4ds4AA5lr
ASA-2024-004: Default configuration param for Evidence may limit window of validityEcosystems: go
Packages: github.com/cometbft/cometbft
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
Moderate
Ecosystems: maven
Packages: org.apache.syncope:syncope
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
GSA_kwCzR0hTQS1yMnhmLXc1cGotOXB3OM4AAT02
Apache Syncope JEXL Code InjectionEcosystems: maven
Packages: org.apache.syncope:syncope
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
High
Ecosystems: maven
Packages: org.apache.zeppelin:zeppelin
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
GSA_kwCzR0hTQS04N3AyLWN2aHEtcTRtds0VlA
Authentication bypass in Apache ZeppelinEcosystems: maven
Packages: org.apache.zeppelin:zeppelin
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
Moderate
Ecosystems: maven
Packages: org.directwebremoting:dwr
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS1xNXYyLTJ2NjYtNmh3bc4AAd_M
Improper Neutralization of Input During Web Page Generation in Direct Web RemotingEcosystems: maven
Packages: org.directwebremoting:dwr
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
High
Ecosystems: pypi
Packages: trytond
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS1xam1jLXd3bXctY3E5cs4AAe5F
Tryton Directory Traversal vulnerabilityEcosystems: pypi
Packages: trytond
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Low
Ecosystems: npm
Packages: @apollo/server
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 11 months ago
GSA_kwCzR0hTQS02OGpoLXJmNngtODM2Zs4AAz6F
@apollo/server vulnerable to unsafe application of Content Security Policy via reused noncesEcosystems: npm
Packages: @apollo/server
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 11 months ago
Moderate
Ecosystems: cargo
Packages: molecule
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTgyaG0tdmg3Zy1ocmg5
Partial read is incorrect in moleculeEcosystems: cargo
Packages: molecule
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
Critical
Ecosystems: npm
Packages: appium-desktop
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 1 year ago
GSA_kwCzR0hTQS14cTZqLXg4cHEtZzNncs4AAzDz
appium-desktop OS Command Injection vulnerabilityEcosystems: npm
Packages: appium-desktop
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 1 year ago
Low
Ecosystems: npm
Packages: zod
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 8 months ago
GSA_kwCzR0hTQS1tOTVxLTdxcDMteHY0Ms4AA2IO
Zod denial of service vulnerabilityEcosystems: npm
Packages: zod
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 8 months ago
Low
Ecosystems: npm
Packages: @floffah/build
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 3 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpjZ3ItOTY5OC04Mmp4
Improper Neutralization of Special Elements used in a Command ('Command Injection') in @floffah/buildEcosystems: npm
Packages: @floffah/build
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 3 years ago
Moderate
Ecosystems: pypi
Packages: parlai
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
GSA_kwCzR0hTQS1td2dqLTd4N2otNjk2Ns0Vuw
Deserialization of Untrusted Data in ParlAIEcosystems: pypi
Packages: parlai
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
Moderate
Ecosystems: packagist
Packages: typo3/cms
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS05ajhoLXhyZ2otN2d3Ms4AAehP
TYPO3 Improper Session InvalidationEcosystems: packagist
Packages: typo3/cms
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Critical
Ecosystems: npm
Packages: @openzeppelin/contracts-upgradeable
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
GSA_kwCzR0hTQS1xNGg5LTQ2eGctbTN4Oc0Vww
UUPSUpgradeable vulnerability in @openzeppelin/contracts-upgradeableEcosystems: npm
Packages: @openzeppelin/contracts-upgradeable
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
Moderate
Ecosystems: packagist
Packages: symfony/symfony, symfony/security, symfony/routing, symfony/http-foundation
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS04M2MzLXF4MjctMnJ3cs4AAfXs
Symfony Allows URI Restrictions Bypass Via Double-Encoded StringEcosystems: packagist
Packages: symfony/symfony, symfony/security, symfony/routing, symfony/http-foundation
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Low
Ecosystems: packagist
Packages: moodle/moodle
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
GSA_kwCzR0hTQS00cHBnLTJteDYtZnF4Oc30Sg
Moodle allows attackers to bypass intended login restrictionsEcosystems: packagist
Packages: moodle/moodle
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
High
Ecosystems: npm
Packages: cmake
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 5 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTRqNTktaGZ3Ni02dzdo
Downloads Resources over HTTP in cmakeEcosystems: npm
Packages: cmake
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 5 years ago
Low
Ecosystems: npm
Packages: @openzeppelin/contracts-upgradeable, @openzeppelin/contracts
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
GSA_kwCzR0hTQS05dng2LTd4eGYteDk2N84AA5qR
OpenZeppelin Contracts base64 encoding may read from potentially dirty memoryEcosystems: npm
Packages: @openzeppelin/contracts-upgradeable, @openzeppelin/contracts
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
High
Ecosystems: npm
Packages: openframe-image
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 5 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1ncjItM21wdi00M2dj
Downloads Resources over HTTP in openframe-imageEcosystems: npm
Packages: openframe-image
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 5 years ago
Moderate
Ecosystems: go
Packages: github.com/treeverse/lakefs
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 9 months ago
GSA_kwCzR0hTQS05cGhoLXIzN3YtMzR3aM4AA1SQ
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML FilesEcosystems: go
Packages: github.com/treeverse/lakefs
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 9 months ago
Moderate
Ecosystems: packagist
Packages: bbpress/bbpress
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS1wOXhwLXhnaHAtZ3F2cM4AAkyl
bbPress stored Cross-Site Scripting (XSS) vulnerability in the Forum creation sectionEcosystems: packagist
Packages: bbpress/bbpress
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
High
Ecosystems: npm
Packages: htmr
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 3 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWY4cnEtbTI4aC04aHhq
Cross-Site Scripting in htmrEcosystems: npm
Packages: htmr
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 3 years ago
Moderate
Ecosystems: packagist
Packages: moodle/moodle
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
GSA_kwCzR0hTQS1jbTRyLTU4cGotaDJwaM30TQ
Moodle allows attackers to extract archives to arbitrary directoriesEcosystems: packagist
Packages: moodle/moodle
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
High
Ecosystems: npm
Packages: mixme
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
GSA_kwCzR0hTQS04NHA3LWZoOWMtNmc4aM0V0Q
Prototype Pollution in mixmeEcosystems: npm
Packages: mixme
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
Moderate
Ecosystems: go
Packages: github.com/sourcegraph/sourcegraph
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW14NDMtcjk4NS01aDRt
Open redirect vulnerability in SourcegraphEcosystems: go
Packages: github.com/sourcegraph/sourcegraph
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
High
Ecosystems: pypi
Packages: calibreweb
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 1 year ago
GSA_kwCzR0hTQS1taG1wLW02ZzctN2MyNM4AAyzA
Weak Password Requirements in calibrewebEcosystems: pypi
Packages: calibreweb
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 1 year ago
Low
Ecosystems: packagist
Packages: moodle/moodle
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
GSA_kwCzR0hTQS03NWM2LXhxd3ItdjJyOc30bQ
Moodle cross-site scripting (XSS) vulnerabilityEcosystems: packagist
Packages: moodle/moodle
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
Ecosystems: packagist
Packages: ec-cube/ec-cube
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS1jOG14LTQzY3EtOTkzd84AAocK
EC-CUBE Cross-site scripting vulnerabilityEcosystems: packagist
Packages: ec-cube/ec-cube
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Moderate
Ecosystems: npm
Packages: @npmcli/git
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 3 years ago
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWh4d20teDU1My14MzU5
Arbitrary Command Injection due to Improper Command SanitizationEcosystems: npm
Packages: @npmcli/git
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 3 years ago
Moderate
Ecosystems: packagist
Packages: ec-cube/ec-cube
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS12cnB2LTI2Zm0tN3ZmN84AAo-c
EC-CUBE Cross-site scripting vulnerabilityEcosystems: packagist
Packages: ec-cube/ec-cube
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
High
Ecosystems: pypi
Packages: kiwitcms
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 1 year ago
GSA_kwCzR0hTQS1md2NmLTc1M3YtZmdjas4AAy8_
Unrestricted file upload in kiwi TCMSEcosystems: pypi
Packages: kiwitcms
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 1 year ago
Moderate
Ecosystems: packagist
Packages: ec-cube/ec-cube
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS1yNnFxLXFjOW0tOTh3Ms4AAo_T
EC-CUBE Cross-site scripting vulnerabilityEcosystems: packagist
Packages: ec-cube/ec-cube
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Moderate
Ecosystems: maven
Packages: org.apache.activemq:activemq-client
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
GSA_kwCzR0hTQS05Y3ZyLTh4cTQtMm03M84AATvL
Improper Neutralization of Input During Web Page Generation in Apache ActiveMQEcosystems: maven
Packages: org.apache.activemq:activemq-client
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
GSA_kwCzR0hTQS1mN3c3LTZwamMtd3dtNs3Mhg
Apache Tomcat affected by vulnerability in TLS and SSL protocolEcosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
Ecosystems: npm
Packages: millisecond
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
GSA_kwCzR0hTQS1tNDg5LXhyMzUtZmp4cs0V8w
Regular Expression Denial of Service in millisecondEcosystems: npm
Packages: millisecond
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
Moderate
Ecosystems: pypi
Packages: attic
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
GSA_kwCzR0hTQS01eDZxLWZmd2otOHZjZs4AAaay
attic has improper verification of unencrypted backupsEcosystems: pypi
Packages: attic
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Moderate
Ecosystems: packagist
Packages: ec-cube/ec-cube
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
GSA_kwCzR0hTQS1wdzk3LTZ2NzQtOXczcM0ulw
EC-CUBE improperly handles HTTP Host header valuesEcosystems: packagist
Packages: ec-cube/ec-cube
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
Ecosystems: npm
Packages: mongo-express
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
GSA_kwCzR0hTQS1mZmZnLWN3YzkteHZqN84AA5rI
mongo-express Cross-site Request Forgery vulnerabilityEcosystems: npm
Packages: mongo-express
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 3 months ago
Moderate
Ecosystems: npm
Packages: serve-here.js
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
GSA_kwCzR0hTQS00NDQ4LXJjODItZmNyN80V8g
Path Traversal in serve-here.jsEcosystems: npm
Packages: serve-here.js
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
Statistics
Advisories: 18,619
Packages: 8,352
Repositories: 5,059
Ecosystems: 12
Packages: 8,352
Repositories: 5,059
Ecosystems: 12
Filter by Severity
Filter by Ecosystem
Filter by Package
tensorflow
432
tensorflow-cpu
387
tensorflow-gpu
384
moodle/moodle
323
Microsoft.ChakraCore
247
org.jenkins-ci.main:jenkins-core
189
magento/community-edition
183
org.apache.tomcat:tomcat
134
pimcore/pimcore
116
dolibarr/dolibarr
107
typo3/cms
102
phpmyadmin/phpmyadmin
92
microweber/microweber
91
django
80
apache-airflow
78
typo3/cms-core
77
drupal/core
76
thorsten/phpmyfaq
70
com.fasterxml.jackson.core:jackson-databind
69
ansible
63
drupal/drupal
61
github.com/usememos/memos
59
actionpack
57
org.apache.struts:struts2-core
55
librenms/librenms
54
salt
53
symfony/symfony
53
Plone
52
concrete5/concrete5
52
apache-superset
49
shopware/platform
48
org.keycloak:keycloak-core
47
com.liferay.portal:release.portal.bom
45
nova
45
nokogiri
44
github.com/grafana/grafana
44
plone
43
baserproject/basercms
43
rdiffweb
42
Pillow
41
showdoc/showdoc
40
craftcms/cms
40
intelliants/subrion
40
github.com/mattermost/mattermost/server/v8
38
vyper
38
froxlor/froxlor
37
github.com/mattermost/mattermost-server/v6
37
nilsteampassnet/teampass
37
com.thoughtworks.xstream:xstream
36
com.jfinal:jfinal
36
org.apache.tomcat.embed:tomcat-embed-core
36
shopware/core
36
matrix-synapse
35
net.mingsoft:ms-mcms
35
moin
34
github.com/answerdev/answer
34
org.xwiki.platform:xwiki-platform-oldcore
34
org.jenkins-ci.plugins:script-security
32
silverstripe/framework
32
org.elasticsearch:elasticsearch
32
k8s.io/kubernetes
32
snipe/snipe-it
32
mlflow
31
opencv-contrib-python
30
keystone
30
Django
30
opencv-python
30
mautic/core
30
github.com/argoproj/argo-cd
29
parse-server
29
getgrav/grav
29
github.com/hashicorp/vault
28
github.com/rancher/rancher
28
io.undertow:undertow-core
27
shopware/shopware
27
org.keycloak:keycloak-services
27
centreon/centreon
27
github.com/hashicorp/nomad
26
openssl-src
26
github.com/hashicorp/consul
26
electron
26
prestashop/prestashop
26
rubygems-update
25
org.keycloak:keycloak-parent
25
org.apache.solr:solr-core
25
gogs.io/gogs
24
magento/core
24
pocketmine/pocketmine-mp
23
github.com/argoproj/argo-cd/v2
23
remdex/livehelperchat
23
org.eclipse.jetty:jetty-server
23
org.springframework.security:spring-security-core
23
puppet
23
org.apache.nifi:nifi
22
org.bouncycastle:bcprov-jdk14
22
ckb
22
getkirby/cms
22
rack
22
grumpydictator/firefly-iii
22
@openzeppelin/contracts-upgradeable
21
org.apache.openmeetings:openmeetings-parent
21
activerecord
21
contao/core-bundle
21
github.com/ethereum/go-ethereum
20
@openzeppelin/contracts
20
tribalsystems/zenario
20
github.com/docker/docker
20
github.com/cilium/cilium
20
org.cloudfoundry.identity:cloudfoundry-identity-server
20
org.springframework:spring-core
19
DotNetNuke.Core
19
code.gitea.io/gitea
19
cockpit-hq/cockpit
18
Microsoft.AspNetCore.App.Runtime.win-x64
18
glance
18
langchain
18
com.vaadin:vaadin-bom
18
directus
18
contao/contao
18
Microsoft.AspNetCore.App.Runtime.win-x86
18
helm.sh/helm/v3
18
simplesamlphp/simplesamlphp
18
com.liferay.portal:release.dxp.bom
18
forkcms/forkcms
18
golang.org/x/net
17
Microsoft.AspNetCore.App.Runtime.win-arm
17
org.xwiki.platform:xwiki-platform-web-templates
17
cakephp/cakephp
17
org.apache.geode:geode-core
17
PaddlePaddle
17
francoisjacquet/rosariosis
17
symfony/security
17
topthink/framework
17
mercurial
17
genix/cms
17
cobbler
17
pillow
16
neutron
16
Microsoft.AspNetCore.App.Runtime.linux-musl-x64
16
Microsoft.AspNetCore.App.Runtime.linux-arm64
16
Microsoft.AspNetCore.App.Runtime.linux-x64
16
yetiforce/yetiforce-crm
16
sequelize
16
Microsoft.AspNetCore.App.Runtime.linux-arm
16
org.apache.dubbo:dubbo
16
wasmtime
16
org.bouncycastle:bcprov-jdk15
16
org.apache.activemq:activemq-client
16
rusqlite
16
Microsoft.AspNetCore.App.Runtime.osx-x64
16
paddlepaddle
15
gradio
15
Microsoft.AspNetCore.App.Runtime.win-arm64
15
org.apache.jspwiki:jspwiki-main
15
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
15
next
15
cryptography
15
github.com/goharbor/harbor
15
notebook
15
org.apache.struts.xwork:xwork-core
15
openmage/magento-lts
15
pyftpdlib
14
ezsystems/ezpublish-kernel
14
publify_core
14
github.com/containerd/containerd
14
swagger-ui
14
ghost
14
smarty/smarty
14
symfony/security-http
14
modoboa
14
org.apache.inlong:manager-pojo
14
typo3/cms-backend
14
org.xwiki.platform:xwiki-platform-web
14
tinymce
14
activesupport
14
pyload-ng
14
zendframework/zendframework1
14
ec-cube/ec-cube
14
phpmailer/phpmailer
14
elefant/cms
13
org.apache.cxf:cxf
13
passenger
13
strapi
13
october/system
13
bolt/bolt
13
ckeditor4
13
lavalite/cms
13
org.apache.hadoop:hadoop-main
13
joplin
13
github.com/traefik/traefik/v2
13
OctoPrint
13
github.com/mattermost/mattermost-server
13
github.com/nats-io/nats-server/v2
13
impresscms/impresscms
13
codeigniter4/framework
13
org.jenkins-ci.plugins:git
12
org.bouncycastle:bcprov-jdk15on
12
swift
12
vantage6
12
org.jenkins-ci.plugins.workflow:workflow-cps
12
Filter by Repository
https://github.com/tensorflow/tensorflow
432
https://github.com/chakra-core/ChakraCore
214
https://github.com/moodle/moodle
210
https://github.com/xwiki/xwiki-platform
172
https://github.com/jenkinsci/jenkins
148
https://github.com/pimcore/pimcore
111
https://github.com/apache/tomcat
96
https://github.com/apache/airflow
90
https://github.com/django/django
87
https://github.com/microweber/microweber
85
https://github.com/FasterXML/jackson-databind
70
https://github.com/thorsten/phpmyfaq
69
https://github.com/keycloak/keycloak
59
https://github.com/usememos/memos
59
https://github.com/Dolibarr/dolibarr
55
https://github.com/rails/rails
53
https://github.com/ansible/ansible
53
https://github.com/python-pillow/Pillow
52
https://github.com/kubernetes/kubernetes
49
https://github.com/symfony/symfony
47
https://github.com/TYPO3/typo3
46
https://github.com/apache/struts
46
https://github.com/librenms/librenms
46
https://github.com/shopware/platform
43
https://github.com/ikus060/rdiffweb
42
https://github.com/spring-projects/spring-framework
41
https://github.com/grafana/grafana
39
https://github.com/phpmyadmin/phpmyadmin
38
https://github.com/vyperlang/vyper
38
https://github.com/star7th/showdoc
38
https://github.com/plone/Products.CMFPlone
37
https://github.com/argoproj/argo-cd
37
https://github.com/x-stream/xstream
36
https://github.com/openstack/nova
36
https://github.com/answerdev/answer
34
https://github.com/concretecms/concretecms
34
https://github.com/apache/activemq
33
https://github.com/octobercms/october
33
https://github.com/sparklemotion/nokogiri
33
https://github.com/matrix-org/synapse
32
https://github.com/saltstack/salt
32
https://github.com/go-gitea/gitea
31
https://github.com/magento/magento2
31
https://github.com/PaddlePaddle/Paddle
31
https://github.com/parse-community/parse-server
29
https://github.com/craftcms/cms
29
https://github.com/mautic/mautic
28
https://github.com/CVEProject/cvelist
28
https://github.com/snipe/snipe-it
28
https://github.com/opencv/opencv
28
https://github.com/openstack/keystone
27
https://github.com/apache/inlong
26
https://github.com/froxlor/froxlor
26
https://github.com/rancher/rancher
25
https://github.com/electron/electron
25
https://github.com/mlflow/mlflow
25
https://github.com/TYPO3/TYPO3.CMS
24
https://github.com/getgrav/grav
24
https://github.com/shopware/shopware
24
https://github.com/dotnet/runtime
24
https://github.com/pmmp/PocketMine-MP
23
https://github.com/livehelperchat/livehelperchat
23
https://github.com/github/advisory-database
23
https://github.com/eclipse/jetty.project
23
https://github.com/baserproject/basercms
22
https://github.com/PrestaShop/PrestaShop
22
https://github.com/nervosnetwork/ckb
22
https://github.com/contao/contao
22
https://github.com/firefly-iii/firefly-iii
22
https://github.com/jenkinsci/script-security-plugin
21
https://github.com/apache/nifi
21
https://github.com/strapi/strapi
21
https://github.com/jeecgboot/jeecg-boot
20
https://github.com/OpenNMS/opennms
20
https://github.com/OpenZeppelin/openzeppelin-contracts
20
https://github.com/cilium/cilium
20
https://github.com/netty/netty
20
https://github.com/gogs/gogs
20
https://github.com/bcgit/bc-java
19
https://github.com/apache/cxf
19
https://github.com/hashicorp/consul
19
https://github.com/intelliants/subrion
19
https://github.com/helm/helm
19
https://github.com/nilsteampassnet/teampass
19
https://github.com/cloudfoundry/uaa
19
https://github.com/getkirby/kirby
18
https://github.com/nilsteampassnet/TeamPass
18
https://github.com/rubygems/rubygems
18
https://github.com/directus/directus
17
https://github.com/vaadin/platform
17
https://github.com/liufee/cms
17
https://github.com/bytecodealliance/wasmtime
17
https://github.com/rack/rack
17
https://github.com/sequelize/sequelize
16
https://github.com/hashicorp/vault
16
https://github.com/yetiforcecompany/yetiforcecrm
16
https://github.com/rusqlite/rusqlite
16
https://github.com/etcd-io/etcd
16
https://github.com/umbraco/Umbraco-CMS
16
https://github.com/forkcms/forkcms
16
https://github.com/opencast/opencast
16
https://github.com/ethereum/go-ethereum
16
https://github.com/geoserver/geoserver
15
https://github.com/simplesamlphp/simplesamlphp
15
https://github.com/goharbor/harbor
15
https://github.com/OpenMage/magento-lts
15
https://github.com/centreon/centreon
15
https://github.com/puppetlabs/puppet
15
https://github.com/denoland/deno
15
https://github.com/apache/camel
15
https://github.com/moby/moby
14
https://github.com/containerd/containerd
14
https://github.com/pyca/cryptography
14
https://github.com/pyload/pyload
14
https://github.com/tinymce/tinymce
14
https://github.com/gradio-app/gradio
14
https://github.com/langchain-ai/langchain
14
https://github.com/vantage6/vantage6
14
https://github.com/mattermost/mattermost
14
https://github.com/cockpit-hq/cockpit
14
https://github.com/PHPMailer/PHPMailer
14
https://github.com/cobbler/cobbler
14
https://github.com/quarkusio/quarkus
13
https://github.com/publify/publify
13
https://github.com/modoboa/modoboa
13
https://github.com/traefik/traefik
13
https://github.com/swagger-api/swagger-ui
13
https://github.com/undertow-io/undertow
13
https://github.com/hashicorp/nomad
13
https://github.com/golang/go
13
https://github.com/dompdf/dompdf
13
https://github.com/ming-soft/MCMS
13
https://github.com/silverstripe/silverstripe-framework
13
https://github.com/xuxueli/xxl-job
13
https://github.com/laurent22/joplin
12
https://github.com/twisted/twisted
12
https://github.com/apache/dolphinscheduler
12
https://github.com/dromara/hutool
12
https://github.com/ckeditor/ckeditor4
12
https://github.com/nodejs/undici
12
https://github.com/apache/kylin
12
https://github.com/patriksimek/vm2
12
https://github.com/TryGhost/Ghost
12
https://github.com/centreon/centreon-archived
12
https://github.com/backstage/backstage
12
https://github.com/aio-libs/aiohttp
11
https://github.com/urllib3/urllib3
11
https://github.com/NodeBB/NodeBB
11
https://github.com/containers/podman
11
https://github.com/scrapy/scrapy
11
https://github.com/openfga/openfga
11
https://github.com/puma/puma
11
https://github.com/nats-io/nats-server
11
https://github.com/top-think/framework
11
https://github.com/thorsten/phpMyFAQ
11
https://github.com/vaadin/flow
11
https://github.com/jquery/jquery
11
https://github.com/1Panel-dev/1Panel
11
https://github.com/onionshare/onionshare
11
https://github.com/vercel/next.js
11
https://github.com/zitadel/zitadel
11
https://github.com/smarty-php/smarty
11
https://github.com/janeczku/calibre-web
11
https://github.com/dotnet/aspnetcore
11
https://github.com/drupal/core
11
https://github.com/igniterealtime/Openfire
11
https://github.com/opencontainers/runc
11
https://github.com/cakephp/cakephp
11
https://github.com/cloudflare/cfrpki
11
https://github.com/Studio-42/elFinder
11
https://github.com/jupyter/notebook
10
https://github.com/nocodb/nocodb
10
https://github.com/nextauthjs/next-auth
10
https://github.com/Sylius/Sylius
10
https://github.com/pimcore/admin-ui-classic-bundle
10
https://github.com/phusion/passenger
10
https://github.com/dpgaspar/Flask-AppBuilder
10
https://github.com/greenpau/caddy-security
10
https://github.com/zopefoundation/Zope
10
https://github.com/jenkinsci/git-plugin
10
https://github.com/WWBN/AVideo
10
https://github.com/dolibarr/dolibarr
10
https://github.com/keystonejs/keystone
10
https://github.com/openstack/glance
10
https://github.com/codeigniter4/CodeIgniter4
10
https://github.com/wagtail/wagtail
10
https://github.com/OPCFoundation/UA-.NETStandard
10
https://github.com/ezsystems/ezpublish-kernel
10
https://github.com/cui2shark/cms
9
https://github.com/LavaLite/cms
9
https://github.com/funadmin/funadmin
9
https://github.com/faucetsdn/ryu
9
https://github.com/laravel/framework
9
https://github.com/neorazorx/facturascripts
9
https://github.com/giampaolo/pyftpdlib
9
https://github.com/nautobot/nautobot
9
https://github.com/apache/lucene-solr
9
https://github.com/pgadmin-org/pgadmin4
9
https://github.com/DSpace/DSpace
9