An open API service providing security vulnerability metadata for many open source software ecosystems.

Browse Security Advisories

Critical
11 months ago

Liferay Portal and Liferay DXP Vulnerable to CSRF in the Script Console GSA_kwCzR0hTQS1jaGoyLTR2ZzctaGhnM84ABAkm

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
11 months ago

Liferay Portal and Liferay DXP Workflow Component Does Not Check User Permissions GSA_kwCzR0hTQS0zbWZxLWZwMmYtdndxaM4ABAkx

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
about 1 year ago

HTTP client can manipulate custom HTTP headers that are added by Traefik GSA_kwCzR0hTQS02MmM4LW1oNTMtNGNxds4AA_sN

go github.com/traefik/traefik, github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
Critical
about 1 year ago

Grafana plugin SDK Information Leakage GSA_kwCzR0hTQS14eHh3LTNqNmgtcTdoNs4AA_sL

go github.com/grafana/grafana-plugin-sdk-go
Critical
about 1 year ago

Chaosblade vulnerable to OS command execution GSA_kwCzR0hTQS03MjNoLXgzN2ctZjhxbc4AA_rL

go github.com/chaosblade-io/chaosblade
Critical
about 1 year ago

ThinkPHP deserialization vulnerability GSA_kwCzR0hTQS1mNHdoLTM1OWctNHBxN84AA_Yu

packagist topthink/framework
Critical
about 1 year ago

Apache Dolphinscheduler Code Injection vulnerability GSA_kwCzR0hTQS0yZm02LW12NTctcDJxaM4AA-yo

maven org.apache.dolphinscheduler:dolphinscheduler-task-api
Critical
about 1 year ago

XWiki Platform allows XSS through XClass name in string properties GSA_kwCzR0hTQS13Y2c5LXBncXYteG01ds4AA-yA

maven org.xwiki.platform:xwiki-platform-oldcore
Critical
about 1 year ago

CometVisu Backend for openHAB affected by RCE through path traversal GSA_kwCzR0hTQS1mNzI5LTU4eDQtZ3FnZs4AA-gh

maven org.openhab.ui.bundles:org.openhab.ui.cometvisu
Critical
about 1 year ago

CasaOS Command Injection vulnerability GSA_kwCzR0hTQS05MnZjLTRmY3ctZzY4cc4AA-ZD

go github.com/IceWhaleTech/CasaOS
Critical
about 1 year ago

rudder-server is vulnerable to SQL injection GSA_kwCzR0hTQS0zam1tLWY2amotcmNjM84AA-ZC

go github.com/rudderlabs/rudder-server
Critical
about 1 year ago

Authz zero length regression GSA_kwCzR0hTQS12MjN2LTZqdzItOThmcc4AA-Q4

go github.com/docker/docker
Critical
about 1 year ago

Remote code execution in Spring Cloud Data Flow GSA_kwCzR0hTQS1wNTI4LTNtdmYtZ3I4N84AA-Hu

maven org.springframework.cloud:spring-cloud-skipper
Critical
about 1 year ago

fabedge has insecure permissions GSA_kwCzR0hTQS1jOWNtLTVqODItbTZwas4AA-HP

go github.com/fabedge/fabedge
Critical
about 1 year ago

Volcano has insecure permissions GSA_kwCzR0hTQS01ZzN4LThnMnYtcjh4OM4AA-HK

go github.com/volcano-sh/volcano
Critical
about 1 year ago

Microsoft Security Advisory CVE-2024-35264 | .NET Remote Code Execution Vulnerability GSA_kwCzR0hTQS1jaGZjLTl3Nm0tNzVyZs4AA9un

nuget Microsoft.AspNetCore.App.Runtime.win-x86, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-arm64, Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.osx-x64, Microsoft.AspNetCore.App.Runtime.osx-arm64, Microsoft.AspNetCore.App.Runtime.linux-x64, Microsoft.AspNetCore.App.Runtime.linux-musl-x64, Microsoft.AspNetCore.App.Runtime.linux-musl-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-arm, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-arm
Critical
about 1 year ago

Missing key verification in gost GSA_kwCzR0hTQS04d3h4LTM1cWMtdnA2cs4AA9f9

go github.com/ginuerzh/gost
Critical
over 1 year ago

Session Middleware Token Injection Vulnerability GSA_kwCzR0hTQS05OGoyLTNqM3AtZncyds4AA9cs

go github.com/gofiber/fiber/v2/middleware/session, github.com/gofiber/fiber/v2, github.com/gofiber/fiber
Critical
over 1 year ago

Remote Code Execution (RCE) vulnerability in geoserver GSA_kwCzR0hTQS02amo2LWdtN3AtZmN2ds4AA9cr

maven org.geoserver:gs-wms, org.geoserver:gs-wfs, org.geoserver.web:gs-web-app
Critical
over 1 year ago

XWiki programming rights may be inherited by inclusion GSA_kwCzR0hTQS1xY2ozLXdwZ20tcXB4aM4AA9UF

maven org.xwiki.platform:xwiki-platform-rendering-macro-include
Critical
over 1 year ago

XWiki Platform allows remote code execution from user account GSA_kwCzR0hTQS1qNTg0LWoydmotM2Y5M84AA9Pv

maven org.xwiki.platform:xwiki-platform-oldcore
Critical
over 1 year ago

Apache Submarine Server Core Incorrect Authorization vulnerability GSA_kwCzR0hTQS02cTk3LTh2M2ctcnB4d84AA8-X

pypi, maven apache-submarine, org.apache.submarine:submarine-server-core

Filter by Severity

Filter by Ecosystem

Filter by Package

magento/community-edition 25 dolibarr/dolibarr 25 com.fasterxml.jackson.core:jackson-databind 24 org.jenkins-ci.main:jenkins-core 19 net.mingsoft:ms-mcms 19 com.liferay.portal:release.portal.bom 18 com.liferay.portal:release.dxp.bom 18 salt 17 magento/project-community-edition 16 moodle/moodle 16 topthink/framework 15 mlflow 14 Django 14 org.apache.dubbo:dubbo 13 drupal/core 12 org.apache.struts:struts2-core 12 org.xwiki.platform:xwiki-platform-oldcore 12 gogs.io/gogs 11 langchain 11 vm2 10 apache-airflow 10 org.xwiki.platform:xwiki-platform-web-templates 10 phpmyadmin/phpmyadmin 10 flowise 9 drupal/drupal 9 ansible 9 funadmin/funadmin 9 org.xwiki.platform:xwiki-platform-administration-ui 8 github.com/argoproj/argo-cd/v2 8 froxlor/froxlor 8 rdiffweb 8 symfony/symfony 8 github.com/argoproj/argo-cd 7 vllm 7 pyload-ng 7 rusqlite 7 github.com/rancher/rancher 7 studio-42/elfinder 7 parse-server 7 paddlepaddle 7 sequelize 7 shopware/platform 7 zendframework/zendframework1 7 aaptjs 6 mercurial 6 craftcms/cms 6 nilsteampassnet/teampass 6 ezsystems/ezpublish-kernel 6 org.apache.inlong:manager-pojo 6 zendframework/zendframework 6 pillow 6 org.jeecgframework.boot:jeecg-boot-common 6 typo3/cms 6 org.apache.shiro:shiro-core 6 thorsten/phpmyfaq 6 github.com/answerdev/answer 6 mautic/core 6 github.com/hashicorp/vault 6 tensorflow-gpu 6 librenms/librenms 5 safe-eval 5 ckb 5 bentoml 5 dompdf/dompdf 5 code.gitea.io/gitea 5 executorch 5 org.apache.openmeetings:openmeetings-parent 5 tensorflow 5 org.xwiki.platform:xwiki-platform-web 5 github.com/grafana/grafana 5 steal 5 org.jenkins-ci.plugins:script-security 5 centreon/centreon 5 tensorflow-cpu 5 org.jeecgframework.boot:jeecg-boot-parent 5 adodb/adodb-php 5 prestashop/prestashop 5 dbgpt 5 shopware/core 5 nodebb 5 org.xwiki.commons:xwiki-commons-xml 5 Microsoft.ChakraCore 5 github.com/mattermost/mattermost/server/v8 5 org.apache.solr:solr-core 4 org.xwiki.platform:xwiki-platform-flamingo-skin-resources 4 org.apache.ignite:ignite-core 4 org.apache.kylin:kylin-server-base 4 org.apache.tomcat.embed:tomcat-embed-core 4 org.apache.tapestry:tapestry-core 4 nukeviet/nukeviet 4 org.xwiki.platform:xwiki-platform-appwithinminutes-ui 4 ait-core 4 org.apache.activemq:activemq-client 4 simplesamlphp/simplesamlphp 4 ray 4 tribalsystems/zenario 4 ai.h2o:h2o-core 4 org.eclipse.jetty:jetty-server 4 nokogiri 4 baserproject/basercms 4 realms-shim 4 contao/contao 4 mongoose 4 aim 4 org.apache.tomcat:tomcat-catalina 4 smallvec 4 net.opentsdb:opentsdb 4 github.com/usememos/memos 4 apache-airflow-providers-apache-hive 4 org.cloudfoundry.identity:cloudfoundry-identity-server 4 Pillow 4 shopware/shopware 4 hermes-engine 4 messagepack-rs 4 contao/core-bundle 4 cobbler 4 swagger-ui 4 org.jeecgframework.boot:jeecg-boot-base-core 4 calibreweb 4 openssl-src 4 showdoc/showdoc 4 org.xwiki.platform:xwiki-platform-search-ui 4 gradio 4 h2o 4 ruby-saml 4 feehi/cms 4 safer-eval 4 org.apache.inlong:manager-service 4 langchain-experimental 4 twisted 3 github.com/cosmos/ibc-go/v4 3 picklescan 3 org.springframework.security:spring-security-core 3 github.com/beego/beego 3 github.com/cosmos/ibc-go/v7 3 nvflare 3 org.apache.jmeter:ApacheJMeter 3 org.apache.ozone:ozone-main 3 rubygems-update 3 modoboa 3 wwbn/avideo 3 org.jenkins-ci.plugins.workflow:workflow-cps 3 io.undertow:undertow-core 3 org.jenkins-ci.plugins:active-directory 3 org.apache.hadoop:hadoop-common 3 symfony/security 3 pimcore/pimcore 3 feathers-sequelize 3 org.apache.linkis:linkis 3 torchserve 3 github.com/pterodactyl/wings 3 io.dataease:dataease-plugin-common 3 github.com/cosmos/ibc-go/v3 3 org.apache.ranger:ranger 3 ezsystems/ezplatform-kernel 3 github.com/cosmos/ibc-go/v5 3 org.apache.storm:storm 3 pandasai 3 github.com/beego/beego/v2 3 handlebars 3 ro.pippo:pippo-core 3 smarty/smarty 3 actix-web 3 namada-apps 3 edu.stanford.nlp:stanford-corenlp 3 Plone 3 github.com/hashicorp/nomad 3 github.com/cosmos/ibc-go/v2 3 codeigniter4/framework 3 org.jeecgframework.boot:jeecg-boot-base 3 github.com/IceWhaleTech/CasaOS 3 mitmproxy 3 jsrsasign 3 vyper 3 strapi 3 log4j:log4j 3 ibexa/core 3 org.xwiki.platform:xwiki-platform-distribution-war 3 llama-index 3 pyyaml 3 org.apache.any23:apache-any23 3 PaddlePaddle 3 xcb 3 github.com/gofiber/fiber/v2 3 com.jflyfox:jflyfox_jfinal 3 com.hazelcast:hazelcast 3 lmdb 3 impresscms/impresscms 3 SQLAlchemy 3 github.com/cosmos/ibc-go/v8 3 org.richfaces:richfaces-core 3 org.apache.dolphinscheduler:dolphinscheduler 3 org.xwiki.platform:xwiki-platform-icon-ui 3 org.xwiki.platform:xwiki-platform-panels-ui 3 silverstripe/framework 3 llama-index-core 3 dulwich 3 codeigniter/framework 3 symfony/security-core 3 agentscope 3

Filter by Repository

https://github.com/xwiki/xwiki-platform 100 https://github.com/FasterXML/jackson-databind 24 https://github.com/jenkinsci/jenkins 18 https://github.com/apache/airflow 16 https://github.com/Dolibarr/dolibarr 15 https://github.com/django/django 15 https://github.com/mlflow/mlflow 14 https://github.com/saltstack/salt 13 https://github.com/langchain-ai/langchain 12 https://github.com/argoproj/argo-cd 11 https://github.com/gogs/gogs 11 https://github.com/patriksimek/vm2 10 https://github.com/ming-soft/MCMS 10 https://github.com/apache/inlong 10 https://github.com/magento/magento2 10 https://github.com/python-pillow/Pillow 9 https://github.com/jeecgboot/jeecg-boot 9 https://github.com/top-think/framework 9 https://github.com/funadmin/funadmin 9 https://github.com/PaddlePaddle/Paddle 9 https://github.com/ansible/ansible 8 https://github.com/apache/struts 8 https://github.com/go-gitea/gitea 8 https://github.com/ikus060/rdiffweb 8 https://github.com/rancher/rancher 7 https://github.com/Studio-42/elFinder 7 https://github.com/apache/tomcat 7 https://github.com/rusqlite/rusqlite 7 https://github.com/sequelize/sequelize 7 https://github.com/run-llama/llama_index 7 https://github.com/symfony/symfony 7 https://github.com/FlowiseAI/Flowise 7 https://github.com/parse-community/parse-server 7 https://github.com/pyload/pyload 7 https://github.com/dompdf/dompdf 6 https://github.com/liferay/liferay-portal 6 https://github.com/answerdev/answer 6 https://github.com/tensorflow/tensorflow 6 https://github.com/shopware/platform 6 https://github.com/shenzhim/aaptjs 6 https://github.com/thorsten/phpmyfaq 6 https://github.com/xwiki/xwiki-commons 6 https://github.com/craftcms/cms 5 https://github.com/NodeBB/NodeBB 5 https://github.com/twisted/twisted 5 https://github.com/moodle/moodle 5 https://github.com/auth0/auth0-PHP 5 https://github.com/keycloak/keycloak 5 https://github.com/vllm-project/vllm 5 https://github.com/froxlor/froxlor 5 https://github.com/nervosnetwork/ckb 5 https://github.com/hacksparrow/safe-eval 5 https://github.com/dromara/hutool 5 https://github.com/PrestaShop/PrestaShop 5 https://github.com/apache/activemq 5 https://github.com/spring-projects/spring-framework 5 https://github.com/stealjs/steal 5 https://github.com/ADOdb/ADOdb 5 https://github.com/grafana/grafana 5 https://github.com/SAML-Toolkits/ruby-saml 5 https://github.com/pytorch/executorch 5 https://github.com/ray-project/ray 4 https://github.com/bentoml/BentoML 4 https://github.com/OpenTSDB/opentsdb 4 https://github.com/liufee/cms 4 https://github.com/nilsteampassnet/TeamPass 4 https://github.com/pippo-java/pippo 4 https://github.com/hwchase17/langchain 4 https://github.com/cobbler/cobbler 4 https://github.com/CVEProject/cvelist 4 https://github.com/swagger-api/swagger-ui 4 https://github.com/contao/contao 4 https://github.com/otake84/messagepack-rs 4 https://github.com/servo/rust-smallvec 4 https://github.com/phpmyadmin/phpmyadmin 4 https://github.com/gradio-app/gradio 4 https://github.com/star7th/showdoc 4 https://github.com/mautic/mautic 4 https://github.com/kubernetes/kubernetes 4 https://github.com/xwiki/xwiki-rendering 4 https://github.com/ezsystems/ezpublish-kernel 4 https://github.com/dataease/dataease 4 https://github.com/janeczku/calibre-web 4 https://github.com/usememos/memos 4 https://github.com/cloudfoundry/uaa 4 https://github.com/apache/camel 3 https://github.com/node-saml/xml-crypto 3 https://github.com/simplesamlphp/simplesamlphp 3 https://github.com/opencast/opencast 3 https://github.com/librenms/librenms 3 https://github.com/thlorenz/browserify-shim 3 https://github.com/chakra-core/ChakraCore 3 https://github.com/apache/shiro 3 https://github.com/rubygems/rubygems 3 https://github.com/publify/publify 3 https://github.com/TribalSystems/Zenario 3 https://github.com/pimcore/pimcore 3 https://github.com/TeamSeri0us/pocs 3 https://github.com/simpleledger/slpjs 3 https://github.com/baserproject/basercms 3 https://github.com/feathersjs-ecosystem/feathers-sequelize 3 https://github.com/mmaitre314/picklescan 3 https://github.com/strapi/strapi 3 https://github.com/kjur/jsrsasign 3 https://github.com/jbroadway/elefant 3 https://github.com/LetianYuan/My-CVE-Public-References 3 https://github.com/anoma/namada 3 https://github.com/pterodactyl/wings 3 https://github.com/Automattic/mongoose 3 https://github.com/mitmproxy/mitmproxy 3 https://github.com/rubygems/rubygems.org 3 https://github.com/dexidp/dex 3 https://github.com/shopware5/shopware 3 https://github.com/smarty-php/smarty 3 https://github.com/actix/actix-web 3 https://github.com/yaml/pyyaml 3 https://github.com/mbechler/marshalsec 3 https://github.com/crewjam/saml 3 https://github.com/github/securitylab 3 https://github.com/cosmos/ibc-go 3 https://github.com/ezsystems/ezplatform-kernel 3 https://github.com/ibexa/core 3 https://github.com/beego/beego 3 https://github.com/andrewhickman/id-map 3 https://github.com/nukeviet/nukeviet 3 https://github.com/NASA-AMMOS/AIT-Core 3 https://github.com/pgadmin-org/pgadmin4 3 https://github.com/jflyfox/jfinal_cms 3 https://github.com/geoserver/geoserver 3 https://github.com/ImpressCMS/impresscms 3 https://github.com/codeigniter4/CodeIgniter4 3 https://github.com/neorazorx/facturascripts 3 https://github.com/denoland/deno 3 https://github.com/gofiber/fiber 3 https://github.com/eosphoros-ai/DB-GPT 3 https://github.com/vyperlang/vyper 3 https://github.com/PHPMailer/PHPMailer 3 https://github.com/NVIDIA/NVFlare 3 https://github.com/pytorch/pytorch 3 https://github.com/centreon/centreon-archived 3 https://github.com/rails/rails 3 https://github.com/modoboa/modoboa 3 https://github.com/facebook/hermes 3 https://github.com/octobercms/october 3 https://github.com/shopware/shopware 3 https://github.com/sqlalchemy/sqlalchemy 3 https://github.com/apache/dolphinscheduler 3 https://github.com/hazelcast/hazelcast 3 https://github.com/h2oai/h2o-3 3 https://github.com/pytorch/serve 3 https://github.com/chaos-mesh/chaos-mesh 3 https://github.com/dwisiswant0/advisory 3 https://github.com/sparklemotion/nokogiri 3 https://github.com/facade/ignition 3 https://github.com/rochacbruno/quokka 2 https://github.com/frohoff/ysoserial 2 https://github.com/Islandora/Crayfish 2 https://github.com/mpdavis/python-jose 2 https://github.com/apache/kylin 2 https://github.com/javamelody/javamelody 2 https://github.com/better-auth/better-auth 2 https://github.com/qcubed/qcubed 2 https://github.com/keystonejs/keystone 2 https://github.com/Admidio/admidio 2 https://github.com/OpenAPITools/openapi-generator 2 https://github.com/simpleledger/slp-validate.js 2 https://github.com/qdrant/qdrant 2 https://github.com/uasoft-indonesia/badaso 2 https://github.com/apache/submarine 2 https://github.com/sjep/array 2 https://github.com/top-think/thinkphp 2 https://github.com/lightning-ai/pytorch-lightning 2 https://github.com/spring-projects/spring-security 2 https://github.com/modelscope/agentscope 2 https://github.com/OpenZeppelin/openzeppelin-contracts 2 https://github.com/russellhaering/gosaml2 2 https://github.com/jenkinsci/script-security-plugin 2 https://github.com/firebase/php-jwt 2 https://github.com/http4s/http4s 2 https://github.com/NVIDIA/gpu-operator 2 https://github.com/apache/pinot 2 https://github.com/h2database/h2database 2 https://github.com/MrSwitch/hello.js 2 https://github.com/ibexa/admin-ui 2 https://github.com/evmos/evmos 2 https://github.com/jenkinsci/semantic-versioning-plugin 2 https://github.com/apache/zeppelin 2 https://github.com/scalyr/scalyr-agent-2 2 https://github.com/deepjavalibrary/djl 2 https://github.com/noear/solon 2 https://github.com/dominictarr/libnested 2 https://github.com/fluxcd/flux2 2 https://github.com/viz-rs/nano-id 2 https://github.com/moby/buildkit 2 https://github.com/web2py/web2py 2 https://github.com/go-git/go-git 2 https://github.com/apache/incubator-hugegraph 2 https://github.com/sidorares/node-mysql2 2 https://github.com/unshiftio/url-parse 2