An open API service providing security vulnerability metadata for many open source software ecosystems.

Browse Security Advisories

High
5 months ago

OPA server Data API HTTP path injection of Rego GSA_kwCzR0hTQS02bTh3LWpjODctNmNyN84ABHYV

go github.com/open-policy-agent/opa, github.com/open-policy-agent/opa/server, github.com/open-policy-agent/opa/v1/server
High
5 months ago

Keycloak hostname verification GSA_kwCzR0hTQS1odzU4LTM3OTMtNDJnZ84ABHSk

maven org.keycloak:keycloak-services
High
5 months ago

Any user with view access to the XWiki space can change the authenticator GSA_kwCzR0hTQS1mOWM2LTJmOXAtODJqas4ABHSi

maven org.xwiki.platform:xwiki-platform-security-authentication-ui
High
5 months ago

Apache HttpClient disables domain checks GSA_kwCzR0hTQS03M20yLXFmcTMtNTZjeM4ABHIl

maven org.apache.httpcomponents.client5:httpclient5
High
5 months ago

Traefik has a possible vulnerability with the path matchers GSA_kwCzR0hTQS02cDY4LXc0NWctNDhqN84ABHEL

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2, github.com/traefik/traefik
High
5 months ago

GoBGP panics due to a zero value for softwareVersionLen GSA_kwCzR0hTQS03bTM1LXZ3MmMtNjk2ds4ABHDs

go github.com/osrg/gobgp/v3, github.com/osrg/gobgp
High
6 months ago

OpenMetadata SQL Injection GSA_kwCzR0hTQS14OHBtLXdyZzItbXFteM4ABG_L

maven org.open-metadata:openmetadata-service
High
6 months ago

mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File GSA_kwCzR0hTQS03dnBwLTljeGotcThnds4ABGu_

go github.com/mholt/archiver/v3, github.com/mholt/archiver
High
6 months ago

CefSharp affected by incorrect handle provided in unspecified circumstances in Mojo on Windows GSA_kwCzR0hTQS1mODd3LTNqNXctdjU4cM4ABGup

nuget CefSharp.OffScreen, CefSharp.OffScreen.NetCore, CefSharp.WinForms.NetCore, CefSharp.WinForms, CefSharp.Wpf.NetCore, CefSharp.Wpf.HwndHost, CefSharp.Wpf
High
6 months ago

GraphQL query operations security can be bypassed GSA_kwCzR0hTQS1jZzNjLTI0NXctNzI4bc4ABGap

packagist api-platform/core, api-platform/graphql
High
6 months ago

OpenDaylight SFC Insecure Shiro Cookie Configuration GSA_kwCzR0hTQS14cDc1LXc3dnEtNXg2as4ABF1c

maven org.opendaylight.sfc:odl-sfc-openflow-renderer, org.opendaylight.sfc:odl-sfc-ovs
High
6 months ago

OpenDaylight SFC Denial of Service (DoS) GSA_kwCzR0hTQS12M3ZwLWZnMnYtZzdxNM4ABF1Y

maven org.opendaylight.sfc:odl-sfc-ovs, org.opendaylight.sfc:odl-sfc-openflow-renderer
High
6 months ago

Mattermost Fails to Enforce MFA on Plugin Endpoints GSA_kwCzR0hTQS03MnF2LWo4dnIteHZmds4ABFw7

go github.com/mattermost/mattermost/server/v8

Filter by Severity

Filter by Ecosystem

Filter by Package

Microsoft.ChakraCore 234 tensorflow 122 tensorflow-gpu 112 tensorflow-cpu 112 magento/community-edition 80 moodle/moodle 61 org.jenkins-ci.main:jenkins-core 55 com.fasterxml.jackson.core:jackson-databind 43 typo3/cms 41 Django 38 dolibarr/dolibarr 35 drupal/core 32 librenms/librenms 32 github.com/rancher/rancher 31 org.apache.tomcat:tomcat 31 pimcore/pimcore 30 mlflow 30 salt 29 apache-airflow 29 Plone 28 phpmyadmin/phpmyadmin 28 microweber/microweber 27 nokogiri 26 ansible 24 typo3/cms-core 24 org.apache.struts:struts2-core 24 com.liferay.portal:release.portal.bom 23 drupal/drupal 23 opencv-contrib-python 22 com.thoughtworks.xstream:xstream 22 opencv-python 22 com.jfinal:jfinal 21 thorsten/phpmyfaq 20 matrix-synapse 20 symfony/symfony 20 django 20 com.liferay.portal:release.dxp.bom 19 org.jenkins-ci.plugins:script-security 19 org.apache.tomcat.embed:tomcat-embed-core 18 pillow 18 Pillow 18 pocketmine/pocketmine-mp 18 magento/project-community-edition 18 gradio 17 github.com/grafana/grafana 17 rdiffweb 17 io.undertow:undertow-core 17 openssl-src 16 getgrav/grav 16 parse-server 16 nilsteampassnet/teampass 15 org.xwiki.platform:xwiki-platform-oldcore 15 github.com/hashicorp/consul 15 open-webui 15 keystone 15 github.com/hashicorp/vault 15 github.com/usememos/memos 14 shopware/platform 14 vyper 14 Microsoft.AspNetCore.App.Runtime.win-x64 14 centreon/centreon 14 Microsoft.AspNetCore.App.Runtime.win-x86 14 Microsoft.NetCore.App.Runtime.win-arm 14 org.keycloak:keycloak-core 14 net.mingsoft:ms-mcms 14 craftcms/cms 14 org.apache.solr:solr-core 13 mautic/core 13 apache-superset 13 rubygems-update 13 org.keycloak:keycloak-services 13 mindsdb 13 golang.org/x/net 13 shopware/core 13 baserproject/basercms 12 Microsoft.AspNetCore.App.Runtime.linux-arm 12 Microsoft.AspNetCore.App.Runtime.win-arm 12 Microsoft.NetCore.App.Runtime.win-x86 12 Microsoft.NetCore.App.Runtime.win-arm64 12 Microsoft.NetCore.App.Runtime.win-x64 12 electron 12 org.apache.openmeetings:openmeetings-parent 12 phpoffice/phpspreadsheet 12 silverstripe/framework 12 activerecord 12 org.keycloak:keycloak-parent 11 Microsoft.AspNetCore.App.Runtime.linux-x64 11 Microsoft.AspNetCore.App.Runtime.win-arm64 11 Microsoft.AspNetCore.App.Runtime.linux-arm64 11 github.com/argoproj/argo-cd/v2 11 intelliants/subrion 11 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 11 actionpack 11 cockpit-hq/cockpit 11 next 11 github.com/zitadel/zitadel 11 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 11 directus 11 gogs.io/gogs 11 froxlor/froxlor 11 org.springframework.security:spring-security-core 11 github.com/hashicorp/nomad 11 github.com/argoproj/argo-cd 11 github.com/nats-io/nats-server/v2 10 laravel/framework 10 github.com/ollama/ollama 10 funadmin/funadmin 10 k8s.io/kubernetes 10 openmage/magento-lts 10 github.com/traefik/traefik/v2 10 deno 10 Microsoft.AspNetCore.App.Runtime.osx-x64 10 nova 10 surrealdb 10 snipe/snipe-it 10 Microsoft.NetCore.App.Runtime.linux-musl-x64 9 mercurial 9 ckb 9 Microsoft.NetCore.App.Runtime.osx-x64 9 org.apache.tomcat:tomcat-catalina 9 rusqlite 9 cobbler 9 org.cloudfoundry.identity:cloudfoundry-identity-server 9 aim 9 neutron 9 Microsoft.NetCore.App.Runtime.linux-musl-arm 9 lollms 9 Microsoft.NetCore.App.Runtime.linux-arm64 9 rack 9 Microsoft.NetCore.App.Runtime.linux-musl-arm64 9 h2o 9 github.com/ethereum/go-ethereum 9 org.apache.geode:geode-core 9 litellm 9 Microsoft.NetCore.App.Runtime.osx-arm64 9 Microsoft.NetCore.App.Runtime.linux-x64 9 Microsoft.NetCore.App.Runtime.linux-arm 9 flowise 9 zendframework/zendframework1 9 org.apache.nifi:nifi 9 org.apache.hadoop:hadoop-main 9 phpbb/phpbb 8 plone 8 Microsoft.NETCore.App.Runtime.win-x64 8 yeswiki/yeswiki 8 smarty/smarty 8 Microsoft.NETCore.App.Runtime.win-arm64 8 org.craftercms:crafter-studio 8 github.com/docker/docker 8 github.com/sylabs/singularity 8 org.apache.struts.xwork:xwork-core 8 pyload-ng 8 moin 8 org.springframework:spring-core 8 october/system 8 @anthropic-ai/claude-code 8 composer/composer 8 org.eclipse.jetty:jetty-server 8 org.bouncycastle:bcprov-jdk15on 8 cryptography 8 org.apache.inlong:manager-pojo 7 contao/core-bundle 7 OPCFoundation.NetStandard.Opc.Ua.Core 7 phpmailer/phpmailer 7 apollo-router 7 opencv-contrib-python-headless 7 org.elasticsearch:elasticsearch 7 tar 7 cakephp/cakephp 7 k8s.io/ingress-nginx 7 codeigniter4/framework 7 mantisbt/mantisbt 7 github.com/mattermost/mattermost/server/v8 7 DotNetNuke.Core 7 golang.org/x/crypto 7 cn.hutool:hutool-core 7 @strapi/strapi 7 strapi 7 Microsoft.NETCore.App.Runtime.win-x86 7 ai.h2o:h2o-core 7 magento/core 7 ryu 7 org.jenkins-ci.plugins.workflow:workflow-cps 7 com.xuxueli:xxl-job 7 kiwitcms 6 opencart/opencart 6 org.apache.dolphinscheduler:dolphinscheduler 6 Microsoft.NETCore.App 6 sequelize 6 mediawiki/core 6 Magick.NET-Q16-x86 6 prestashop/prestashop 6 github.com/filebrowser/filebrowser/v2 6 @openzeppelin/contracts 6 org.apache.tomcat:tomcat-coyote 6 ezsystems/ezpublish-kernel 6 Microsoft.AspNetCore.App.Runtime.linux-musl-arm 6 github.com/goharbor/harbor 6 handlebars 6 opencv-python-headless 6

Filter by Repository

https://github.com/chakra-core/ChakraCore 204 https://github.com/tensorflow/tensorflow 122 https://github.com/xwiki/xwiki-platform 64 https://github.com/django/django 51 https://github.com/FasterXML/jackson-databind 44 https://github.com/jenkinsci/jenkins 43 https://github.com/apache/tomcat 39 https://github.com/apache/airflow 39 https://github.com/python-pillow/Pillow 35 https://github.com/moodle/moodle 33 https://github.com/keycloak/keycloak 31 https://github.com/dotnet/runtime 28 https://github.com/pimcore/pimcore 28 https://github.com/librenms/librenms 28 https://github.com/rancher/rancher 27 https://github.com/microweber/microweber 25 https://github.com/opencv/opencv 25 https://github.com/symfony/symfony 23 https://github.com/apache/struts 22 https://github.com/x-stream/xstream 22 https://github.com/Dolibarr/dolibarr 21 https://github.com/sparklemotion/nokogiri 21 https://github.com/ansible/ansible 19 https://github.com/spring-projects/spring-framework 19 https://github.com/thorsten/phpmyfaq 18 https://github.com/pmmp/PocketMine-MP 18 https://github.com/TYPO3/typo3 18 https://github.com/ikus060/rdiffweb 17 https://github.com/plone/Products.CMFPlone 16 https://github.com/gradio-app/gradio 16 https://github.com/parse-community/parse-server 16 https://github.com/github/advisory-database 15 https://github.com/kubernetes/kubernetes 15 https://github.com/rails/rails 15 https://github.com/mlflow/mlflow 15 https://github.com/apache/inlong 15 https://github.com/zitadel/zitadel 14 https://github.com/grafana/grafana 14 https://github.com/getgrav/grav 14 https://github.com/jenkinsci/script-security-plugin 14 https://github.com/vyperlang/vyper 14 https://github.com/openstack/keystone 14 https://github.com/usememos/memos 14 https://github.com/argoproj/argo-cd 14 https://github.com/saltstack/salt 13 https://github.com/matrix-org/synapse 13 https://github.com/undertow-io/undertow 13 https://github.com/mautic/mautic 13 https://github.com/mindsdb/mindsdb 13 https://github.com/liferay/liferay-portal 12 https://github.com/directus/directus 12 https://github.com/electron/electron 12 https://github.com/PHPOffice/PhpSpreadsheet 12 https://github.com/hashicorp/consul 12 https://github.com/silverstripe/silverstripe-framework 11 https://github.com/apache/nifi 11 https://github.com/octobercms/october 10 https://github.com/denoland/deno 10 https://github.com/surrealdb/surrealdb 10 https://github.com/dotnet/aspnetcore 10 https://github.com/strapi/strapi 10 https://github.com/centreon/centreon 10 https://github.com/go-gitea/gitea 10 https://github.com/golang/go 10 https://github.com/run-llama/llama_index 10 https://github.com/OpenMage/magento-lts 10 https://github.com/funadmin/funadmin 10 https://github.com/netty/netty 9 https://github.com/vercel/next.js 9 https://github.com/snipe/snipe-it 9 https://github.com/cloudfoundry/uaa 9 https://github.com/nilsteampassnet/teampass 9 https://github.com/traefik/traefik 9 https://github.com/apache/cxf 9 https://github.com/apache/camel 9 https://github.com/laravel/framework 9 https://github.com/hashicorp/vault 9 https://github.com/spring-projects/spring-security 9 https://github.com/openstack/nova 9 https://github.com/rusqlite/rusqlite 9 https://github.com/geoserver/geoserver 9 https://github.com/nervosnetwork/ckb 9 https://github.com/cui2shark/cms 9 https://github.com/OPCFoundation/UA-.NETStandard 8 https://github.com/shopware/platform 8 https://github.com/dnnsoftware/Dnn.Platform 8 https://github.com/PaddlePaddle/Paddle 8 https://github.com/nats-io/nats-server 8 https://github.com/OpenRefine/OpenRefine 8 https://github.com/pyload/pyload 8 https://github.com/phpmyadmin/phpmyadmin 8 https://github.com/gogs/gogs 8 https://github.com/cockpit-hq/cockpit 8 https://github.com/anthropics/claude-code 8 https://github.com/TYPO3/TYPO3.CMS 8 https://github.com/backstage/backstage 8 https://github.com/pyca/cryptography 8 https://github.com/craftcms/cms 8 https://github.com/bcgit/bc-java 8 https://github.com/h2oai/h2o-3 8 https://github.com/composer/composer 7 https://github.com/YesWiki/yeswiki 7 https://github.com/contao/contao 7 https://github.com/PHPMailer/PHPMailer 7 https://github.com/eclipse/jetty.project 7 https://github.com/rubygems/rubygems 7 https://github.com/faucetsdn/ryu 7 https://github.com/apache/activemq 7 https://github.com/smarty-php/smarty 7 https://github.com/DSpace/DSpace 7 https://github.com/magento/magento2 7 https://github.com/FlowiseAI/Flowise 7 https://github.com/MobSF/Mobile-Security-Framework-MobSF 7 https://github.com/parisneo/lollms 7 https://github.com/filebrowser/filebrowser 7 https://github.com/cobbler/cobbler 7 https://github.com/xuxueli/xxl-job 7 https://github.com/bodil/sized-chunks 6 https://github.com/cosmos/cosmos-sdk 6 https://github.com/matrix-org/matrix-js-sdk 6 https://github.com/getkirby/kirby 6 https://github.com/shopware/shopware 6 https://github.com/cilium/cilium 6 https://github.com/pgadmin-org/pgadmin4 6 https://github.com/open-webui/open-webui 6 https://github.com/nilsteampassnet/TeamPass 6 https://github.com/intelliants/subrion 6 https://github.com/aubio/aubio 6 https://github.com/WWBN/AVideo 6 https://github.com/vllm-project/vllm 6 https://github.com/haxtheweb/issues 6 https://github.com/ImageMagick/ImageMagick 6 https://github.com/apollographql/router 6 https://github.com/OpenZeppelin/openzeppelin-contracts 6 https://github.com/containers/podman 6 https://github.com/nautobot/nautobot 6 https://github.com/ls1intum/Ares 6 https://github.com/DrunkenShells/Disclosures 6 https://github.com/dromara/hutool 6 https://github.com/protocolbuffers/protobuf 6 https://github.com/getsentry/sentry 6 https://github.com/kyverno/kyverno 6 https://github.com/sequelize/sequelize 6 https://github.com/Graylog2/graylog2-server 6 https://github.com/quarkusio/quarkus 6 https://github.com/kiwitcms/Kiwi 6 https://github.com/gravitl/netmaker 6 https://github.com/RaspAP/raspap-webgui 6 https://github.com/CVEProject/cvelist 6 https://github.com/rack/rack 6 https://github.com/TYPO3-CMS/core 6 https://github.com/opencast/opencast 6 https://github.com/drupal/core 6 https://github.com/guzzle/guzzle 6 https://github.com/cefsharp/CefSharp 6 https://github.com/froxlor/froxlor 6 https://github.com/mantisbt/mantisbt 6 https://github.com/npm/node-tar 6 https://github.com/goharbor/harbor 6 https://github.com/hyperledger/fabric 6 https://github.com/OpenNMS/opennms 6 https://github.com/phpseclib/phpseclib 6 https://github.com/istio/istio 6 https://github.com/ethyca/fides 6 https://github.com/apache/hadoop 5 https://sourceforge.net/projects/phpmyadmin.sourceforge.net 5 https://github.com/hpcng/singularity 5 https://github.com/BlackFan/client-side-prototype-pollution 5 https://github.com/sebhildebrandt/systeminformation 5 https://github.com/forkcms/forkcms 5 https://github.com/docker/docker 5 https://github.com/minio/minio 5 https://github.com/cloudflare/cfrpki 5 https://github.com/cakephp/cakephp 5 https://github.com/faisalman/ua-parser-js 5 https://github.com/opencart/opencart 5 https://github.com/PrestaShop/PrestaShop 5 https://github.com/hashicorp/go-getter 5 https://github.com/cri-o/cri-o 5 https://github.com/apache/xmlgraphics-batik 5 https://github.com/codeigniter4/CodeIgniter4 5 https://github.com/apache/dolphinscheduler 5 https://github.com/ethereum/go-ethereum 5 https://github.com/pear/Archive_Tar 5 https://github.com/HumanSignal/label-studio 5 https://github.com/zendframework/zendframework 5 https://github.com/bolt/bolt 5 https://github.com/openstack/neutron 5 https://github.com/answerdev/answer 5 https://github.com/yiisoft/yii2 5 https://github.com/langchain-ai/langchain 5 https://github.com/beego/beego 5 https://github.com/zopefoundation/Zope 5 https://github.com/element-hq/synapse 5 https://github.com/Pylons/waitress 5 https://github.com/vantage6/vantage6 5 https://github.com/apache/kylin 5 https://github.com/axios/axios 5 https://github.com/IBAX-io/go-ibax 5