Browse Security Advisories
High Security Advisories for github.com/mattermost/mattermost-plugin-confluence Clear Filters
High
about 7 years ago
Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts
pypi
Plone, plone.app.users
High
about 7 years ago
Plone and Zope2 vulnerable to unauthorized access to restricted attributes
pypi
Plone, Zope2
High
about 7 years ago
Plone and Zope2 do not reseed pseudo-random number generator
pypi
Plone, Zope2
High
about 7 years ago
Kcapifony gem for Ruby places database user passwords on the command line
rubygems
kcapifony
High
about 7 years ago
mime Regular Expression Denial of Service when MIME lookup performed on untrusted user input
npm
mime
High
about 7 years ago
Denial of Service vulnerability with large JSON payloads in fastify
npm
fastify
High
about 7 years ago
Mercurial has Incorrect Permission Assignment for Critical Resource
pypi
mercurial
High
about 7 years ago
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
pypi
gunicorn
High
about 7 years ago
JSNAPy allows unprivileged local users to alter files under the directory
pypi
jsnapy
High
about 7 years ago
Arbitrary code using "crafted image file" approach affecting Pillow
pypi
Pillow
High
about 7 years ago
Jupyter Notebook file bypasses sanitization, executes JavaScript
pypi
notebook
High
over 7 years ago
Electron protocol handler browser vulnerable to Command Injection
npm
electron
High
over 7 years ago
Electron Vulnerable to Code Execution by Re-Enabling Node.js Integration
npm
electron
High
over 7 years ago
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
rubygems
sanitize
High
over 7 years ago
Cap-Strap gem for Ruby places credentials on the useradd command line
rubygems
cap-strap
High
over 7 years ago
AWS Lambda parser is vulnerable to Regular Expression Denial of Service
npm
aws-lambda-multipart-parser
High
over 7 years ago
lynx doesn't properly sanitize user input and exposes database password to unauthorized users
rubygems
lynx
High
over 7 years ago
lawn-login exposes database password to unauthorized users
rubygems
lawn-login
High
over 7 years ago
Samlify vulnerable to Authentication Bypass by allowing tokens to be reused with different usernames
npm
samlify
High
almost 8 years ago
private_address_check contains Incomplete List of Disallowed Inputs
rubygems
private_address_check
High
almost 8 years ago
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
rubygems
gollum-lib, gollum
High
almost 8 years ago
actionpack allows remote attackers to bypass intended access restrictions
rubygems
actionpack
High
almost 8 years ago
activesupport in Rails vulnerable to incorrect data conversion
rubygems
activesupport
Filter by Severity
Filter by Ecosystem
maven
2,228
pypi
1,763
npm
1,679
packagist
1,407
go
1,010
nuget
874
cargo
392
rubygems
300
actions
19
swift
18
hex
11
pub
5
Filter by Package
Microsoft.ChakraCore
234
tensorflow
120
tensorflow-gpu
113
tensorflow-cpu
112
magento/community-edition
79
moodle/moodle
61
org.jenkins-ci.main:jenkins-core
56
Django
46
com.fasterxml.jackson.core:jackson-databind
43
dolibarr/dolibarr
35
typo3/cms
34
Plone
33
librenms/librenms
32
org.apache.tomcat:tomcat
31
github.com/rancher/rancher
31
mlflow
30
pimcore/pimcore
30
drupal/core
30
salt
29
apache-airflow
29
phpmyadmin/phpmyadmin
28
drupal/drupal
28
typo3/cms-core
27
microweber/microweber
27
nokogiri
26
ansible
24
com.liferay.portal:release.portal.bom
23
opencv-python
23
org.apache.struts:struts2-core
23
opencv-contrib-python
22
com.thoughtworks.xstream:xstream
22
com.jfinal:jfinal
21
matrix-synapse
20
thorsten/phpmyfaq
20
symfony/symfony
20
org.jenkins-ci.plugins:script-security
19
com.liferay.portal:release.dxp.bom
19
magento/project-community-edition
18
pillow
18
github.com/hashicorp/vault
18
Pillow
18
pocketmine/pocketmine-mp
18
rdiffweb
17
io.undertow:undertow-core
17
github.com/grafana/grafana
17
gradio
17
parse-server
16
org.apache.tomcat.embed:tomcat-embed-core
16
getgrav/grav
16
openssl-src
16
Microsoft.AspNetCore.App.Runtime.win-x86
15
nilsteampassnet/teampass
15
org.xwiki.platform:xwiki-platform-oldcore
15
github.com/hashicorp/consul
15
open-webui
15
Microsoft.AspNetCore.App.Runtime.win-x64
15
keystone
15
vyper
14
net.mingsoft:ms-mcms
14
centreon/centreon
14
org.keycloak:keycloak-core
14
shopware/platform
14
craftcms/cms
14
github.com/usememos/memos
14
org.apache.solr:solr-core
13
shopware/core
13
golang.org/x/net
13
rubygems-update
13
org.keycloak:keycloak-services
13
Microsoft.AspNetCore.App.Runtime.win-arm
13
apache-superset
13
silverstripe/framework
13
Microsoft.NetCore.App.Runtime.win-arm
13
mindsdb
13
django
13
Microsoft.AspNetCore.App.Runtime.win-arm64
13
Microsoft.AspNetCore.App.Runtime.linux-arm
12
Microsoft.NetCore.App.Runtime.win-arm64
12
mautic/core
12
activerecord
12
Microsoft.NetCore.App.Runtime.win-x86
12
Microsoft.AspNetCore.App.Runtime.linux-arm64
12
org.apache.openmeetings:openmeetings-parent
12
Microsoft.AspNetCore.App.Runtime.linux-x64
12
Microsoft.NetCore.App.Runtime.win-x64
12
baserproject/basercms
12
electron
12
Microsoft.AspNetCore.App.Runtime.linux-musl-x64
11
github.com/zitadel/zitadel
11
phpoffice/phpspreadsheet
11
directus
11
intelliants/subrion
11
froxlor/froxlor
11
github.com/hashicorp/nomad
11
org.keycloak:keycloak-parent
11
cockpit-hq/cockpit
11
next
11
github.com/argoproj/argo-cd
11
Microsoft.AspNetCore.App.Runtime.osx-x64
11
gogs.io/gogs
11
org.springframework.security:spring-security-core
11
github.com/ollama/ollama
10
nova
10
github.com/argoproj/argo-cd/v2
10
snipe/snipe-it
10
funadmin/funadmin
10
surrealdb
10
deno
10
k8s.io/kubernetes
10
github.com/traefik/traefik/v2
10
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
10
github.com/nats-io/nats-server/v2
10
actionpack
10
laravel/framework
10
openmage/magento-lts
10
org.cloudfoundry.identity:cloudfoundry-identity-server
9
lollms
9
github.com/ethereum/go-ethereum
9
org.apache.hadoop:hadoop-main
9
aim
9
litellm
9
h2o
9
org.apache.tomcat:tomcat-catalina
9
rack
9
org.bouncycastle:bcprov-jdk14
9
cobbler
9
rusqlite
9
neutron
9
org.apache.geode:geode-core
9
flowise
9
mercurial
9
org.apache.nifi:nifi
9
org.apache.struts.xwork:xwork-core
9
ckb
9
github.com/sylabs/singularity
8
org.bouncycastle:bcprov-jdk15
8
Microsoft.NETCore.App.Runtime.win-x64
8
Microsoft.NetCore.App.Runtime.osx-arm64
8
Microsoft.NETCore.App.Runtime.win-arm64
8
org.springframework:spring-core
8
Microsoft.NetCore.App.Runtime.linux-x64
8
Microsoft.NetCore.App.Runtime.linux-arm
8
Microsoft.NETCore.App.Runtime.win-x86
8
phpbb/phpbb
8
zendframework/zendframework1
8
Microsoft.NetCore.App.Runtime.osx-x64
8
october/system
8
smarty/smarty
8
composer/composer
8
github.com/mattermost/mattermost/server/v8
8
moin
8
Microsoft.NetCore.App.Runtime.linux-musl-arm
8
Microsoft.NetCore.App.Runtime.linux-arm64
8
yeswiki/yeswiki
8
github.com/docker/docker
8
Microsoft.NetCore.App.Runtime.linux-musl-x64
8
cryptography
8
Microsoft.NetCore.App.Runtime.linux-musl-arm64
8
@anthropic-ai/claude-code
8
org.craftercms:crafter-studio
8
ai.h2o:h2o-core
8
org.eclipse.jetty:jetty-server
8
pyload-ng
8
org.apache.inlong:manager-pojo
7
phpmailer/phpmailer
7
codeigniter4/framework
7
@strapi/strapi
7
tar
7
org.elasticsearch:elasticsearch
7
OPCFoundation.NetStandard.Opc.Ua.Core
7
strapi
7
org.apache.tomcat:tomcat-coyote
7
org.jenkins-ci.plugins.workflow:workflow-cps
7
org.apache.dolphinscheduler:dolphinscheduler
7
ryu
7
k8s.io/ingress-nginx
7
opencv-python-headless
7
DotNetNuke.Core
7
cn.hutool:hutool-core
7
golang.org/x/crypto
7
mantisbt/mantisbt
7
com.xuxueli:xxl-job
7
symfony/security
7
Microsoft.AspNetCore.App.Runtime.linux-musl-arm
7
apollo-router
7
contao/core-bundle
7
org.jenkins-ci.plugins.workflow:workflow-cps-global-lib
7
magento/core
7
cakephp/cakephp
7
org.apache.kylin:kylin
7
symfony/security-http
7
zendframework/zendframework
7
istio.io/istio
6
sized-chunks
6
org.apache.tika:tika-core
6
github.com/kyverno/kyverno
6
mobsf
6
mediawiki/core
6
Microsoft.NETCore.App
6
github.com/gravitl/netmaker
6
Filter by Repository
https://github.com/chakra-core/ChakraCore
204
https://github.com/tensorflow/tensorflow
122
https://github.com/xwiki/xwiki-platform
64
https://github.com/django/django
51
https://github.com/FasterXML/jackson-databind
44
https://github.com/jenkinsci/jenkins
43
https://github.com/apache/tomcat
39
https://github.com/apache/airflow
39
https://github.com/python-pillow/Pillow
35
https://github.com/moodle/moodle
33
https://github.com/keycloak/keycloak
31
https://github.com/dotnet/runtime
28
https://github.com/pimcore/pimcore
28
https://github.com/librenms/librenms
28
https://github.com/rancher/rancher
27
https://github.com/opencv/opencv
25
https://github.com/microweber/microweber
25
https://github.com/symfony/symfony
23
https://github.com/x-stream/xstream
22
https://github.com/apache/struts
22
https://github.com/Dolibarr/dolibarr
21
https://github.com/sparklemotion/nokogiri
21
https://github.com/ansible/ansible
19
https://github.com/spring-projects/spring-framework
19
https://github.com/pmmp/PocketMine-MP
18
https://github.com/TYPO3/typo3
18
https://github.com/thorsten/phpmyfaq
18
https://github.com/ikus060/rdiffweb
17
https://github.com/plone/Products.CMFPlone
16
https://github.com/parse-community/parse-server
16
https://github.com/gradio-app/gradio
16
https://github.com/kubernetes/kubernetes
15
https://github.com/mlflow/mlflow
15
https://github.com/rails/rails
15
https://github.com/apache/inlong
15
https://github.com/github/advisory-database
15
https://github.com/zitadel/zitadel
14
https://github.com/vyperlang/vyper
14
https://github.com/argoproj/argo-cd
14
https://github.com/usememos/memos
14
https://github.com/jenkinsci/script-security-plugin
14
https://github.com/grafana/grafana
14
https://github.com/getgrav/grav
14
https://github.com/openstack/keystone
14
https://github.com/undertow-io/undertow
13
https://github.com/matrix-org/synapse
13
https://github.com/mautic/mautic
13
https://github.com/saltstack/salt
13
https://github.com/mindsdb/mindsdb
13
https://github.com/directus/directus
12
https://github.com/PHPOffice/PhpSpreadsheet
12
https://github.com/electron/electron
12
https://github.com/liferay/liferay-portal
12
https://github.com/hashicorp/consul
12
https://github.com/apache/nifi
11
https://github.com/silverstripe/silverstripe-framework
11
https://github.com/denoland/deno
10
https://github.com/go-gitea/gitea
10
https://github.com/run-llama/llama_index
10
https://github.com/funadmin/funadmin
10
https://github.com/centreon/centreon
10
https://github.com/surrealdb/surrealdb
10
https://github.com/octobercms/october
10
https://github.com/strapi/strapi
10
https://github.com/golang/go
10
https://github.com/OpenMage/magento-lts
10
https://github.com/dotnet/aspnetcore
10
https://github.com/laravel/framework
9
https://github.com/netty/netty
9
https://github.com/traefik/traefik
9
https://github.com/snipe/snipe-it
9
https://github.com/vercel/next.js
9
https://github.com/apache/camel
9
https://github.com/hashicorp/vault
9
https://github.com/cloudfoundry/uaa
9
https://github.com/apache/cxf
9
https://github.com/geoserver/geoserver
9
https://github.com/nilsteampassnet/teampass
9
https://github.com/cui2shark/cms
9
https://github.com/spring-projects/spring-security
9
https://github.com/rusqlite/rusqlite
9
https://github.com/nervosnetwork/ckb
9
https://github.com/openstack/nova
9
https://github.com/OPCFoundation/UA-.NETStandard
8
https://github.com/cockpit-hq/cockpit
8
https://github.com/pyca/cryptography
8
https://github.com/anthropics/claude-code
8
https://github.com/shopware/platform
8
https://github.com/craftcms/cms
8
https://github.com/OpenRefine/OpenRefine
8
https://github.com/TYPO3/TYPO3.CMS
8
https://github.com/apache/kylin
8
https://github.com/h2oai/h2o-3
8
https://github.com/backstage/backstage
8
https://github.com/dnnsoftware/Dnn.Platform
8
https://github.com/phpmyadmin/phpmyadmin
8
https://github.com/gogs/gogs
8
https://github.com/nats-io/nats-server
8
https://github.com/pyload/pyload
8
https://github.com/PaddlePaddle/Paddle
8
https://github.com/bcgit/bc-java
8
https://github.com/PHPMailer/PHPMailer
7
https://github.com/FlowiseAI/Flowise
7
https://github.com/apache/activemq
7
https://github.com/faucetsdn/ryu
7
https://github.com/contao/contao
7
https://github.com/smarty-php/smarty
7
https://github.com/DSpace/DSpace
7
https://github.com/rubygems/rubygems
7
https://github.com/filebrowser/filebrowser
7
https://github.com/MobSF/Mobile-Security-Framework-MobSF
7
https://github.com/xuxueli/xxl-job
7
https://github.com/composer/composer
7
https://github.com/parisneo/lollms
7
https://github.com/cobbler/cobbler
7
https://github.com/eclipse/jetty.project
7
https://github.com/magento/magento2
7
https://github.com/YesWiki/yeswiki
7
https://github.com/matrix-org/matrix-js-sdk
6
https://github.com/RaspAP/raspap-webgui
6
https://github.com/guzzle/guzzle
6
https://github.com/open-webui/open-webui
6
https://github.com/CVEProject/cvelist
6
https://github.com/vllm-project/vllm
6
https://github.com/hyperledger/fabric
6
https://github.com/getsentry/sentry
6
https://github.com/containers/podman
6
https://github.com/drupal/core
6
https://github.com/OpenZeppelin/openzeppelin-contracts
6
https://github.com/ethyca/fides
6
https://github.com/ImageMagick/ImageMagick
6
https://github.com/phpseclib/phpseclib
6
https://github.com/istio/istio
6
https://github.com/intelliants/subrion
6
https://github.com/npm/node-tar
6
https://github.com/cilium/cilium
6
https://github.com/OpenNMS/opennms
6
https://github.com/mantisbt/mantisbt
6
https://github.com/apollographql/router
6
https://github.com/TYPO3-CMS/core
6
https://github.com/nautobot/nautobot
6
https://github.com/pgadmin-org/pgadmin4
6
https://github.com/DrunkenShells/Disclosures
6
https://github.com/cefsharp/CefSharp
6
https://github.com/shopware/shopware
6
https://github.com/kyverno/kyverno
6
https://github.com/dromara/hutool
6
https://github.com/nilsteampassnet/TeamPass
6
https://github.com/opencast/opencast
6
https://github.com/aubio/aubio
6
https://github.com/ls1intum/Ares
6
https://github.com/quarkusio/quarkus
6
https://github.com/haxtheweb/issues
6
https://github.com/froxlor/froxlor
6
https://github.com/goharbor/harbor
6
https://github.com/rack/rack
6
https://github.com/gravitl/netmaker
6
https://github.com/Graylog2/graylog2-server
6
https://github.com/getkirby/kirby
6
https://github.com/cosmos/cosmos-sdk
6
https://github.com/bodil/sized-chunks
6
https://github.com/sequelize/sequelize
6
https://github.com/kiwitcms/Kiwi
6
https://github.com/WWBN/AVideo
6
https://github.com/protocolbuffers/protobuf
6
https://github.com/element-hq/synapse
5
https://github.com/apache/dolphinscheduler
5
https://github.com/langchain-ai/langchain
5
https://github.com/answerdev/answer
5
https://github.com/cakephp/cakephp
5
https://sourceforge.net/projects/phpmyadmin.sourceforge.net
5
https://github.com/bolt/bolt
5
https://github.com/cloudflare/cfrpki
5
https://github.com/HumanSignal/label-studio
5
https://github.com/docker/docker
5
https://github.com/IBAX-io/go-ibax
5
https://github.com/sebhildebrandt/systeminformation
5
https://github.com/codeigniter4/CodeIgniter4
5
https://github.com/Pylons/waitress
5
https://github.com/minio/minio
5
https://github.com/pear/Archive_Tar
5
https://github.com/zendframework/zendframework
5
https://github.com/hashicorp/go-getter
5
https://github.com/BlackFan/client-side-prototype-pollution
5
https://github.com/vantage6/vantage6
5
https://github.com/opencart/opencart
5
https://github.com/cri-o/cri-o
5
https://github.com/openstack/neutron
5
https://github.com/PrestaShop/PrestaShop
5
https://github.com/apache/xmlgraphics-batik
5
https://github.com/faisalman/ua-parser-js
5
https://github.com/ethereum/go-ethereum
5
https://github.com/yiisoft/yii2
5
https://github.com/forkcms/forkcms
5
https://github.com/zopefoundation/Zope
5
https://github.com/beego/beego
5
https://github.com/apache/hadoop
5
https://github.com/hpcng/singularity
5
https://github.com/axios/axios
5