Browse Security Advisories
Security Advisories for nova Clear Filters
High
about 5 hours ago
Dolibarr vulnerable to RCE via the computed field parameter
packagist
dolibarr/dolibarr
Low
about 5 hours ago
Auth0 Symfony SDK Does Not Properly Handle File Types in Bulk User Import
packagist
auth0/symfony
Low
about 5 hours ago
Auth0 Wordpress plugin Does Not Properly Handle File Types in Bulk User Import
packagist
auth0/wordpress
Low
about 5 hours ago
laravel-auth0 SDK Does Not Properly Handle File Types in Bulk User Import
packagist
auth0/login
Low
about 5 hours ago
auth0-PHP SDK Does Not Properly Handle File Types in Bulk User Import
packagist
auth0/auth0-php
Critical
about 5 hours ago
risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`
cargo
risc0-zkvm, risc0-aggregation, risc0-zkos-v1compat, risc0-zkvm-platform
High
about 11 hours ago
@plone/volto vulnerable to potential DoS by invoking specific URL by anonymous user
npm
@plone/volto
Moderate
about 11 hours ago
SPDK is vulnerable to buffer overflow in the NVMe-oF target component
pypi
spdk
Critical
about 14 hours ago
Apache Pyfory python is vulnerable to deserialization of untrusted data
pypi
pyfury, pyfory
Moderate
1 day ago
Liferay Portal Vulnerable to XSS in Web Content translation
maven
com.liferay.portal:release.portal.bom
Moderate
1 day ago
Liferay Portal Vulnerable to IDOR via audit events
maven
com.liferay:com.liferay.portal.security.audit.storage.service, com.liferay:com.liferay.portal.security.audit.web
High
1 day ago
github.com/MANTRA-Chain/mantrachain/x/tokenfactory tx gas limit is not enforced in send hooks
go
github.com/MANTRA-Chain/mantrachain, github.com/MANTRA-Chain/mantrachain/v2, github.com/MANTRA-Chain/mantrachain/v3, github.com/MANTRA-Chain/mantrachain/v4
High
1 day ago
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook
go
github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v2
Moderate
1 day ago
FormCMS has an improper access control vulnerability in the /api/schemas/history/[schemaId] endpoint
nuget
FormCMS
High
1 day ago
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload
go
github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd
High
1 day ago
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload
go
github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd
Moderate
1 day ago
Repository Credentials Race Condition Crashes Argo CD Server
go
github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v2
High
1 day ago
figma-developer-mcp vulnerable to command injection in get_figma_data tool
npm
figma-developer-mcp
Moderate
2 days ago
Liferay Portal vulnerable to cross-site scripting in the web content template
maven
com.liferay:com.liferay.journal.web, com.liferay.portal:release.portal.bom
Moderate
2 days ago
Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServlet
maven
com.liferay.portal:com.liferay.portal.impl, com.liferay.portal:release.portal.bom
Moderate
2 days ago
Liferay Portal vulnerable to cross-site scripting in the Calendar widget
maven
com.liferay:com.liferay.calendar.web, com.liferay.portal:release.portal.bom
Moderate
2 days ago
Liferay Portal vulnerable to cross-site scripting in the related asset selector
maven
com.liferay:com.liferay.item.selector.web
Moderate
2 days ago
Liferay Portal vulnerable to cross-site scripting in the Calendar widget
maven
com.liferay:com.liferay.calendar.web
Moderate
2 days ago
Liferay Portal vulnerable to reflected cross-site scripting on the page configuration page
maven
com.liferay:com.liferay.product.navigation.control.menu.web
Moderate
2 days ago
Liferay Portal vulnerable to reflected cross-site scripting via the `redirect` parameter
maven
com.liferay.portal:release.portal.bom
Moderate
2 days ago
Coder AgentAPI exposed user chat history via a DNS rebinding attack
go
github.com/coder/agentapi
High
2 days ago
go-f3 module vulnerable to integer overflow leading to panic
go
github.com/filecoin-project/go-f3
Moderate
2 days ago
go-f3 Vulnerable to Cached Justification Verification Bypass
go
github.com/filecoin-project/go-f3
Critical
2 days ago
j178/prek-action vulnerable to arbitrary code injection in composite action
actions
j178/prek-action
Moderate
2 days ago
mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders
pypi
mkdocs-include-markdown-plugin
High
2 days ago
go-mail has insufficient address encoding when passing mail addresses to the SMTP client
go
github.com/wneessen/go-mail
Moderate
5 days ago
github.com/nyaruka/phonenumbers Vulnerable to Improper Validation of Syntactic Correctness of Input
go
github.com/nyaruka/phonenumbers
Moderate
5 days ago
algoliasearch-helper is vulnerable to Prototype Pollution in _merge()
npm
algoliasearch-helper
Moderate
5 days ago
OpenMLS improper persistence of the secret tree during message processing
cargo
openmls
Low
5 days ago
kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace
go
github.com/kcp-dev/kcp
High
5 days ago
Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass
npm
@apollo/explorer, @apollo/sandbox
Moderate
5 days ago
express-xss-sanitizer has an unbounded recursion depth
npm
express-xss-sanitizer
Critical
6 days ago
get-jwks: poisoned JWKS cache allows post-fetch issuer validation bypass
npm
get-jwks
Low
6 days ago
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
pypi
jupyterlab
High
6 days ago
Rancher update on users can deny the service to the admin
go
github.com/rancher/rancher
High
6 days ago
Rancher CLI SAML authentication is vulnerable to phishing attacks
go
github.com/rancher/rancher
Moderate
6 days ago
Rancher sends sensitive information to external services through the `/meta/proxy` endpoint
go
github.com/rancher/rancher
High
6 days ago
Argument injection vulnerability in SonarQube Scan Action
actions
SonarSource/sonarqube-scan-action
Moderate
6 days ago
Apache Airflow: Connection sensitive details exposed to users with READ permissions
pypi
apache-airflow
High
6 days ago
Hutool allows remote code execution (RCE) via the QLExpressEngine class
maven
cn.hutool:hutool-extra
Moderate
6 days ago
Liferay Portal and DXP vulnerable to a memory leak
maven
com.liferay:com.liferay.portal.vulcan.impl
High
6 days ago
Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters
rubygems
rack
Critical
6 days ago
Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning
go
github.com/gardener/gardener-extension-provider-openstack, github.com/gardener/gardener-extension-provider-azure, github.com/gardener/gardener-extension-provider-gcp, github.com/gardener/gardener-extension-provider-aws
Moderate
7 days ago
json-schema-editor-visual vulnerable to prototype pollution
npm
json-schema-editor-visual
Low
7 days ago
web3-core-subscriptions has a Prototype Pollution vulnerability
npm
web3-core-subscriptions
High
7 days ago
Star Citizen EmbedVideo Extension Stored XSS through wikitext caused by usage of non-reserved data attributes
packagist
starcitizenwiki/embedvideo
Moderate
7 days ago
Mastra Docs MCP Server `@mastra/mcp-docs-server` Leads to Information Exposure
npm
@mastra/mcp-docs-server
High
7 days ago
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
npm
@anthropic-ai/claude-code
High
7 days ago
tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
npm
tar-fs
Moderate
7 days ago
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
pypi
pip
Moderate
8 days ago
Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands
maven
org.apache.zookeeper:zookeeper
Critical
8 days ago
Apache IoTDB: Deserialization of untrusted Data
maven
org.apache.iotdb:iotdb-confignode
Filter by Severity
Filter by Ecosystem
maven
6,742
packagist
5,241
pypi
4,834
npm
4,308
go
2,862
nuget
1,593
cargo
1,088
rubygems
901
actions
39
hex
38
swift
33
pub
9
Filter by Package
tensorflow
430
moodle/moodle
417
tensorflow-cpu
408
tensorflow-gpu
403
magento/community-edition
265
Microsoft.ChakraCore
247
org.jenkins-ci.main:jenkins-core
241
typo3/cms
170
com.liferay.portal:release.portal.bom
147
org.apache.tomcat:tomcat
131
github.com/mattermost/mattermost/server/v8
128
pimcore/pimcore
120
dolibarr/dolibarr
117
com.liferay.portal:release.dxp.bom
116
typo3/cms-core
108
Django
108
phpmyadmin/phpmyadmin
107
microweber/microweber
103
drupal/core
98
magento/project-community-edition
97
silverstripe/framework
91
apache-airflow
86
librenms/librenms
83
thorsten/phpmyfaq
73
Plone
71
drupal/drupal
70
com.fasterxml.jackson.core:jackson-databind
69
github.com/usememos/memos
68
concrete5/concrete5
67
salt
65
ansible
63
apache-superset
61
actionpack
61
symfony/symfony
59
shopware/platform
58
org.apache.struts:struts2-core
56
github.com/grafana/grafana
56
mlflow
53
craftcms/cms
53
org.keycloak:keycloak-core
50
github.com/hashicorp/vault
49
github.com/rancher/rancher
48
mautic/core
48
nova
48
baserproject/basercms
47
nokogiri
46
shopware/core
46
vyper
44
gradio
44
org.xwiki.platform:xwiki-platform-oldcore
43
nilsteampassnet/teampass
42
org.keycloak:keycloak-services
42
rdiffweb
42
github.com/mattermost/mattermost-server
42
matrix-synapse
42
k8s.io/kubernetes
41
showdoc/showdoc
41
mantisbt/mantisbt
41
org.elasticsearch:elasticsearch
41
intelliants/subrion
40
froxlor/froxlor
40
directus
39
picklescan
39
snipe/snipe-it
38
github.com/mattermost/mattermost-server/v6
37
com.thoughtworks.xstream:xstream
37
net.mingsoft:ms-mcms
36
org.apache.tomcat.embed:tomcat-embed-core
36
com.jfinal:jfinal
36
github.com/argoproj/argo-cd/v2
36
io.undertow:undertow-core
35
moin
35
github.com/answerdev/answer
34
org.jenkins-ci.plugins:script-security
33
parse-server
33
gogs.io/gogs
32
zendframework/zendframework1
32
shopware/shopware
31
opencv-contrib-python
31
github.com/hashicorp/nomad
31
github.com/cilium/cilium
31
keystone
31
opencv-python
31
rack
30
github.com/argoproj/argo-cd
30
getgrav/grav
30
contao/core-bundle
29
github.com/hashicorp/consul
29
next
29
org.apache.solr:solr-core
28
mediawiki/core
28
electron
28
pillow
28
github.com/docker/docker
28
Pillow
28
DotNetNuke.Core
27
django
27
plone
27
org.springframework.security:spring-security-core
27
centreon/centreon
27
org.opencms:opencms-core
27
prestashop/prestashop
27
github.com/traefik/traefik/v2
25
openssl-src
25
org.eclipse.jetty:jetty-server
25
rubygems-update
25
pocketmine/pocketmine-mp
25
vllm
25
open-webui
25
org.keycloak:keycloak-parent
24
getkirby/cms
24
flowise
24
surrealdb
24
pyload-ng
23
remdex/livehelperchat
23
puppet
23
org.apache.tomcat:tomcat-catalina
23
grumpydictator/firefly-iii
23
simplesamlphp/simplesamlphp
23
laravel/framework
23
activerecord
22
zendframework/zendframework
22
ckb
22
tribalsystems/zenario
22
org.apache.openmeetings:openmeetings-parent
22
@openzeppelin/contracts-upgradeable
21
@openzeppelin/contracts
21
github.com/goharbor/harbor
21
glance
21
org.apache.nifi:nifi
21
org.bouncycastle:bcprov-jdk15on
20
cockpit-hq/cockpit
20
funadmin/funadmin
20
code.gitea.io/gitea
20
org.xwiki.platform:xwiki-platform-web-templates
20
aim
20
github.com/ethereum/go-ethereum
20
ethyca-fides
20
org.cloudfoundry.identity:cloudfoundry-identity-server
20
Microsoft.AspNetCore.App.Runtime.win-x64
19
wasmtime
19
contao/contao
19
Microsoft.AspNetCore.App.Runtime.win-x86
19
typo3/cms-backend
19
deno
19
phpoffice/phpspreadsheet
19
topthink/framework
19
neutron
19
github.com/zitadel/zitadel
19
helm.sh/helm/v3
19
transformers
19
com.vaadin:vaadin-bom
18
cobbler
18
mindsdb
18
org.apache.jspwiki:jspwiki-main
18
mercurial
18
org.springframework:spring-core
18
genix/cms
18
forkcms/forkcms
18
langchain
18
OctoPrint
17
calibreweb
17
github.com/traefik/traefik/v3
17
org.apache.tomcat:tomcat-coyote
17
opencart/opencart
17
golang.org/x/net
17
notebook
17
github.com/openfga/openfga
17
cryptography
17
yetiforce/yetiforce-crm
17
Microsoft.AspNetCore.App.Runtime.win-arm
17
ezsystems/ezpublish-kernel
17
openmage/magento-lts
17
org.apache.geode:geode-core
17
francoisjacquet/rosariosis
17
org.apache.inlong:manager-pojo
17
cakephp/cakephp
17
org.apache.activemq:activemq-client
16
Microsoft.AspNetCore.App.Runtime.linux-x64
16
lollms
16
paddlepaddle
16
Microsoft.AspNetCore.App.Runtime.linux-arm
16
ghost
16
rusqlite
16
PaddlePaddle
16
tinymce
16
org.apache.ranger:ranger
16
org.apache.dubbo:dubbo
16
phpbb/phpbb
16
Microsoft.AspNetCore.App.Runtime.win-arm64
16
sequelize
16
Microsoft.NetCore.App.Runtime.win-arm
16
october/system
16
vite
15
aiohttp
15
github.com/nats-io/nats-server/v2
15
smarty/smarty
15
ckeditor4
15
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
15
pimcore/admin-ui-classic-bundle
15
Filter by Repository
https://github.com/tensorflow/tensorflow
433
https://github.com/moodle/moodle
243
https://github.com/xwiki/xwiki-platform
221
https://github.com/chakra-core/ChakraCore
214
https://github.com/jenkinsci/jenkins
178
https://github.com/liferay/liferay-portal
139
https://github.com/django/django
119
https://github.com/pimcore/pimcore
116
https://github.com/apache/tomcat
114
https://github.com/apache/airflow
104
https://github.com/TYPO3/typo3
94
https://github.com/microweber/microweber
90
https://github.com/keycloak/keycloak
86
https://github.com/librenms/librenms
74
https://github.com/FasterXML/jackson-databind
70
https://github.com/rails/rails
70
https://github.com/thorsten/phpmyfaq
69
https://github.com/usememos/memos
68
https://github.com/silverstripe/silverstripe-framework
68
https://github.com/kubernetes/kubernetes
66
https://github.com/symfony/symfony
64
https://github.com/Dolibarr/dolibarr
60
https://github.com/ansible/ansible
59
https://github.com/python-pillow/Pillow
52
https://github.com/spring-projects/spring-framework
51
https://github.com/argoproj/argo-cd
50
https://github.com/grafana/grafana
47
https://github.com/apache/struts
47
https://github.com/mautic/mautic
46
https://github.com/phpmyadmin/phpmyadmin
45
https://github.com/vyperlang/vyper
44
https://github.com/concretecms/concretecms
44
https://github.com/rancher/rancher
44
https://github.com/shopware/platform
43
https://github.com/saltstack/salt
42
https://github.com/ikus060/rdiffweb
42
https://github.com/craftcms/cms
41
https://github.com/directus/directus
41
https://github.com/mattermost/mattermost
39
https://github.com/star7th/showdoc
39
https://github.com/mmaitre314/picklescan
39
https://github.com/magento/magento2
38
https://github.com/openstack/nova
38
https://github.com/mantisbt/mantisbt
38
https://github.com/gradio-app/gradio
38
https://github.com/plone/Products.CMFPlone
37
https://github.com/x-stream/xstream
37
https://github.com/dotnet/runtime
37
https://github.com/octobercms/october
36
https://github.com/shopware/shopware
35
https://github.com/sparklemotion/nokogiri
35
https://github.com/mlflow/mlflow
35
https://github.com/umbraco/Umbraco-CMS
35
https://github.com/answerdev/answer
34
https://github.com/apache/activemq
34
https://github.com/parse-community/parse-server
33
https://github.com/opencv/opencv
32
https://github.com/matrix-org/synapse
32
https://github.com/go-gitea/gitea
32
https://github.com/cilium/cilium
31
https://github.com/PaddlePaddle/Paddle
31
https://github.com/apache/inlong
31
https://github.com/contao/contao
30
https://github.com/snipe/snipe-it
30
https://github.com/CVEProject/cvelist
28
https://github.com/openstack/keystone
28
https://github.com/gogs/gogs
28
https://github.com/electron/electron
28
https://github.com/geoserver/geoserver
26
https://github.com/froxlor/froxlor
26
https://github.com/netty/netty
26
https://github.com/apache/nifi
26
https://github.com/baserproject/basercms
26
https://github.com/github/advisory-database
26
https://github.com/strapi/strapi
25
https://github.com/vercel/next.js
25
https://github.com/pmmp/PocketMine-MP
25
https://github.com/traefik/traefik
25
https://github.com/surrealdb/surrealdb
25
https://github.com/bcgit/bc-java
24
https://github.com/getgrav/grav
24
https://github.com/apache/cxf
24
https://github.com/rack/rack
24
https://github.com/langchain-ai/langchain
24
https://github.com/firefly-iii/firefly-iii
23
https://github.com/nilsteampassnet/TeamPass
23
https://github.com/TYPO3/TYPO3.CMS
23
https://github.com/moby/moby
23
https://github.com/livehelperchat/livehelperchat
23
https://github.com/eclipse/jetty.project
23
https://github.com/run-llama/llama_index
23
https://github.com/PrestaShop/PrestaShop
23
https://github.com/pyload/pyload
23
https://github.com/jenkinsci/script-security-plugin
22
https://github.com/hashicorp/consul
22
https://github.com/bytecodealliance/wasmtime
22
https://github.com/denoland/deno
22
https://github.com/vllm-project/vllm
22
https://github.com/getkirby/kirby
22
https://github.com/zitadel/zitadel
22
https://github.com/helm/helm
22
https://github.com/nervosnetwork/ckb
22
https://github.com/PHPOffice/PhpSpreadsheet
22
https://github.com/OpenZeppelin/openzeppelin-contracts
21
https://github.com/goharbor/harbor
21
https://github.com/undertow-io/undertow
21
https://github.com/laravel/framework
21
https://github.com/FlowiseAI/Flowise
20
https://github.com/OpenNMS/opennms
20
https://github.com/funadmin/funadmin
20
https://github.com/dnnsoftware/Dnn.Platform
20
https://github.com/simplesamlphp/simplesamlphp
20
https://github.com/ethyca/fides
20
https://github.com/jeecgboot/jeecg-boot
20
https://github.com/TYPO3-CMS/core
19
https://github.com/intelliants/subrion
19
https://github.com/backstage/backstage
19
https://github.com/nilsteampassnet/teampass
19
https://github.com/hashicorp/vault
19
https://github.com/alkacon/opencms-core
19
https://github.com/opencast/opencast
19
https://github.com/cloudfoundry/uaa
19
https://github.com/huggingface/transformers
19
https://github.com/vaadin/platform
18
https://github.com/apache/camel
18
https://github.com/rubygems/rubygems
18
https://github.com/liufee/cms
17
https://github.com/ethereum/go-ethereum
17
https://github.com/openfga/openfga
17
https://github.com/OpenMage/magento-lts
17
https://github.com/mindsdb/mindsdb
17
https://github.com/vantage6/vantage6
17
https://github.com/containerd/containerd
17
https://github.com/forkcms/forkcms
16
https://github.com/sequelize/sequelize
16
https://github.com/rusqlite/rusqlite
16
https://github.com/pyca/cryptography
16
https://github.com/hashicorp/nomad
16
https://github.com/yetiforcecompany/yetiforcecrm
16
https://github.com/etcd-io/etcd
16
https://github.com/quarkusio/quarkus
16
https://github.com/tinymce/tinymce
16
https://github.com/centreon/centreon
15
https://github.com/nodejs/undici
15
https://github.com/dotnet/aspnetcore
15
https://github.com/aio-libs/aiohttp
15
https://github.com/decidim/decidim
15
https://github.com/cobbler/cobbler
15
https://github.com/zendframework/zendframework
15
https://github.com/containers/podman
15
https://github.com/drupal/core
15
https://github.com/ckeditor/ckeditor4
15
https://github.com/puppetlabs/puppet
15
https://github.com/OPCFoundation/UA-.NETStandard
15
https://github.com/PHPMailer/PHPMailer
15
https://github.com/xuxueli/xxl-job
15
https://github.com/MobSF/Mobile-Security-Framework-MobSF
15
https://github.com/dompdf/dompdf
15
https://github.com/vitejs/vite
15
https://github.com/apache/superset
14
https://github.com/golang/go
14
https://github.com/urllib3/urllib3
14
https://github.com/thorsten/phpMyFAQ
14
https://github.com/pimcore/admin-ui-classic-bundle
14
https://github.com/twisted/twisted
14
https://github.com/dpgaspar/Flask-AppBuilder
14
https://github.com/apache/zeppelin
14
https://github.com/Graylog2/graylog2-server
14
https://github.com/cockpit-hq/cockpit
14
https://github.com/cosmos/cosmos-sdk
14
https://github.com/TryGhost/Ghost
14
https://github.com/apache/kylin
14
https://github.com/spring-projects/spring-security
14
https://github.com/rails/rails-html-sanitizer
14
https://github.com/janeczku/calibre-web
14
https://github.com/publify/publify
14
https://github.com/pgadmin-org/pgadmin4
14
https://github.com/ming-soft/MCMS
13
https://github.com/dromara/hutool
13
https://github.com/1Panel-dev/1Panel
13
https://github.com/modoboa/modoboa
13
https://github.com/apache/dolphinscheduler
13
https://github.com/laurent22/joplin
13
https://github.com/OpenRefine/OpenRefine
13
https://github.com/swagger-api/swagger-ui
13
https://github.com/opencontainers/runc
13
https://github.com/smarty-php/smarty
12
https://github.com/openstack/glance
12
https://github.com/nautobot/nautobot
12
https://github.com/OctoPrint/OctoPrint
12
https://github.com/matrix-org/matrix-js-sdk
12
https://github.com/centreon/centreon-archived
12
https://github.com/igniterealtime/Openfire
12
https://github.com/modxcms/revolution
12
https://github.com/DSpace/DSpace
12
https://github.com/yiisoft/yii2
12
https://github.com/puma/puma
12
https://github.com/ImageMagick/ImageMagick
12
https://github.com/YesWiki/yeswiki
12