An open API service providing security vulnerability metadata for many open source software ecosystems.

Browse Security Advisories

Moderate
about 22 hours ago

Liferay Portal Vulnerable to XSS in Web Content translation GSA_kwCzR0hTQS1xaDkyLWNyNWYtMzU5Nc4ABMy2

maven com.liferay.portal:release.portal.bom
Moderate
1 day ago

Liferay Portal Vulnerable to IDOR via audit events GSA_kwCzR0hTQS1wdzg2LXF2eDktMzRyN84ABMyw

maven com.liferay:com.liferay.portal.security.audit.storage.service, com.liferay:com.liferay.portal.security.audit.web
Moderate
1 day ago

Repository Credentials Race Condition Crashes Argo CD Server GSA_kwCzR0hTQS1nODhwLXI0MnItcHBwOc4ABMyV

go github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v2
Moderate
2 days ago

Liferay Portal vulnerable to cross-site scripting in the web content template GSA_kwCzR0hTQS1qdjh4LW1tM3YtNzVyN84ABMxD

maven com.liferay:com.liferay.journal.web, com.liferay.portal:release.portal.bom
Moderate
2 days ago

Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServlet GSA_kwCzR0hTQS0yaG03LXI4ZjMtNDIzaM4ABMw8

maven com.liferay.portal:com.liferay.portal.impl, com.liferay.portal:release.portal.bom
Moderate
2 days ago

Liferay Portal vulnerable to cross-site scripting in the Calendar widget GSA_kwCzR0hTQS1wZjg2LTR3MzUtY2o4Oc4ABMxB

maven com.liferay:com.liferay.calendar.web, com.liferay.portal:release.portal.bom
Moderate
6 days ago

Liferay Portal and DXP vulnerable to a memory leak GSA_kwCzR0hTQS1ocnFtLXFwdzktdzhyds4ABMp9

maven com.liferay:com.liferay.portal.vulcan.impl
Moderate
8 days ago

Apache IoTDB: DoS Vulnerability GSA_kwCzR0hTQS12eDg0LXh2cjgtdzI0Y84ABMl8

maven org.apache.iotdb:iotdb-core
Moderate
8 days ago

WSO2 Identity Server Apps allows content spoofing in logs GSA_kwCzR0hTQS1yNmYzLTU1d2otZzlwM84ABMkn

maven org.wso2.identity.apps:authentication-portal
Moderate
8 days ago

Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section GSA_kwCzR0hTQS13Y3doLTdnZnctNXdycs4ABMkj

maven org.http4s:http4s-ember-core_3, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_2.12
Moderate
8 days ago

WSO2 carbon-apimgt affected by an authenticated stored cross-site scripting (XSS) vulnerability GSA_kwCzR0hTQS1jbWpjLXFwN2oteGd3cs4ABMkc

maven org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.publisher.v1, org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.api
Moderate
9 days ago

Liferay Portal and DXP audit events record password reminder answers GSA_kwCzR0hTQS1waDYzLWNodnYtOHg0Ns4ABMin

maven com.liferay:com.liferay.portal.security.audit.event.generators.user.management
Moderate
9 days ago

Liferay Portal and DXP does not properly check permission with import and export tasks GSA_kwCzR0hTQS1wbTQ1LXh4NHEtZm12N84ABMil

maven com.liferay:com.liferay.batch.engine.service, com.liferay:com.liferay.headless.batch.engine.impl
Moderate
12 days ago

Liferay Portal Commerce component has Incorrect Permission Assignment for Critical Resource GSA_kwCzR0hTQS1jaHIzLXc1NDctODVod84ABMZg

maven com.liferay.commerce:com.liferay.commerce.product.type.virtual.service
Moderate
12 days ago

Liferay Portal Cross-Site Request Forgery (CSRF) vulnerability GSA_kwCzR0hTQS02OTdoLTNxNm0tandwNM4ABMZX

maven com.liferay.portal:com.liferay.portal.impl
Moderate
12 days ago

Grafana-Zabbix ReDoS vulnerability GSA_kwCzR0hTQS1nNHJyLTg4ZmMtMjZmas4ABMYk

go github.com/alexanderzobnin/grafana-zabbix
Moderate
13 days ago

Snipe-IT allows XSS GSA_kwCzR0hTQS1jOXdwLXByN2YtaGZxbc4ABMYR

packagist snipe/snipe-it
Moderate
14 days ago

Keycloak SMTP Inject Vulnerability GSA_kwCzR0hTQS1tNGo1LTV4NHItMnhwOc4ABMUD

maven org.keycloak:keycloak-services
Moderate
16 days ago

Liferay Stored Cross-site Scripting vulnerability GSA_kwCzR0hTQS12ZzZoLWc1bXItOWhnds4ABMJs

maven com.liferay.workspace:com.liferay.ticket.workspace
Moderate
16 days ago

Liferay Portal Uses Default Password GSA_kwCzR0hTQS00M3hmLTU5dnItZzRmMs4ABMI1

maven com.liferay.portal:release.portal.bom
Moderate
16 days ago

Liferay Portal Cross-site Scripting (XSS) vulnerability GSA_kwCzR0hTQS1qZnY1LXIzODIteHZ3aM4ABMIt

maven com.liferay:com.liferay.dynamic.data.mapping.form.field.type
Moderate
16 days ago

Liferay Portal vulnerable to Cross-site Scripting GSA_kwCzR0hTQS01YzZ2LWZxY3ctdzZxNc4ABMIY

maven com.liferay:com.liferay.dynamic.data.mapping.form.field.type
Moderate
16 days ago

Liferay Portal has Improper Validation of Specified Quantity in Input GSA_kwCzR0hTQS14dmdnLTloMjktNGczNM4ABMIU

maven com.liferay.portal:com.liferay.portal.kernel, com.liferay.portal:com.liferay.portal.impl
Moderate
16 days ago

MetaMask SDK indirectly exposed via malicious debug@4.4.2 dependency GSA_kwCzR0hTQS1xajNwLXhjOTcteHc3NM4ABMEi

npm @metamask/sdk-communication-layer, @metamask/sdk-react, @metamask/sdk
Moderate
16 days ago

Mattermost makes Use of Weak Hash GSA_kwCzR0hTQS05cDkyLXg3N3ctOWZ3Ms4ABMEa

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
16 days ago

Mattermost Missing Authorization vulnerability GSA_kwCzR0hTQS0zdmNtLWM0MnAtM2hoZs4ABMEP

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8

Filter by Severity

Filter by Ecosystem

Filter by Package

moodle/moodle 306 tensorflow 200 tensorflow-cpu 191 tensorflow-gpu 190 magento/community-edition 165 org.jenkins-ci.main:jenkins-core 148 typo3/cms 127 com.liferay.portal:release.portal.bom 104 org.apache.tomcat:tomcat 96 pimcore/pimcore 87 github.com/mattermost/mattermost/server/v8 84 com.liferay.portal:release.dxp.bom 81 microweber/microweber 72 typo3/cms-core 71 silverstripe/framework 67 phpmyadmin/phpmyadmin 56 dolibarr/dolibarr 55 drupal/core 52 github.com/usememos/memos 50 thorsten/phpmyfaq 47 concrete5/concrete5 46 apache-superset 45 apache-airflow 44 actionpack 43 librenms/librenms 43 Django 42 drupal/drupal 40 showdoc/showdoc 34 picklescan 34 mantisbt/mantisbt 33 org.elasticsearch:elasticsearch 33 org.keycloak:keycloak-core 32 Plone 32 craftcms/cms 31 github.com/grafana/grafana 31 magento/project-community-edition 30 github.com/mattermost/mattermost-server/v6 29 nova 29 github.com/mattermost/mattermost-server 28 symfony/symfony 28 moin 27 snipe/snipe-it 27 intelliants/subrion 27 mautic/core 27 baserproject/basercms 26 k8s.io/kubernetes 25 ansible 25 shopware/platform 23 directus 23 nilsteampassnet/teampass 21 github.com/answerdev/answer 21 github.com/hashicorp/vault 21 org.keycloak:keycloak-services 21 froxlor/froxlor 20 grumpydictator/firefly-iii 20 gradio 20 mediawiki/core 20 matrix-synapse 19 plone 19 shopware/shopware 19 org.apache.struts:struts2-core 19 github.com/cilium/cilium 19 remdex/livehelperchat 18 DotNetNuke.Core 17 getkirby/cms 17 github.com/argoproj/argo-cd/v2 17 salt 17 shopware/core 17 rdiffweb 16 github.com/docker/docker 16 prestashop/prestashop 16 django 16 zendframework/zendframework1 16 github.com/hashicorp/nomad 15 contao/core-bundle 15 org.apache.jspwiki:jspwiki-main 15 vyper 15 yetiforce/yetiforce-crm 15 io.undertow:undertow-core 15 rack 15 org.opencms:opencms-core 15 github.com/hashicorp/consul 14 glance 14 org.apache.tomcat.embed:tomcat-embed-core 14 org.xwiki.platform:xwiki-platform-oldcore 14 tinymce 14 puppet 14 keystone 13 tribalsystems/zenario 13 com.thoughtworks.xstream:xstream 13 com.jfinal:jfinal 13 github.com/openfga/openfga 13 forkcms/forkcms 13 github.com/goharbor/harbor 13 transformers 12 simplesamlphp/simplesamlphp 12 roundup 12 contao/contao 12 typo3/cms-backend 12 nokogiri 12 org.springframework.security:spring-security-core 12 helm.sh/helm/v3 12 next 12 wallabag/wallabag 12 github.com/traefik/traefik/v2 11 github.com/argoproj/argo-cd 11 github.com/containerd/containerd 11 @openzeppelin/contracts-upgradeable 11 TinyMCE 11 @openzeppelin/contracts 11 feehi/feehicms 11 getgrav/grav 11 genix/cms 11 lavalite/cms 11 activesupport 11 ec-cube/ec-cube 11 ghost 11 tinymce/tinymce 11 github.com/ethereum/go-ethereum 11 org.eclipse.jetty:jetty-server 11 com.vaadin:vaadin-bom 10 aiohttp 10 org.apache.solr:solr-core 10 PaddlePaddle 10 ckeditor4 10 OctoPrint 10 opencart/opencart 10 com.liferay.portal:com.liferay.portal.impl 10 notebook 10 org.keycloak:keycloak-parent 10 surrealdb 10 zendframework/zendframework 10 electron 10 vite 10 bolt/bolt 10 org.apache.nifi:nifi 10 laravel/framework 10 github.com/greenpau/caddy-security 10 bootstrap 10 fat_free_crm 10 org.springframework:spring-core 10 vllm 10 francoisjacquet/rosariosis 10 joplin 10 org.apache.jspwiki:jspwiki-war 10 sylius/sylius 9 silverstripe/cms 9 org.mortbay.jetty:jetty 9 cakephp/cakephp 9 urllib3 9 org.igniterealtime.openfire:parent 9 open-webui 9 publify_core 9 org.jenkins-ci.plugins:script-security 9 gogs.io/gogs 9 swagger-ui 9 org.apache.activemq:activemq-client 9 code.gitea.io/gitea 9 phpoffice/phpspreadsheet 9 org.jenkins-ci.plugins:git 9 rubygems-update 9 pyftpdlib 9 wasmtime 9 horizon 9 pimcore/admin-ui-classic-bundle 9 calibreweb 9 org.bouncycastle:bcprov-jdk14 9 org.opencrx:opencrx-core-models 9 github.com/rancher/rancher 9 angular 9 activerecord 8 alextselegidis/easyappointments 8 parse-server 8 opencv-python 8 org.apache.archiva:archiva 8 org.opensearch.plugin:opensearch-security 8 onionshare-cli 8 mlflow 8 Microsoft.ChakraCore 8 github.com/traefik/traefik/v3 8 modoboa 8 camaleon_cms 8 github.com/mattermost/mattermost-plugin-confluence 8 pyload-ng 8 phpmyfaq/phpmyfaq 8 editor.md 8 org.jenkins-ci.plugins:subversion 8 github.com/kubeedge/kubeedge 8 phpbb/phpbb 8 sulu/sulu 8 neutron 8 centreon/centreon 8 rails-html-sanitizer 8 org.jenkins-ci.plugins:electricflow 8 github.com/cri-o/cri-o 8 impresscms/impresscms 8 opencv-contrib-python 8 org.apache.ranger:ranger 8 rails 7 feehi/cms 7

Filter by Repository

https://github.com/tensorflow/tensorflow 200 https://github.com/moodle/moodle 186 https://github.com/liferay/liferay-portal 115 https://github.com/jenkinsci/jenkins 109 https://github.com/pimcore/pimcore 85 https://github.com/TYPO3/typo3 64 https://github.com/microweber/microweber 63 https://github.com/apache/tomcat 62 https://github.com/xwiki/xwiki-platform 50 https://github.com/silverstripe/silverstripe-framework 50 https://github.com/django/django 50 https://github.com/usememos/memos 50 https://github.com/rails/rails 46 https://github.com/thorsten/phpmyfaq 45 https://github.com/apache/airflow 43 https://github.com/keycloak/keycloak 42 https://github.com/kubernetes/kubernetes 40 https://github.com/librenms/librenms 40 https://github.com/mmaitre314/picklescan 34 https://github.com/star7th/showdoc 32 https://github.com/mantisbt/mantisbt 32 https://github.com/concretecms/concretecms 28 https://github.com/symfony/symfony 27 https://github.com/grafana/grafana 27 https://github.com/mautic/mautic 27 https://github.com/phpmyadmin/phpmyadmin 26 https://github.com/craftcms/cms 26 https://github.com/spring-projects/spring-framework 26 https://github.com/ansible/ansible 26 https://github.com/directus/directus 24 https://github.com/mattermost/mattermost 24 https://github.com/argoproj/argo-cd 24 https://github.com/umbraco/Umbraco-CMS 23 https://github.com/Dolibarr/dolibarr 22 https://github.com/answerdev/answer 21 https://github.com/shopware/shopware 21 https://github.com/firefly-iii/firefly-iii 20 https://github.com/apache/activemq 20 https://github.com/snipe/snipe-it 20 https://github.com/plone/Products.CMFPlone 20 https://github.com/magento/magento2 20 https://github.com/cilium/cilium 19 https://github.com/contao/contao 18 https://github.com/openstack/nova 18 https://github.com/livehelperchat/livehelperchat 18 https://github.com/apache/struts 17 https://github.com/shopware/platform 17 https://github.com/ikus060/rdiffweb 16 https://github.com/gradio-app/gradio 16 https://github.com/matrix-org/synapse 16 https://github.com/apache/cxf 15 https://github.com/vyperlang/vyper 15 https://github.com/netty/netty 15 https://github.com/getkirby/kirby 15 https://github.com/CVEProject/cvelist 15 https://github.com/OpenNMS/opennms 14 https://github.com/geoserver/geoserver 14 https://github.com/saltstack/salt 14 https://github.com/tinymce/tinymce 14 https://github.com/TYPO3/TYPO3.CMS 14 https://github.com/froxlor/froxlor 14 https://github.com/yetiforcecompany/yetiforcecrm 14 https://github.com/moby/moby 14 https://github.com/x-stream/xstream 14 https://github.com/baserproject/basercms 14 https://github.com/PaddlePaddle/Paddle 14 https://github.com/go-gitea/gitea 13 https://github.com/nilsteampassnet/TeamPass 13 https://github.com/goharbor/harbor 13 https://github.com/openfga/openfga 13 https://github.com/octobercms/october 13 https://github.com/PrestaShop/PrestaShop 13 https://github.com/apache/nifi 13 https://github.com/containerd/containerd 12 https://github.com/rack/rack 12 https://github.com/helm/helm 12 https://github.com/huggingface/transformers 12 https://github.com/TYPO3-CMS/core 12 https://github.com/bcgit/bc-java 12 https://github.com/traefik/traefik 12 https://github.com/ckeditor/ckeditor4 11 https://github.com/vaadin/platform 11 https://github.com/openstack/keystone 11 https://github.com/OpenZeppelin/openzeppelin-contracts 11 https://github.com/surrealdb/surrealdb 11 https://github.com/electron/electron 11 https://github.com/ethereum/go-ethereum 11 https://github.com/forkcms/forkcms 11 https://github.com/apache/zeppelin 11 https://github.com/laravel/framework 11 https://github.com/github/advisory-database 11 https://github.com/strapi/strapi 11 https://github.com/intelliants/subrion 11 https://github.com/wallabag/wallabag 10 https://github.com/backstage/backstage 10 https://github.com/simplesamlphp/simplesamlphp 10 https://github.com/greenpau/caddy-security 10 https://github.com/bytecodealliance/wasmtime 10 https://github.com/vercel/next.js 10 https://github.com/decidim/decidim 10 https://github.com/laurent22/joplin 10 https://github.com/aio-libs/aiohttp 10 https://github.com/TryGhost/Ghost 10 https://github.com/hashicorp/consul 10 https://github.com/PHPOffice/PhpSpreadsheet 10 https://github.com/vitejs/vite 10 https://github.com/liufee/cms 10 https://github.com/urllib3/urllib3 9 https://github.com/thorsten/phpMyFAQ 9 https://github.com/dnnsoftware/Dnn.Platform 9 https://github.com/vllm-project/vllm 9 https://github.com/rancher/rancher 9 https://github.com/alkacon/opencms-core 9 https://github.com/puppetlabs/puppet 9 https://github.com/pimcore/admin-ui-classic-bundle 9 https://github.com/publify/publify 9 https://github.com/jenkinsci/git-plugin 9 https://github.com/jquery/jquery 9 https://github.com/dpgaspar/Flask-AppBuilder 9 https://github.com/fatfreecrm/fat_free_crm 9 https://github.com/sparklemotion/nokogiri 8 https://github.com/sulu/sulu 8 https://github.com/rubygems/rubygems 8 https://github.com/dolibarr/dolibarr 8 https://github.com/pyload/pyload 8 https://github.com/dotnet/runtime 8 https://github.com/eclipse/jetty.project 8 https://github.com/swagger-api/swagger-ui 8 https://github.com/rails/rails-html-sanitizer 8 https://github.com/zendframework/zendframework 8 https://github.com/OctoPrint/OctoPrint 8 https://github.com/openstack/glance 8 https://github.com/hashicorp/nomad 8 https://github.com/nilsteampassnet/teampass 8 https://github.com/modoboa/modoboa 8 https://github.com/gogs/gogs 8 https://github.com/pandao/editor.md 8 https://github.com/onionshare/onionshare 8 https://github.com/LavaLite/cms 8 https://github.com/opencast/opencast 8 https://github.com/opensearch-project/security 8 https://github.com/kubeedge/kubeedge 8 https://github.com/apache/superset 8 https://github.com/denoland/deno 8 https://github.com/parse-community/parse-server 8 https://github.com/getgrav/grav 8 https://github.com/scrapy/scrapy 7 https://github.com/containers/podman 7 https://github.com/twbs/bootstrap 7 https://github.com/matrix-org/matrix-rust-sdk 7 https://github.com/google/fscrypt 7 https://github.com/undertow-io/undertow 7 https://github.com/MobSF/Mobile-Security-Framework-MobSF 7 https://github.com/croogo/croogo 7 https://github.com/modxcms/revolution 7 https://github.com/dragonflyoss/dragonfly 7 https://github.com/nocodb/nocodb 7 https://github.com/jupyter/notebook 7 https://github.com/kevinpapst/kimai2 7 https://github.com/zitadel/zitadel 7 https://github.com/python-pillow/Pillow 7 https://github.com/jeecgboot/jeecg-boot 7 https://github.com/OPCFoundation/UA-.NETStandard 7 https://github.com/Sylius/Sylius 7 https://github.com/n8n-io/n8n 7 https://github.com/Leantime/leantime 7 https://github.com/vega/vega 7 https://github.com/hashicorp/vault 7 https://github.com/igniterealtime/Openfire 7 https://github.com/nahsra/antisamy 7 https://github.com/opencontainers/runc 7 https://github.com/openstack/horizon 7 https://github.com/janeczku/calibre-web 7 https://github.com/jenkinsci/blueocean-plugin 7 https://github.com/opencv/opencv 7 https://github.com/chakra-core/ChakraCore 7 https://github.com/vaadin/flow 7 https://github.com/pmmp/PocketMine-MP 6 https://github.com/louislam/uptime-kuma 6 https://github.com/ckan/ckan 6 https://github.com/zenml-io/zenml 6 https://github.com/jenkinsci/subversion-plugin 6 https://github.com/StarCitizenTools/mediawiki-skins-Citizen 6 https://github.com/tecnickcom/TCPDF 6 https://github.com/FlowiseAI/Flowise 6 https://github.com/stacklok/minder 6 https://github.com/drupal/core 6 https://github.com/jenkinsci/fortify-on-demand-uploader-plugin 6 https://github.com/jenkinsci/configuration-as-code-plugin 6 https://github.com/nodejs/undici 6 https://github.com/1Panel-dev/1Panel 6 https://github.com/cui2shark/security 6 https://github.com/d4wner/Vulnerabilities-Report 6 https://github.com/psf/requests 6 https://github.com/yiisoft/yii2 6 https://github.com/run-llama/llama_index 6 https://github.com/matrix-org/matrix-js-sdk 6 https://github.com/apache/inlong 6 https://github.com/giampaolo/pyftpdlib 6