Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Moderate Security Advisories

Browse all Security Advisories for Moderate

Loading...
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA5ajYtNHBqci1ncDQ4
MPXJ path Traversal vulnerability
Ecosystems: maven
Packages: net.sf.mpxj:mpxj
Source: GitHub Advisory Database
Blast Radius: 8.8
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTQ1cTItMzRyZi1tcjk0
Code Injection in mquery
Ecosystems: npm
Packages: mquery
Source: GitHub Advisory Database
Blast Radius: 30.9
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZyM3AtZmN2bS14aDdj
SSRF vulnerability in Apache Airflow
Ecosystems: pypi
Packages: apache-airflow
Source: GitHub Advisory Database
Blast Radius: 16.9
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW01N3AtcDY3aC1tcTc0
Command Injection Vulnerability in systeminformation
Ecosystems: npm
Packages: systeminformation
Source: GitHub Advisory Database
Blast Radius: 26.9
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpjODQtM2c0NC13ZjJx
Denial of Service in ecstatic
Ecosystems: npm
Packages: ecstatic
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWN2bXItNjQyOC04N3c5
Cross-Site Scripting in Grav
Ecosystems: packagist
Packages: getgrav/grav
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXEyNjMtZnZ4bS1tNW13
Heap out of bounds access in MakeEdge in TensorFlow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 21.4
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW02NDgtMzNxZi12M2dw
CHECK-fail in LSTM with zero-length input in TensorFlow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 21.4
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhodmMtZzVodi00OGM2
Write to immutable memory region in TensorFlow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 21.4
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFoeHgtajczci1xcG0y
Uninitialized memory access in TensorFlow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 21.4
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJjamotaDZnaC1qZjNy
Information Disclosure in Apache Groovy
Ecosystems: maven
Packages: org.codehaus.groovy:groovy-all, org.codehaus.groovy:groovy
Source: GitHub Advisory Database
Blast Radius: 25.1
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhtNDUtbWdxbS1nam00
Remote Code Execution (RCE) Exploit on Cross Site Scripting (XSS) Vulnerability
Ecosystems: pypi
Packages: red-dashboard
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWczaDgtY2c5eC00N3F3
Kirby Panel users could upload PHP Phar archives as content files before v2.5.14 and v3.4.5
Ecosystems: packagist
Packages: getkirby/cms, getkirby/panel
Source: GitHub Advisory Database
Blast Radius: 17.5
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTd3d3Ytdmgzdi04OWNx
ReDOS vulnerabities: multiple grammars
Ecosystems: npm
Packages: @highlightjs/cdn-assets, highlight.js
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTg2d20tcnJqbS04d2g4
Buffer not correctly recycled in Gzip Request inflation
Ecosystems: maven
Packages: org.eclipse.jetty:jetty-server
Source: GitHub Advisory Database
Blast Radius: 21.8
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTR2MnctaDlqbS1tcWpn
Prototype Pollution in systeminformation
Ecosystems: npm
Packages: systeminformation
Source: GitHub Advisory Database
Blast Radius: 34.1
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTg1cnItNHJoOS1oaHdo
Memory leak in Nanopb
Ecosystems: pypi
Packages: nanopb
Source: GitHub Advisory Database
Blast Radius: 11.7
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZmcmMtN3I3Yy13OW14
Prototype Pollution in highlight.js
Ecosystems: npm
Packages: highlight.js
Source: GitHub Advisory Database
Blast Radius: 33.9
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWdyZmotd2p2OS00Zjl2
Open redirect in Jupyter Server
Ecosystems: pypi
Packages: jupyter-server
Source: GitHub Advisory Database
Blast Radius: 15.8
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTk0dnAtcm1xdi01ODc1
Twig Sandbox Escape by authenticated users with access to editing CMS templates when safemode is enabled.
Ecosystems: packagist
Packages: october/cms
Source: GitHub Advisory Database
Blast Radius: 13.0
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTU4dzQtdzc3dy1xdjN3
Reflected XSS with parameters in PostComment
Ecosystems: packagist
Packages: prestashop/productcomments
Source: GitHub Advisory Database
Blast Radius: 17.4
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXh3aGYtZzZqNS1qNWdj
Float cast overflow undefined behavior
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 18.0
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTRxOTYtNnhocS1mZjQz
malicious SVG attachment causing stored XSS vulnerability
Ecosystems: pypi
Packages: moin
Source: GitHub Advisory Database
Blast Radius: 14.5
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpncmgtNW0zaC05YzVm
Web Cache Poisoning in find-my-way
Ecosystems: npm
Packages: find-my-way
Source: GitHub Advisory Database
Blast Radius: 25.2
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXF2cDUtbW03di00ZjM2
Cross-site Scripting in Strapi
Ecosystems: npm
Packages: strapi-plugin-content-manager
Source: GitHub Advisory Database
Blast Radius: 19.3
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZqNTktZjZjMy0zdnc0
Command Injection in systeminformation
Ecosystems: npm
Packages: systeminformation
Source: GitHub Advisory Database
Blast Radius: 24.8
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhnZ20tanBnMy12NDc2
RSA decryption vulnerable to Bleichenbacher timing vulnerability
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Blast Radius: 30.2
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1wOW0tZzdxai02dnFy
Unauthorized privilege escalation in Mod module
Ecosystems: pypi
Packages: red-discordbot
Source: GitHub Advisory Database
Blast Radius: 10.3
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXB2MzYtaDdqaC1xbTYy
Heap buffer overflow in CefSharp
Ecosystems: nuget
Packages: CefSharp.Wpf.HwndHost, CefSharp.WinForms, CefSharp.Wpf, CefSharp.Common
Source: GitHub Advisory Database
Blast Radius: 1.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTJ4bTIteGoycS1xZ3Bq
receiving subscription objects with deleted session
Ecosystems: npm
Packages: parse-server
Source: GitHub Advisory Database
Blast Radius: 13.3
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTkzOW0tNHhwdy12MzR2
Arbitrary Code Execution in blazar-dashboard
Ecosystems: pypi
Packages: blazar-dashboard
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTh4djktcWNyOS13dzlq
Authenticated XML External Entity Processing
Ecosystems: packagist
Packages: shopware/core, shopware/platform
Source: GitHub Advisory Database
Blast Radius: 13.9
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZndzQteDYzaC01NDk5
Ability to switch customer email address on account detail page and stay verified
Ecosystems: packagist
Packages: sylius/sylius
Source: GitHub Advisory Database
Blast Radius: 12.4
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTN4OGMtZm1wYy01cm1x
Cross-site scripting (XSS) vulnerability in the fallback authentication endpoint
Ecosystems: pypi
Packages: matrix-synapse
Source: GitHub Advisory Database
Blast Radius: 8.6
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWoyNTctamZ2di1oM3g1
Privilege Escalation in Channelmgnt plug-in for Sopel
Ecosystems: pypi
Packages: sopel-plugins-channelmgnt, sopel_plugins.channelmgnt
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZyN3gtaGM4bS05ODVy
Cross-site Scripting in Joplin
Ecosystems: npm
Packages: joplin
Source: GitHub Advisory Database
Blast Radius: 7.7
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTI2OWctcHdwNS04N3Bw
TemporaryFolder on unix-like systems does not limit access to created files
Ecosystems: maven
Packages: junit:junit
Source: GitHub Advisory Database
Blast Radius: 27.3
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTU4MjItcHc1Ny12djM3
XSS vulnerability when listing users on add & modify server pages.
Ecosystems: packagist
Packages: pterodactyl/panel
Source: GitHub Advisory Database
Blast Radius: 1.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTc3MzMtaGp2Ni00aDQ3
Cross-Site Scripting in ternary conditional operator
Ecosystems: packagist
Packages: typo3/cms, typo3/cms-core, typo3fluid/fluid
Source: GitHub Advisory Database
Blast Radius: 16.9
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg1NnAtYzhjZy1xNDM1
Open Redirect in Next.js versions
Ecosystems: npm
Packages: next
Source: GitHub Advisory Database
Blast Radius: 26.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTU1dzktYzNnMi00cnJo
Man-in-the-middle attack in Apache Axis
Ecosystems: maven
Packages: axis:axis, org.apache.axis:axis
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVqanYteDRmcS1xandw
Possible timing attack in derivation_endpoint
Ecosystems: rubygems
Packages: shrine
Source: GitHub Advisory Database
Blast Radius: 16.3
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTM2ajMteHhmNy00cHFn
Android WebView Universal Cross-site Scripting
Ecosystems: npm
Packages: react-native-webview
Source: GitHub Advisory Database
Blast Radius: 27.7
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhqbXEtMjM2ai04bTg3
Denial of service in tensorflow-lite
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 19.5
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWN2cGMtOHBoaC04ZjQ1
Out of bounds access in tensorflow-lite
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 23.4
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE0cWYtM2ZjNi04eDM0
Segfault and data corruption in tensorflow-lite
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 42.3
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE4Z3YtcTd3ci05amY4
Segfault in Tensorflow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 25.8
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc3cDUtNTc1OS1xdjQ2
Data leak in Tensorflow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 44.3
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA1ZjgtZ2Z3NS0zM3c0
Heap buffer overflow in Tensorflow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 23.4
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFjNTMtNDRjai12ZnZ4
Denial of Service in Tensorflow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 30.7
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTYzeG0tcng1cC14dnFy
Heap buffer overflow in Tensorflow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 41.9
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE4cWotZmM5cS1jcGhy
Undefined behavior in Tensorflow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 25.8
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpjODctNnZwcC03ZmYz
Heap buffer overflow in Tensorflow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 26.3
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXBnNTktMmY5Mi01Y3Bo
Heap buffer overflow in Tensorflow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 41.9
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTltcXAtN3YyaC0yMzgy
Denial of Service in Tensorflow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 25.8
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThmeHctNzZweC0zcnh2
Memory leak in Tensorflow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 20.9
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTRnOWYtNjNyeC01Y3c0
Segfault in Tensorflow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 25.8
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWY3d20teDRndy02bTIz
Contao Insert tag injection in forms
Ecosystems: packagist
Packages: contao/core-bundle, contao/contao
Source: GitHub Advisory Database
Blast Radius: 17.4
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhnd20tcHY5aC1xNW03
Potential XSS in jQuery dependency in Mirador
Ecosystems: npm
Packages: mirador
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTRwNnctbTl3Yy1jOWM5
Sensitive Data Exposure in Apache Ant
Ecosystems: maven
Packages: org.apache.ant:ant
Source: GitHub Advisory Database
Blast Radius: 26.8
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTM2cmgtZ2dwci1qM2dq
Renovate vulnerable to Azure DevOps token leakage in logs
Ecosystems: npm
Packages: renovate
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXc5OTItMmdtai05eHhq
Cross-Site Scripting in swagger-ui
Ecosystems: npm
Packages: swagger-ui
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTNmOTUtdzVoNS1mcTg2
Prototype Pollution in mergify
Ecosystems: npm
Packages: mergify
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTIycTktaHFtNS1taG1j
Cross-Site Scripting in swagger-ui
Ecosystems: npm
Packages: swagger-ui
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZwOTMtZ2N4NS00dzUy
Cross-Site Scripting in swagger-ui
Ecosystems: npm
Packages: swagger-ui
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNwZ3Itd21yOS1xeHY0
Cross-Site Scripting in serve
Ecosystems: npm
Packages: serve
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTRmOW0tcHh3aC02OGhn
Cross-Site Scripting in swagger-ui
Ecosystems: npm
Packages: swagger-ui
Source: GitHub Advisory Database
Blast Radius: 25.5
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTM4OGctandwZy14Nmo0
Cross-Site Scripting in swagger-ui
Ecosystems: npm
Packages: swagger-ui
Source: GitHub Advisory Database
Blast Radius: 25.5
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXc5NzMtMnFjYy1wNzh4
User Impersonation in converse.js
Ecosystems: npm
Packages: converse.js
Source: GitHub Advisory Database
Blast Radius: 5.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo4cjItMng5NC0ycTY3
Cross-Site Scripting in diagram-js-direct-editing
Ecosystems: npm
Packages: diagram-js-direct-editing
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThmdzQteGg4My0zajZx
Cross-Site Scripting in diagram-js
Ecosystems: npm
Packages: diagram-js
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA4MmctMnhwcC1tNXIz
Cross-Site Scripting in dojo
Ecosystems: npm
Packages: dojo
Source: GitHub Advisory Database
Blast Radius: 17.8
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXdndzMtZ2Y0cC02Mnhj
Command Injection in wizard-syncronizer
Ecosystems: npm
Packages: wizard-syncronizer
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTl2NjItMjRjci01OGN4
Denial of Service in node-sass
Ecosystems: npm
Packages: node-sass
Source: GitHub Advisory Database
Blast Radius: 35.1
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo2djkteGd2aC1mNzk2
Command Injection in wxchangba
Ecosystems: npm
Packages: wxchangba
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNmanYtNTQ5OC1tcGg1
XSS in Action View
Ecosystems: rubygems
Packages: actionview
Source: GitHub Advisory Database
Blast Radius: 31.2
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg0NHgtcjg0dy04djY3
Lack of URL normalization may lead to authorization bypass when URL access rules are used
Ecosystems: npm
Packages: lemonldap-ng-handler
Source: GitHub Advisory Database
Blast Radius: 2.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA5cGMtMjk5cC12eGdw
yargs-parser Vulnerable to Prototype Pollution
Ecosystems: npm
Packages: yargs-parser
Source: GitHub Advisory Database
Blast Radius: 35.2
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTJnZ3EtdmZjcC1nd2hq
Cross-Site Scripting in @hapi/boom
Ecosystems: npm
Packages: @hapi/boom
Source: GitHub Advisory Database
Blast Radius: 33.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhycHAtZjg0dy14aGZn
Outdated Static Dependency in vue-moment
Ecosystems: npm
Packages: vue-moment
Source: GitHub Advisory Database
Blast Radius: 19.9
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc1M3ctNTJ4Yy0yajg1
Cross-Site Scripting in react
Ecosystems: npm
Packages: react
Source: GitHub Advisory Database
Blast Radius: 41.9
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlneHItcmh4Ni00amd2
Sandbox Breakout / Prototype Pollution in notevil
Ecosystems: npm
Packages: notevil
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWY1MmctNmpoeC01ODZw
Denial of Service in handlebars
Ecosystems: npm
Packages: handlebars
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1mY3AtMzR4dy1wNTd4
Authentication Bypass in saml2-js
Ecosystems: npm
Packages: saml2-js
Source: GitHub Advisory Database
Blast Radius: 23.4
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTV2N3Itamc5ci12cTQ0
Insecure Cryptography Algorithm in simple-crypto-js
Ecosystems: npm
Packages: simple-crypto-js
Source: GitHub Advisory Database
Blast Radius: 15.3
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhncDItY2M0ci03dmY2
Denial of Service in http-live-simulator
Ecosystems: npm
Packages: http-live-simulator
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA3N2gtaHY2Zy1mbWZw
Sensitive Data Exposure in ibm_db
Ecosystems: npm
Packages: ibm_db
Source: GitHub Advisory Database
Blast Radius: 16.9
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWMzbTgteDNjZy1xbTJj
Configuration Override in helmet-csp
Ecosystems: npm
Packages: helmet-csp
Source: GitHub Advisory Database
Blast Radius: 31.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpmY2Mtcm03Zi14Z2Y4
Cross-Site Scripting in mavon-editor
Ecosystems: npm
Packages: mavon-editor
Source: GitHub Advisory Database
Blast Radius: 22.9
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTg4aDktZmM2di1qY3c3
Unintended Require in larvitbase-www
Ecosystems: npm
Packages: larvitbase-www
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTR4ZjktcGd2di14eDY3
Regular Expression Denial of Service in simple-markdown
Ecosystems: npm
Packages: simple-markdown
Source: GitHub Advisory Database
Blast Radius: 15.5
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTR2dnAteDloMi14MnZm
Path Traversal in public
Ecosystems: npm
Packages: public
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZ3NHAtMzZqOS1ycmoz
Denial of Service in sequelize
Ecosystems: npm
Packages: sequelize
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNyNjctNzhqci1qOTRw
Local File Inclusion in domokeeper
Ecosystems: npm
Packages: domokeeper
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTU4OG0tOXFnNS0zNXBx
Reverse Tabnabbing in quill
Ecosystems: npm
Packages: quill
Source: GitHub Advisory Database
Blast Radius: 29.6
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg5N2ctNG14Ny01cDJw
Open Redirect in apostrophe
Ecosystems: npm
Packages: apostrophe
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWM1M3gtd3d4Mi1wZzk2
Cross-Site Scripting in @berslucas/liljs
Ecosystems: npm
Packages: @berslucas/liljs
Source: GitHub Advisory Database
Blast Radius: 1.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWN4bTMtMjg0cC1xYzR2
Prototype Pollution in sds
Ecosystems: npm
Packages: sds
Source: GitHub Advisory Database
Blast Radius: 1.6
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTg2bXItNm04OS12Z2oz
Buffer Overflow in node-weakauras-parser
Ecosystems: npm
Packages: node-weakauras-parser
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXB4bXAtZndqYy00eDdx
HTML Injection in marky-markdown
Ecosystems: npm
Packages: marky-markdown
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 4 years ago
Statistics
Advisories: 20,545
Packages: 8,999
Repositories: 2,700
Ecosystems: 12
Filter by Package
moodle/moodle 267 tensorflow 208 tensorflow-cpu 205 tensorflow-gpu 204 magento/community-edition 132 typo3/cms 119 org.jenkins-ci.main:jenkins-core 117 org.apache.tomcat:tomcat 91 pimcore/pimcore 86 typo3/cms-core 72 microweber/microweber 65 silverstripe/framework 64 dolibarr/dolibarr 55 apache-airflow 53 phpmyadmin/phpmyadmin 50 drupal/core 48 actionpack 45 thorsten/phpmyfaq 45 github.com/usememos/memos 45 Django 44 apache-superset 42 github.com/mattermost/mattermost/server/v8 42 drupal/drupal 40 Plone 38 github.com/grafana/grafana 36 concrete5/concrete5 36 org.keycloak:keycloak-core 35 librenms/librenms 35 showdoc/showdoc 34 symfony/symfony 33 ansible 32 github.com/mattermost/mattermost-server/v6 30 moin 30 nova 29 plone 29 craftcms/cms 28 org.elasticsearch:elasticsearch 28 intelliants/subrion 26 baserproject/basercms 26 com.liferay.portal:release.portal.bom 25 snipe/snipe-it 24 django 24 k8s.io/kubernetes 22 github.com/answerdev/answer 21 grumpydictator/firefly-iii 20 org.apache.struts:struts2-core 20 mediawiki/core 20 shopware/shopware 19 shopware/platform 19 froxlor/froxlor 18 nilsteampassnet/teampass 18 remdex/livehelperchat 18 github.com/docker/docker 17 gradio 17 zendframework/zendframework1 17 keystone 17 mautic/core 17 matrix-synapse 17 getkirby/cms 16 org.apache.tomcat.embed:tomcat-embed-core 16 github.com/argoproj/argo-cd/v2 16 directus 16 rdiffweb 16 io.undertow:undertow-core 15 prestashop/prestashop 15 github.com/cilium/cilium 15 org.keycloak:keycloak-services 15 glance 15 github.com/hashicorp/consul 14 puppet 14 shopware/core 14 vyper 14 nokogiri 14 yetiforce/yetiforce-crm 14 tinymce 14 github.com/hashicorp/vault 14 org.xwiki.platform:xwiki-platform-oldcore 14 org.apache.jspwiki:jspwiki-main 13 tribalsystems/zenario 13 com.jfinal:jfinal 13 forkcms/forkcms 13 github.com/hashicorp/nomad 13 contao/core-bundle 12 simplesamlphp/simplesamlphp 12 github.com/goharbor/harbor 12 com.thoughtworks.xstream:xstream 12 github.com/argoproj/argo-cd 11 org.springframework.security:spring-security-core 11 lavalite/cms 11 roundup 11 feehi/feehicms 11 getgrav/grav 11 rack 11 org.eclipse.jetty:jetty-server 11 TinyMCE 11 tinymce/tinymce 11 DotNetNuke.Core 11 ec-cube/ec-cube 11 genix/cms 11 org.bouncycastle:bcprov-jdk14 11 org.keycloak:keycloak-parent 11 org.apache.solr:solr-core 11 org.apache.nifi:nifi 10 francoisjacquet/rosariosis 10 ghost 10 PaddlePaddle 10 activesupport 10 fat_free_crm 10 bootstrap 10 typo3/cms-backend 10 github.com/containerd/containerd 10 bootstrap 10 silverstripe/cms 10 github.com/ethereum/go-ethereum 10 github.com/greenpau/caddy-security 10 salt 10 github.com/mattermost/mattermost-server 10 org.springframework:spring-core 10 zendframework/zendframework 10 joplin 10 bolt/bolt 10 org.apache.jspwiki:jspwiki-war 10 ckeditor4 10 org.bouncycastle:bcprov-jdk15on 10 @openzeppelin/contracts-upgradeable 10 com.vaadin:vaadin-bom 10 opencart/opencart 10 @openzeppelin/contracts 10 wallabag/wallabag 10 angular 9 github.com/traefik/traefik/v2 9 pyftpdlib 9 rubygems-update 9 cakephp/cakephp 9 bootstrap 9 gogs.io/gogs 9 org.webjars:bootstrap 9 notebook 9 twbs/bootstrap 9 wasmtime 9 horizon 9 org.jenkins-ci.plugins:git 9 code.gitea.io/gitea 9 aiohttp 9 org.igniterealtime.openfire:parent 9 swagger-ui 9 wagtail 9 helm.sh/helm/v3 9 publify_core 9 org.opencms:opencms-core 9 github.com/zitadel/zitadel 9 org.mortbay.jetty:jetty 9 org.opencrx:opencrx-core-models 9 org.jenkins-ci.plugins:electricflow 8 camaleon_cms 8 laravel/framework 8 editor.md 8 contao/contao 8 next 8 github.com/openfga/openfga 8 centreon/centreon 8 actionview 8 phpbb/phpbb 8 rails-html-sanitizer 8 bootstrap.sass 8 org.jenkins-ci.plugins:script-security 8 rails 8 modoboa 8 onionshare-cli 8 sylius/sylius 8 org.apache.activemq:activemq-client 8 electron 8 OctoPrint 8 jquery-rails 8 Microsoft.ChakraCore 8 opencv-python 8 opencv-contrib-python 8 impresscms/impresscms 8 github.com/kubeedge/kubeedge 8 pimcore/admin-ui-classic-bundle 8 jQuery.UI.Combined 7 github.com/apache/incubator-answer 7 org.bouncycastle:bcprov-jdk15to18 7 jquery-ui-rails 7 sulu/sulu 7 urllib3 7 github.com/1Panel-dev/1Panel 7 swift 7 silverstripe/admin 7 validator 7 pyload-ng 7 trytond 7 github.com/moby/moby 7 org.bouncycastle:bcprov-jdk15 7 org.owasp.antisamy:antisamy 7 github.com/google/fscrypt 7 activerecord 7 io.jenkins:configuration-as-code 7 vantage6 7 org.webjars.npm:jquery 7
Filter by Repository
https://github.com/tensorflow/tensorflow 208 https://github.com/moodle/moodle 167 https://github.com/jenkinsci/jenkins 91 https://github.com/pimcore/pimcore 83 https://github.com/microweber/microweber 61 https://github.com/apache/airflow 53 https://github.com/TYPO3/typo3 53 https://github.com/django/django 53 https://github.com/apache/tomcat 53 https://github.com/silverstripe/silverstripe-framework 47 https://github.com/usememos/memos 45 https://github.com/thorsten/phpmyfaq 45 https://github.com/xwiki/xwiki-platform 43 https://github.com/rails/rails 39 https://github.com/kubernetes/kubernetes 35 https://github.com/librenms/librenms 33 https://github.com/star7th/showdoc 32 https://github.com/keycloak/keycloak 31 https://github.com/ansible/ansible 31 https://github.com/grafana/grafana 30 https://github.com/symfony/symfony 27 https://github.com/spring-projects/spring-framework 24 https://github.com/craftcms/cms 23 https://github.com/phpmyadmin/phpmyadmin 22 https://github.com/argoproj/argo-cd 22 https://github.com/Dolibarr/dolibarr 22 https://github.com/concretecms/concretecms 21 https://github.com/answerdev/answer 21 https://github.com/plone/Products.CMFPlone 20 https://github.com/magento/magento2 20 https://github.com/firefly-iii/firefly-iii 20 https://github.com/snipe/snipe-it 20 https://github.com/apache/activemq 19 https://github.com/openstack/nova 19 https://github.com/livehelperchat/livehelperchat 18 https://github.com/mautic/mautic 17 https://github.com/apache/struts 17 https://github.com/shopware/platform 17 https://github.com/shopware/shopware 17 https://github.com/ikus060/rdiffweb 16 https://github.com/matrix-org/synapse 16 https://github.com/directus/directus 15 https://github.com/CVEProject/cvelist 15 https://github.com/cilium/cilium 15 https://github.com/openstack/keystone 15 https://github.com/vyperlang/vyper 14 https://github.com/baserproject/basercms 14 https://github.com/yetiforcecompany/yetiforcecrm 14 https://github.com/PaddlePaddle/Paddle 14 https://github.com/umbraco/Umbraco-CMS 14 https://github.com/froxlor/froxlor 14 https://github.com/OpenNMS/opennms 14 https://github.com/tinymce/tinymce 14 https://github.com/TYPO3/TYPO3.CMS 14 https://github.com/apache/cxf 14 https://github.com/gradio-app/gradio 14 https://github.com/octobercms/october 13 https://github.com/x-stream/xstream 13 https://github.com/go-gitea/gitea 13 https://github.com/getkirby/kirby 13 https://github.com/contao/contao 13 https://github.com/netty/netty 12 https://github.com/goharbor/harbor 12 https://github.com/PrestaShop/PrestaShop 12 https://github.com/moby/moby 11 https://github.com/apache/nifi 11 https://github.com/mattermost/mattermost 11 https://github.com/forkcms/forkcms 11 https://github.com/greenpau/caddy-security 10 https://github.com/geoserver/geoserver 10 https://github.com/traefik/traefik 10 https://github.com/nilsteampassnet/TeamPass 10 https://github.com/simplesamlphp/simplesamlphp 10 https://github.com/hashicorp/consul 10 https://github.com/vaadin/platform 10 https://github.com/OpenZeppelin/openzeppelin-contracts 10 https://github.com/liufee/cms 10 https://github.com/zitadel/zitadel 10 https://github.com/laurent22/joplin 10 https://github.com/github/advisory-database 10 https://github.com/backstage/backstage 10 https://github.com/ethereum/go-ethereum 10 https://github.com/strapi/strapi 10 https://github.com/containerd/containerd 10 https://github.com/intelliants/subrion 10 https://github.com/sparklemotion/nokogiri 9 https://github.com/aio-libs/aiohttp 9 https://github.com/TryGhost/Ghost 9 https://github.com/rack/rack 9 https://github.com/publify/publify 9 https://github.com/wagtail/wagtail 9 https://github.com/fatfreecrm/fat_free_crm 9 https://github.com/jquery/jquery 9 https://github.com/TYPO3-CMS/core 9 https://github.com/bytecodealliance/wasmtime 9 https://github.com/helm/helm 9 https://github.com/electron/electron 9 https://github.com/puppetlabs/puppet 9 https://github.com/ckeditor/ckeditor4 9 https://github.com/openstack/glance 9 https://github.com/jenkinsci/git-plugin 9 https://github.com/pimcore/admin-ui-classic-bundle 8 https://github.com/eclipse/jetty.project 8 https://github.com/onionshare/onionshare 8 https://github.com/kubeedge/kubeedge 8 https://github.com/python-pillow/Pillow 8 https://github.com/decidim/decidim 8 https://github.com/apache/zeppelin 8 https://github.com/swagger-api/swagger-ui 8 https://github.com/wallabag/wallabag 8 https://github.com/dotnet/runtime 8 https://github.com/rails/rails-html-sanitizer 8 https://github.com/LavaLite/cms 8 https://github.com/openfga/openfga 8 https://github.com/zendframework/zendframework 8 https://github.com/modoboa/modoboa 8 https://github.com/rubygems/rubygems 8 https://github.com/pandao/editor.md 8 https://github.com/nilsteampassnet/teampass 8 https://github.com/getgrav/grav 8 https://github.com/bcgit/bc-java 8 https://github.com/sulu/sulu 7 https://github.com/thorsten/phpMyFAQ 7 https://github.com/laravel/framework 7 https://github.com/scrapy/scrapy 7 https://github.com/opencv/opencv 7 https://github.com/undertow-io/undertow 7 https://github.com/1Panel-dev/1Panel 7 https://github.com/saltstack/salt 7 https://github.com/jupyter/notebook 7 https://github.com/jenkinsci/blueocean-plugin 7 https://github.com/urllib3/urllib3 7 https://github.com/hashicorp/vault 7 https://github.com/twbs/bootstrap 7 https://github.com/openstack/horizon 7 https://github.com/gogs/gogs 7 https://github.com/containers/podman 7 https://github.com/Sylius/Sylius 7 https://github.com/jeecgboot/jeecg-boot 7 https://github.com/dolibarr/dolibarr 7 https://github.com/vantage6/vantage6 7 https://github.com/kevinpapst/kimai2 7 https://github.com/nahsra/antisamy 7 https://github.com/pyload/pyload 7 https://github.com/vaadin/flow 7 https://github.com/chakra-core/ChakraCore 7 https://github.com/google/fscrypt 7 https://github.com/oroinc/orocommerce 6 https://github.com/tornadoweb/tornado 6 https://github.com/puma/puma 6 https://github.com/pimcore/customer-data-framework 6 https://github.com/mantisbt/mantisbt 6 https://github.com/opencast/opencast 6 https://github.com/jenkinsci/configuration-as-code-plugin 6 https://github.com/opencart/opencart 6 https://github.com/apache/superset 6 https://github.com/jenkinsci/fortify-on-demand-uploader-plugin 6 https://github.com/nocodb/nocodb 6 https://github.com/jquery/jquery-ui 6 https://github.com/zenml-io/zenml 6 https://github.com/croogo/croogo 6 https://github.com/jenkinsci/script-security-plugin 6 https://github.com/yiisoft/yii2 6 https://github.com/ckan/ckan 6 https://github.com/neorazorx/facturascripts 6 https://github.com/d4wner/Vulnerabilities-Report 6 https://github.com/panva/jose 6 https://github.com/dompdf/dompdf 6 https://github.com/owen2345/camaleon-cms 6 https://github.com/igniterealtime/Openfire 6 https://github.com/stacklok/minder 6 https://github.com/parse-community/parse-server 6 https://github.com/rancher/rancher 6 https://github.com/lxml/lxml 6 https://github.com/ruby/rexml 6 https://github.com/cubefs/cubefs 6 https://github.com/vercel/next.js 6 https://github.com/cui2shark/security 6 https://github.com/cloudflare/cfrpki 6 https://github.com/hashicorp/nomad 6 https://github.com/opensearch-project/security 6 https://github.com/giampaolo/pyftpdlib 6 https://github.com/PHPOffice/PhpSpreadsheet 6 https://github.com/pomerium/pomerium 6 https://github.com/jenkinsci/config-file-provider-plugin 6 https://github.com/jenkinsci/subversion-plugin 5 https://github.com/centreon/centreon-archived 5 https://github.com/kivikakk/comrak 5 https://github.com/Amanieu/parking_lot 5 https://github.com/matrix-org/matrix-appservice-irc 5 https://github.com/OPCFoundation/UA-.NETStandard 5 https://github.com/pmmp/PocketMine-MP 5 https://github.com/alkacon/opencms-core 5 https://github.com/vapor/vapor 5 https://github.com/opencontainers/runc 5 https://github.com/psf/requests 5 https://github.com/lief-project/LIEF 5 https://github.com/unshiftio/url-parse 5 https://github.com/apache/tika 5