Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Moderate Security Advisories

Browse all Security Advisories for Moderate

Loading...
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTg3OXItN2Yzdy04amoz
Moderate severity vulnerability that affects Plone and Zope2
Ecosystems: pypi
Packages: Plone, Zope2
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTd3cGgtZmM0dy13cXAy
Improper date handling in Django
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 38.0
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTc3aHYtODc5Ni04Y2Nw
HTTP header injection in Plone and Zope2
Ecosystems: pypi
Packages: Plone, Zope2
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTRtNzItcm1tOS0ycWpy
feedparser Cross-site Scripting vulnerability
Ecosystems: pypi
Packages: feedparser
Source: GitHub Advisory Database
Blast Radius: 25.8
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZ3cjUtcTlyeC0yOTRm
Improper query string handling in Django
Ecosystems: pypi
Packages: Django, django
Source: GitHub Advisory Database
Blast Radius: 32.9
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXY3cTgtd3Z2aC1jOTdw
Moderate severity vulnerability that affects Zope2
Ecosystems: pypi
Packages: Zope2
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTQ4dnYtMnBtcS05ZnZ2
Moderate severity vulnerability that affects Plone and Zope2
Ecosystems: pypi
Packages: Plone, Zope2
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTNxcHItN3JtZy03M3Y4
Moderate severity vulnerability that affects Plone and Zope2
Ecosystems: pypi
Packages: Plone, Zope2
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA3aDktdmY5Mi01Zmo1
Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool
Ecosystems: pypi
Packages: Products.CMFPlone, Products.PasswordResetTool
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXBjd20tOGpjMy1xeHZq
Plone Denial of Service vulnerability
Ecosystems: pypi
Packages: Plone
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXBxM3gtOTZjMy14Z2pn
Moderate severity vulnerability that affects Products.PlonePAS
Ecosystems: pypi
Packages: Products.PlonePAS
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc5ODItOXI4Zy02cXh3
Ciborg gem for Ruby allows local users to write files and gain privileges via Symlink
Ecosystems: rubygems
Packages: ciborg
Source: GitHub Advisory Database
Blast Radius: 2.6
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJ2ajktOGN2eC0zdnE5
Invalid Curve Attack in node-jose
Ecosystems: npm
Packages: node-jose
Source: GitHub Advisory Database
Blast Radius: 20.2
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFtbTkteDVnci00Z2Zt
Open Redirect in hekto
Ecosystems: npm
Packages: hekto
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWgyNGYtOW1tNC13MzM2
Cross-site Scripting (XSS) - Stored in crud-file-server
Ecosystems: npm
Packages: crud-file-server
Source: GitHub Advisory Database
Blast Radius: 2.9
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTY4NmctM3hyMy14NHg2
Information Exposure on Case Insensitive File Systems in serve
Ecosystems: npm
Packages: serve
Source: GitHub Advisory Database
Blast Radius: 26.6
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNxOTQtcWY2cS1tZjJo
Pysaml2 improperly initializes encryption vector
Ecosystems: pypi
Packages: pysaml2
Source: GitHub Advisory Database
Blast Radius: 13.7
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhwNW0tNGM5Zi00OThx
django-epiceditor vulnerable to XSS in form field
Ecosystems: pypi
Packages: django-epiceditor
Source: GitHub Advisory Database
Blast Radius: 5.8
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW0yNDItd2M4Ni04NzY4
python-fedora vulnerable to an open redirect resulting in loss of CSRF protection
Ecosystems: pypi
Packages: python-fedora
Source: GitHub Advisory Database
Blast Radius: 10.5
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhjcDgtaGg3NC1mNm1j
oslo.middleware Information Disclosure vulnerability
Ecosystems: pypi
Packages: oslo.middleware
Source: GitHub Advisory Database
Blast Radius: 14.0
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWN3aDUtM2N3Ny00Mjg2
tlslite-ng off-by-one error on mac checking
Ecosystems: pypi
Packages: tlslite-ng
Source: GitHub Advisory Database
Blast Radius: 12.2
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFjNTUtdm0zai03NGdw
JSNAPy allows unprivileged local users to alter files under the directory
Ecosystems: pypi
Packages: jsnapy
Source: GitHub Advisory Database
Blast Radius: 9.4
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA2aDktZ3c0OS1ycW00
markdown2 is vulnerable to cross-site scripting
Ecosystems: pypi
Packages: markdown2
Source: GitHub Advisory Database
Blast Radius: 22.0
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA1d3ItdnA4Zy1xNXA0
Plone Sandbox Escape
Ecosystems: pypi
Packages: Plone
Source: GitHub Advisory Database
Blast Radius: 3.6
Published: about 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZ3cmYtcjVyNC03Nzc1
Incorrect handling of CORS preflight request headers in hapi
Ecosystems: npm
Packages: hapi
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1xMzUtd3F2Zi1yMjNj
Sinatra Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: sinatra
Source: GitHub Advisory Database
Blast Radius: 31.5
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWd2cHgtOTQ1OS13M21q
Cross-Site Scripting in @ckeditor/ckeditor5-link
Ecosystems: npm
Packages: @ckeditor/ckeditor5-link
Source: GitHub Advisory Database
Blast Radius: 22.0
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXB4M3Itam05Zy1jOHc4
rails-html-sanitizer Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: rails-html-sanitizer
Source: GitHub Advisory Database
Blast Radius: 34.9
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZwY2gtcnh3My1mZ3g4
Cross-Site Scripting in @risingstack/protect
Ecosystems: npm
Packages: @risingstack/protect
Source: GitHub Advisory Database
Blast Radius: 8.3
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTg4MnAtanFnbS1mNDVn
Uncontrolled resource consumption in nokogiri
Ecosystems: rubygems
Packages: nokogiri
Source: GitHub Advisory Database
Blast Radius: 39.3
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg3cnYtY3I2di00dm00
Cross-site Scripting in loofah
Ecosystems: rubygems
Packages: nokogiri, loofah
Source: GitHub Advisory Database
Blast Radius: 36.8
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWh3aGgtMmZ3bS1jZmd3
Doorkeeper is vulnerable to stored XSS and code execution
Ecosystems: rubygems
Packages: doorkeeper
Source: GitHub Advisory Database
Blast Radius: 22.8
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZ3cHYtY2o2eC12M2p3
http vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Ecosystems: rubygems
Packages: http
Source: GitHub Advisory Database
Blast Radius: 25.0
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTY4OGMtM3g0OS02cnFq
rack-protection gem timing attack vulnerability when validating CSRF token
Ecosystems: rubygems
Packages: rack-protection
Source: GitHub Advisory Database
Blast Radius: 30.1
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTMyNWotMjRmNC1xdjV4
Regular Expression Denial of Service in ssri
Ecosystems: npm
Packages: ssri
Source: GitHub Advisory Database
Blast Radius: 35.3
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXB4cjgtdzNqcS1yY3dq
rails_admin ruby gem XSS
Ecosystems: rubygems
Packages: rails_admin
Source: GitHub Advisory Database
Blast Radius: 24.2
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThwMnAtcDhtZy14M2N3
Insight API transaction broadcast endpoint can result in Full Path Disclosure
Ecosystems: npm
Packages: insight-api
Source: GitHub Advisory Database
Blast Radius: 6.5
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXc3cTkteHIyeC13aDd4
delayed_job_web Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: delayed_job_web
Source: GitHub Advisory Database
Blast Radius: 15.7
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXdmd20tY2hqNy13NTly
Ox gem stack overflow in sax_parse
Ecosystems: rubygems
Packages: ox
Source: GitHub Advisory Database
Blast Radius: 16.9
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWgyOWYtN2Y1Ni1qOHdo
Sinatra Path Traversal vulnerability
Ecosystems: rubygems
Packages: sinatra
Source: GitHub Advisory Database
Blast Radius: 27.4
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZ4NDUtODZxNi1yY21y
Gyazo allows local users to write arbitrary files
Ecosystems: rubygems
Packages: gyazo
Source: GitHub Advisory Database
Blast Radius: 5.9
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJteGctNzNnZy00cDk4
Cross-Site Scripting (XSS) in jquery
Ecosystems: maven, rubygems, npm, nuget
Packages: org.webjars.npm:jquery, jquery-rails, jquery, jQuery
Source: GitHub Advisory Database
Blast Radius: 104.9
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW12dzgtdjc2Ny1xaGpt
Radiant CMS vulnerable to Cross-site Scripting
Ecosystems: rubygems
Packages: radiant
Source: GitHub Advisory Database
Blast Radius: 9.2
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW03cDgtOXc2Ni05ZnJt
net-ldap Improper Certificate Validation vulnerability
Ecosystems: rubygems
Packages: net-ldap
Source: GitHub Advisory Database
Blast Radius: 22.8
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTdweDctN3hqeC1oeG04
Marked vulnerable to XSS from data URIs
Ecosystems: npm
Packages: marked
Source: GitHub Advisory Database
Blast Radius: 34.6
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg5bWotZmdoYy02NjR3
Denial of Service in mqtt
Ecosystems: npm
Packages: mqtt
Source: GitHub Advisory Database
Blast Radius: 26.3
Published: over 6 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWh3Y2YtcHA4Ny03eDZw
mde ejs vulnerable to XSS
Ecosystems: npm
Packages: ejs
Source: GitHub Advisory Database
Blast Radius: 37.7
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWh4aGotaHA5bS1xd2M0
private_address_check vulnerable to bypass of Resolv.getaddresses method
Ecosystems: rubygems
Packages: private_address_check
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTY1M20tcjMzeC0zOWZm
Geminabox contains Cross-site Scripting
Ecosystems: rubygems
Packages: geminabox
Source: GitHub Advisory Database
Blast Radius: 14.9
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg3cDIteDJqNi1td2hy
Gemirro Stored XSS in Gemspec "homepage" value
Ecosystems: rubygems
Packages: gemirro
Source: GitHub Advisory Database
Blast Radius: 1.8
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTdjdjYtZ3Z4My1tNTRt
Cross-Site Scripting in keystone
Ecosystems: npm
Packages: keystone
Source: GitHub Advisory Database
Blast Radius: 14.1
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTV2M2YtNzNndi14N3g1
cairo is vulnerable to denial of service due to a null pointer dereference
Ecosystems: rubygems
Packages: cairo
Source: GitHub Advisory Database
Blast Radius: 16.6
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTdxY3gtam1yYy1oMnJy
Cross-Site Scripting in keystone
Ecosystems: npm
Packages: keystone
Source: GitHub Advisory Database
Blast Radius: 17.9
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZjcWYtaDRoNC02OTVt
actionpack CRLF injection vulnerability
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTc1dzYtcDZtZy12aDhq
Rails actionpack gem vulnerable to Cross-site Scripting
Ecosystems: rubygems
Packages: actionview, actionpack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZqZmctcTY2Mi1nbTZq
Moderate severity vulnerability that affects rails
Ecosystems: rubygems
Packages: rails
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTJ4amotNXg2aC04dm1m
Cross-site Scripting in actionpack
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXF2OHAtdjlxdy13Yzdn
activesupport Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: activesupport
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlmaDMtdmgzaC1xNGcz
activesupport Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: activesupport
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhncHAtcHA4OS00Zmdm
Action Pack contains database-query restrictions bypass
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlwM3Ytd2Yydy12Mjlj
Moderate severity vulnerability that affects rails
Ecosystems: rubygems
Packages: rails
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThxcmgtaDltMi01ZnZm
Cross site scripting that affects rails
Ecosystems: rubygems
Packages: activesupport, actionpack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZtcTItMzdqNS13NnI2
WEBrick Improper Input Validation vulnerability
Ecosystems: rubygems
Packages: webrick
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWdqeHctNXcycS03Z3Jm
Rails activerecord gem has Improper Input Validation vulnerability
Ecosystems: rubygems
Packages: activerecord
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhnajYtcGdybS14NHIy
gtk2 vulnerable to Use of Externally-Controlled Format String
Ecosystems: rubygems
Packages: gtk2
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWdtMjUtZnBtci00M2Zq
Moderate severity vulnerability that affects rails
Ecosystems: rubygems
Packages: rails
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNqOTItYzRmai13OWM1
Mail Gem Path Traversal vulnerability
Ecosystems: rubygems
Packages: mail
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZoMzktdjczMy1teGZy
Active Record vulnerable to SQL Injection via nested query parameters
Ecosystems: rubygems
Packages: activerecord
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXEzNGMtNDhnYy1tOWc4
actionpack allows remote attackers to bypass database-query restrictions, perform NULL checks via crafted request
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZnOXctZzZtNC01NTdq
actionpack and activesupport vulnerable to information leaks
Ecosystems: rubygems
Packages: activesupport, actionpack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTkydzktMnBxdy1yaGpq
actionpack Improper Authentication vulnerability
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThmcXgtN3B2NC0zandt
Improper Input Validation in actionpack
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXY5djQtN2pwNi04Yzcz
rails Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: activesupport, actionpack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTN2ZnctN3JjcC0zeGdt
actionpack Improper Input Validation vulnerability
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWptZ2YtcDQ2eC05ODJo
rails is vulnerable to CRLF injection
Ecosystems: rubygems
Packages: rails
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA0YzYtNzdnYy02OTR4
session fixation protection mechanism in cgi_process.rb in Rails
Ecosystems: rubygems
Packages: rails
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWp3aHYtcmdxYy1mcWo1
Session fixation vulnerability in Rails
Ecosystems: rubygems
Packages: rails
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXh4cjgtODMzdi1jN3dj
Cross-site Scripting vulnerability in i18n translations helper method
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTI0ZmctcDk2di1oeGg4
actionpack Cross-Site Request Forgery vulnerability
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXI3cTItNWdxZy02Yzdx
actionpack Improper Input Validation vulnerability
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXdjbTItOWM4OS13bWZt
Cross-site Scripting in jquery-ui
Ecosystems: rubygems, nuget, maven, npm
Packages: jquery-ui-rails, jQuery.UI.Combined, org.webjars.npm:jquery-ui, jquery-ui
Source: GitHub Advisory Database
Blast Radius: 55.7
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNwamMtcDdmYy1qOXho
Mail Improper Input Validation vulnerability
Ecosystems: rubygems
Packages: mail
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXY1amctNTU4ai1xNjdj
actionpack Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNqNDMtOWgzdy12OTc2
Puppet allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service
Ecosystems: rubygems
Packages: puppet
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTljMmotNTkzcS0zZzgy
activesupport Improper Input Validation vulnerability
Ecosystems: rubygems
Packages: activesupport
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg3N3gtbTVxOC1jMjlo
Rack vulnerable to REDoS
Ecosystems: rubygems
Packages: rack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWcyNjYtM2NyaC1oN2dq
ldoce Gem Arbitrary Command Execution
Ecosystems: rubygems
Packages: ldoce
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTk4bWYtOGY1Ny02NHFm
actionpack Cross-site Scripting vulnerability
Ecosystems: rubygems
Packages: actionpack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZnbXgtOGg5My0yNmZo
omniauth-oauth2 Cross-Site Request Forgery vulnerability
Ecosystems: rubygems
Packages: omniauth-oauth2
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWdwcHAtNXhjNS13ZnB4
Active Record allows bypassing of database-query restrictions
Ecosystems: rubygems
Packages: activerecord
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWp4eDgtdjgzdi1yaHcz
Spree Improper Input Validation vulnerability
Ecosystems: rubygems
Packages: spree
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXc2cmMtcTM4Ny12cGdx
insecure temporary directory usage in passenger
Ecosystems: rubygems
Packages: passenger
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWp4aHctbWc4bS0ycGo4
Devise does not properly perform type conversion when performing database queries
Ecosystems: rubygems
Packages: devise
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJwcmotZzZ4Yy1wNWdx
Wicked gem contains Path traversal vulnerability
Ecosystems: rubygems
Packages: wicked
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWM0M3YtaHJtZy01NnI0
Cocaine Gem OS Command Injection vulnerability
Ecosystems: rubygems
Packages: cocaine
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTNjcnItOXZtZy04NjR2
Active Record Improper Input Validation
Ecosystems: rubygems
Packages: activerecord
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE2Y3ctMjU1My03ODM3
newrelic_rpm Gem Discloses Sensitive Information
Ecosystems: rubygems
Packages: newrelic_rpm
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFxeHAteHA5di12dng2
jquery-ui Tooltip widget vulnerable to XSS
Ecosystems: nuget, maven, rubygems, npm
Packages: jQuery.UI.Combined, org.webjars.npm:jquery-ui, jquery-ui-rails, jquery-ui
Source: GitHub Advisory Database
Blast Radius: 1.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJnNW0tM2ZxcC02cHg4
actionmailer email address processing causes Denial of service
Ecosystems: rubygems
Packages: actionmailer
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTNweGgtaDhody1tajh3
Rack rubygems receiving excessively long lines triggers out-of-memory error
Ecosystems: rubygems
Packages: rack
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 7 years ago
Statistics
Advisories: 20,108
Packages: 8,840
Repositories: 2,654
Ecosystems: 12
Filter by Package
moodle/moodle 262 tensorflow 207 tensorflow-gpu 203 tensorflow-cpu 201 typo3/cms 119 magento/community-edition 115 org.jenkins-ci.main:jenkins-core 115 org.apache.tomcat:tomcat 91 pimcore/pimcore 86 typo3/cms-core 72 microweber/microweber 65 silverstripe/framework 64 dolibarr/dolibarr 55 apache-airflow 53 phpmyadmin/phpmyadmin 50 drupal/core 47 github.com/usememos/memos 45 thorsten/phpmyfaq 45 actionpack 43 Django 42 apache-superset 42 drupal/drupal 39 github.com/mattermost/mattermost/server/v8 37 github.com/grafana/grafana 36 concrete5/concrete5 36 plone 35 showdoc/showdoc 34 org.keycloak:keycloak-core 34 librenms/librenms 32 symfony/symfony 32 ansible 32 nova 32 Plone 32 github.com/mattermost/mattermost-server/v6 30 craftcms/cms 28 moin 28 org.elasticsearch:elasticsearch 28 intelliants/subrion 26 com.liferay.portal:release.portal.bom 25 django 24 snipe/snipe-it 24 baserproject/basercms 22 k8s.io/kubernetes 22 github.com/answerdev/answer 21 grumpydictator/firefly-iii 20 org.apache.struts:struts2-core 20 shopware/shopware 19 shopware/platform 19 keystone 18 matrix-synapse 18 froxlor/froxlor 18 rdiffweb 18 remdex/livehelperchat 18 nilsteampassnet/teampass 18 mediawiki/core 18 zendframework/zendframework1 17 github.com/docker/docker 17 glance 16 org.apache.tomcat.embed:tomcat-embed-core 16 getkirby/cms 16 github.com/argoproj/argo-cd/v2 16 directus 16 org.keycloak:keycloak-services 15 prestashop/prestashop 15 salt 15 vyper 15 mautic/core 15 org.xwiki.platform:xwiki-platform-oldcore 14 io.undertow:undertow-core 14 github.com/cilium/cilium 14 shopware/core 14 github.com/hashicorp/vault 14 nokogiri 14 tinymce 14 yetiforce/yetiforce-crm 14 puppet 14 tribalsystems/zenario 13 com.jfinal:jfinal 13 forkcms/forkcms 13 org.apache.jspwiki:jspwiki-main 13 Pillow 13 github.com/goharbor/harbor 12 github.com/hashicorp/consul 12 neutron 12 roundup 12 com.thoughtworks.xstream:xstream 12 contao/core-bundle 12 simplesamlphp/simplesamlphp 12 github.com/hashicorp/nomad 12 feehi/feehicms 11 org.keycloak:keycloak-parent 11 ec-cube/ec-cube 11 lavalite/cms 11 getgrav/grav 11 org.apache.solr:solr-core 11 rack 11 genix/cms 11 org.springframework.security:spring-security-core 11 TinyMCE 11 DotNetNuke.Core 11 tinymce/tinymce 11 pyftpdlib 11 github.com/argoproj/argo-cd 11 org.bouncycastle:bcprov-jdk14 11 PaddlePaddle 10 francoisjacquet/rosariosis 10 @openzeppelin/contracts-upgradeable 10 bootstrap 10 bootstrap 10 org.bouncycastle:bcprov-jdk15on 10 typo3/cms-backend 10 fat_free_crm 10 org.eclipse.jetty:jetty-server 10 silverstripe/cms 10 ghost 10 github.com/mattermost/mattermost-server 10 joplin 10 org.apache.jspwiki:jspwiki-war 10 ckeditor4 10 github.com/greenpau/caddy-security 10 github.com/containerd/containerd 10 github.com/ethereum/go-ethereum 10 org.apache.nifi:nifi 10 opencart/opencart 10 com.vaadin:vaadin-bom 10 activesupport 10 zendframework/zendframework 10 org.springframework:spring-core 10 @openzeppelin/contracts 10 bolt/bolt 10 wallabag/wallabag 10 bootstrap 9 org.webjars:bootstrap 9 org.opencrx:opencrx-core-models 9 code.gitea.io/gitea 9 rubygems-update 9 aiohttp 9 org.igniterealtime.openfire:parent 9 notebook 9 helm.sh/helm/v3 9 cakephp/cakephp 9 angular 9 wagtail 9 org.opencms:opencms-core 9 github.com/traefik/traefik/v2 9 org.mortbay.jetty:jetty 9 twbs/bootstrap 9 publify_core 9 gogs.io/gogs 9 org.jenkins-ci.plugins:git 9 swagger-ui 9 horizon 9 sylius/sylius 8 rails 8 contao/contao 8 org.jenkins-ci.plugins:script-security 8 github.com/kubeedge/kubeedge 8 editor.md 8 org.apache.activemq:activemq-client 8 jquery-rails 8 org.jenkins-ci.plugins:electricflow 8 pimcore/admin-ui-classic-bundle 8 github.com/openfga/openfga 8 wasmtime 8 laravel/framework 8 github.com/rancher/rancher 8 github.com/zitadel/zitadel 8 rails-html-sanitizer 8 impresscms/impresscms 8 centreon/centreon 8 gradio 8 bootstrap.sass 8 actionview 8 opencv-python 8 opencv-contrib-python 8 electron 8 Microsoft.ChakraCore 8 org.apache.santuario:xmlsec 7 jQuery.UI.Combined 7 io.jenkins.blueocean:blueocean 7 org.webjars.npm:jquery-ui 7 jquery-ui-rails 7 jquery-ui 7 modoboa 7 org.opennms:opennms 7 admidio/admidio 7 phpmyfaq/phpmyfaq 7 org.bouncycastle:bcprov-jdk15 7 org.owasp.antisamy:antisamy 7 kevinpapst/kimai2 7 urllib3 7 org.jenkins-ci.plugins:email-ext 7 github.com/moby/moby 7 silverstripe/admin 7 feehi/cms 7 validator 7 org.jenkins-ci.plugins:subversion 7 symfony/http-foundation 7 io.jenkins:configuration-as-code 7 pyload-ng 7
Filter by Repository
https://github.com/tensorflow/tensorflow 207 https://github.com/moodle/moodle 167 https://github.com/jenkinsci/jenkins 91 https://github.com/pimcore/pimcore 83 https://github.com/microweber/microweber 61 https://github.com/apache/airflow 53 https://github.com/TYPO3/typo3 53 https://github.com/apache/tomcat 53 https://github.com/django/django 51 https://github.com/silverstripe/silverstripe-framework 47 https://github.com/thorsten/phpmyfaq 45 https://github.com/usememos/memos 45 https://github.com/xwiki/xwiki-platform 43 https://github.com/rails/rails 35 https://github.com/kubernetes/kubernetes 34 https://github.com/star7th/showdoc 32 https://github.com/keycloak/keycloak 30 https://github.com/grafana/grafana 30 https://github.com/ansible/ansible 30 https://github.com/librenms/librenms 30 https://github.com/plone/Products.CMFPlone 29 https://github.com/symfony/symfony 26 https://github.com/craftcms/cms 23 https://github.com/Dolibarr/dolibarr 22 https://github.com/spring-projects/spring-framework 22 https://github.com/phpmyadmin/phpmyadmin 22 https://github.com/argoproj/argo-cd 22 https://github.com/concretecms/concretecms 21 https://github.com/openstack/nova 21 https://github.com/answerdev/answer 21 https://github.com/snipe/snipe-it 20 https://github.com/magento/magento2 20 https://github.com/firefly-iii/firefly-iii 20 https://github.com/apache/activemq 19 https://github.com/python-pillow/Pillow 18 https://github.com/ikus060/rdiffweb 18 https://github.com/livehelperchat/livehelperchat 18 https://github.com/shopware/shopware 17 https://github.com/shopware/platform 17 https://github.com/matrix-org/synapse 17 https://github.com/apache/struts 17 https://github.com/openstack/keystone 16 https://github.com/vyperlang/vyper 15 https://github.com/mautic/mautic 15 https://github.com/directus/directus 15 https://github.com/CVEProject/cvelist 15 https://github.com/cilium/cilium 14 https://github.com/PaddlePaddle/Paddle 14 https://github.com/froxlor/froxlor 14 https://github.com/OpenNMS/opennms 14 https://github.com/apache/cxf 14 https://github.com/TYPO3/TYPO3.CMS 14 https://github.com/tinymce/tinymce 14 https://github.com/yetiforcecompany/yetiforcecrm 14 https://github.com/go-gitea/gitea 13 https://github.com/getkirby/kirby 13 https://github.com/octobercms/october 13 https://github.com/x-stream/xstream 13 https://github.com/contao/contao 13 https://github.com/PrestaShop/PrestaShop 12 https://github.com/goharbor/harbor 12 https://github.com/netty/netty 12 https://github.com/saltstack/salt 11 https://github.com/forkcms/forkcms 11 https://github.com/moby/moby 11 https://github.com/vaadin/platform 10 https://github.com/containerd/containerd 10 https://github.com/nilsteampassnet/TeamPass 10 https://github.com/OpenZeppelin/openzeppelin-contracts 10 https://github.com/greenpau/caddy-security 10 https://github.com/traefik/traefik 10 https://github.com/simplesamlphp/simplesamlphp 10 https://github.com/apache/nifi 10 https://github.com/liufee/cms 10 https://github.com/laurent22/joplin 10 https://github.com/mattermost/mattermost 10 https://github.com/intelliants/subrion 10 https://github.com/ethereum/go-ethereum 10 https://github.com/strapi/strapi 10 https://github.com/geoserver/geoserver 10 https://github.com/umbraco/Umbraco-CMS 10 https://github.com/baserproject/basercms 10 https://github.com/github/advisory-database 9 https://github.com/jenkinsci/git-plugin 9 https://github.com/aio-libs/aiohttp 9 https://github.com/fatfreecrm/fat_free_crm 9 https://github.com/TYPO3-CMS/core 9 https://github.com/jquery/jquery 9 https://github.com/electron/electron 9 https://github.com/sparklemotion/nokogiri 9 https://github.com/puppetlabs/puppet 9 https://github.com/helm/helm 9 https://github.com/backstage/backstage 9 https://github.com/ckeditor/ckeditor4 9 https://github.com/TryGhost/Ghost 9 https://github.com/zitadel/zitadel 9 https://github.com/openstack/glance 9 https://github.com/rack/rack 9 https://github.com/wagtail/wagtail 9 https://github.com/publify/publify 9 https://github.com/pimcore/admin-ui-classic-bundle 8 https://github.com/pandao/editor.md 8 https://github.com/wallabag/wallabag 8 https://github.com/openfga/openfga 8 https://github.com/rancher/rancher 8 https://github.com/apache/zeppelin 8 https://github.com/hashicorp/consul 8 https://github.com/jupyter/notebook 8 https://github.com/decidim/decidim 8 https://github.com/kubeedge/kubeedge 8 https://github.com/bytecodealliance/wasmtime 8 https://github.com/zendframework/zendframework 8 https://github.com/swagger-api/swagger-ui 8 https://github.com/rails/rails-html-sanitizer 8 https://github.com/bcgit/bc-java 8 https://github.com/dotnet/runtime 8 https://github.com/getgrav/grav 8 https://github.com/nilsteampassnet/teampass 8 https://github.com/rubygems/rubygems 8 https://github.com/LavaLite/cms 8 https://github.com/eclipse/jetty.project 8 https://github.com/google/fscrypt 7 https://github.com/laravel/framework 7 https://github.com/giampaolo/pyftpdlib 7 https://github.com/gogs/gogs 7 https://github.com/vantage6/vantage6 7 https://github.com/openstack/horizon 7 https://github.com/jeecgboot/jeecg-boot 7 https://github.com/pyload/pyload 7 https://github.com/Sylius/Sylius 7 https://github.com/chakra-core/ChakraCore 7 https://github.com/hashicorp/vault 7 https://github.com/thorsten/phpMyFAQ 7 https://github.com/dolibarr/dolibarr 7 https://github.com/modoboa/modoboa 7 https://github.com/opencv/opencv 7 https://github.com/jenkinsci/blueocean-plugin 7 https://github.com/twbs/bootstrap 7 https://github.com/kevinpapst/kimai2 7 https://github.com/urllib3/urllib3 7 https://github.com/1Panel-dev/1Panel 7 https://github.com/vaadin/flow 7 https://github.com/scrapy/scrapy 7 https://github.com/nahsra/antisamy 7 https://github.com/panva/jose 6 https://github.com/opensearch-project/security 6 https://github.com/jenkinsci/configuration-as-code-plugin 6 https://github.com/nocodb/nocodb 6 https://github.com/croogo/croogo 6 https://github.com/pimcore/customer-data-framework 6 https://github.com/parse-community/parse-server 6 https://github.com/jenkinsci/fortify-on-demand-uploader-plugin 6 https://github.com/jenkinsci/config-file-provider-plugin 6 https://github.com/opencart/opencart 6 https://github.com/puma/puma 6 https://github.com/zenml-io/zenml 6 https://github.com/jenkinsci/script-security-plugin 6 https://github.com/yiisoft/yii2 6 https://github.com/stacklok/minder 6 https://github.com/dompdf/dompdf 6 https://github.com/onionshare/onionshare 6 https://github.com/gradio-app/gradio 6 https://github.com/d4wner/Vulnerabilities-Report 6 https://github.com/containers/podman 6 https://github.com/cui2shark/security 6 https://github.com/oroinc/orocommerce 6 https://github.com/ckan/ckan 6 https://github.com/apache/superset 6 https://github.com/neorazorx/facturascripts 6 https://github.com/pomerium/pomerium 6 https://github.com/jquery/jquery-ui 6 https://github.com/igniterealtime/Openfire 6 https://github.com/cubefs/cubefs 6 https://github.com/opencast/opencast 6 https://github.com/cloudflare/cfrpki 6 https://github.com/tornadoweb/tornado 6 https://github.com/bolt/bolt 5 https://github.com/Amanieu/parking_lot 5 https://github.com/hyperium/hyper 5 https://github.com/paritytech/frontier 5 https://github.com/vercel/next.js 5 https://github.com/openstack/cinder 5 https://github.com/nodejs/undici 5 https://github.com/langchain-ai/langchain 5 https://github.com/centreon/centreon-archived 5 https://github.com/nervosnetwork/ckb 5 https://github.com/pyca/cryptography 5 https://github.com/surrealdb/surrealdb 5 https://github.com/undertow-io/undertow 5 https://github.com/cakephp/cakephp 5 https://github.com/cri-o/cri-o 5 https://github.com/roundup-tracker/roundup 5 https://github.com/NodeBB/NodeBB 5 https://github.com/lief-project/LIEF 5 https://github.com/admidio/admidio 5 https://github.com/vitejs/vite 5 https://github.com/cloudfoundry/uaa 5 https://github.com/sulu/sulu 5 https://github.com/hashicorp/nomad 5