Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Low Security Advisories

Loading...
Low
GSA_kwCzR0hTQS12NWY2LWhqbWYtOW1jNc4AA3lG
PyDrive2's unsafe YAML deserialization in LoadSettingsFile allows arbitrary code execution
Ecosystems: pypi
Packages: PyDrive2
Source: GitHub Advisory Database
Published: about 1 hour ago
Low
GSA_kwCzR0hTQS14OXFxLTIzNmotZ2o5N84AA3lE
Canonical LXD documentation improvement to make clear restricted.devices.disk=allow without restricted.devices.disk.paths also allows shift=true
Ecosystems: go
Packages: github.com/canonical/lxd
Source: GitHub Advisory Database
Published: about 1 hour ago
Low
GSA_kwCzR0hTQS1oNTZnLWdxOXYtdmM4cs4AA3kx
jupyter-server errors include tracebacks with path information
Ecosystems: pypi
Packages: jupyter-server
Source: GitHub Advisory Database
Published: about 7 hours ago
Low
GSA_kwCzR0hTQS04aGM1LXJtZ2YtcXg2cM4AA3a0
Keycloak vulnerable to LDAP Injection on UsernameForm Login
Ecosystems: maven
Packages: org.keycloak:keycloak-services, org.keycloak:keycloak-ldap-federation
Source: GitHub Advisory Database
Published: 6 days ago
Low
GSA_kwCzR0hTQS00MjMzLTdxNXEtbTdwNs4AA3Yl
google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability
Ecosystems: npm
Packages: google-translate-api-browser
Source: GitHub Advisory Database
Published: 8 days ago
Low
GSA_kwCzR0hTQS1qY2d2LTNwZnEtajRocs4AA3Xh
Mattermost Injection vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost/server/v8
Source: GitHub Advisory Database
Published: 9 days ago
Low
GSA_kwCzR0hTQS04NXA0LXEzNTctNzJoOc4AA3WE
Apache Storm Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files
Ecosystems: maven
Packages: org.apache.storm:storm-core
Source: GitHub Advisory Database
Published: 13 days ago
Low
GSA_kwCzR0hTQS1oeDkzLWdjNzMtNXJwcs4AA3TE
Exposure of Sensitive Information in Elastic APM .NET Agent
Ecosystems: nuget
Packages: Elastic.Apm
Source: GitHub Advisory Database
Published: 14 days ago
Low
GSA_kwCzR0hTQS0zNmZyLTN3ZzgtcTV2OM4AA3O6
Concrete CMS Cross-site Scripting vulnerability
Ecosystems: packagist
Packages: concrete5/concrete5
Source: GitHub Advisory Database
Published: 19 days ago
Low
GSA_kwCzR0hTQS14eDlwLXh4dmgtN2c4as4AA3Hw
Aiohttp has inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` differing in C and Python fallbacks
Ecosystems: pypi
Packages: aiohttp
Source: GitHub Advisory Database
Published: 21 days ago
Low
GSA_kwCzR0hTQS1wMmpoLTk1amctMnc1Nc4AA3Hv
Information Disclosure in typo3/cms-install tool
Ecosystems: packagist
Packages: typo3/cms-install
Source: GitHub Advisory Database
Published: 21 days ago
Low
GSA_kwCzR0hTQS1yamptLXgzMnAtbTNmN84AA3C1
gnark's range checker gadget allows wider inputs up to word alignment
Ecosystems: go
Packages: github.com/consensys/gnark
Source: GitHub Advisory Database
Published: 23 days ago
Low
GSA_kwCzR0hTQS1qcjgzLTh4NjUteGNyNc4AA3Bu
Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Ecosystems: packagist
Packages: moodle/moodle
Source: GitHub Advisory Database
Published: 26 days ago
Low
GSA_kwCzR0hTQS03MmZwLXc0NGctNjI1cc4AA3BG
Signing DynamoDB Sets when using the AWS Database Encryption SDK.
Ecosystems: maven
Packages: software.amazon.cryptography:aws-database-encryption-sdk-dynamodb
Source: GitHub Advisory Database
Published: 26 days ago
Low
GSA_kwCzR0hTQS1yMnh2LXZwcjItNDJtOc4AA2_p
slsa-verifier vulnerable to mproper validation of npm's publish attestations
Ecosystems: go
Packages: github.com/slsa-framework/slsa-verifier, github.com/slsa-framework/slsa-verifier/v2
Source: GitHub Advisory Database
Published: 27 days ago
Low
GSA_kwCzR0hTQS00NzV2LXBxMmctZnA5Z84AA2_T
s2n-quic potential denial of service via crafted stream frames
Ecosystems: cargo
Packages: s2n-quic
Source: GitHub Advisory Database
Published: 27 days ago
Low
GSA_kwCzR0hTQS12ZnA2LWpydzItOTlnOc4AA2_S
Cosign vulnerable to possible endless data attack from attacker-controlled registry
Ecosystems: go
Packages: github.com/sigstore/cosign, github.com/sigstore/cosign/v2
Source: GitHub Advisory Database
Published: 27 days ago
Low
GSA_kwCzR0hTQS1qNTdyLTRxdzYtNThyM84AA2-Z
rusty_paseto vulnerable to private key extraction due to ed25519-dalek dependency
Ecosystems: cargo
Packages: rusty-paseto
Source: GitHub Advisory Database
Published: 28 days ago
Low
GSA_kwCzR0hTQS04cHA2LTVxcHctODVnM84AA27H
Magnesium-PHP Injection vulnerability
Ecosystems: packagist
Packages: floriangaerber/magnesium
Source: GitHub Advisory Database
Published: about 1 month ago
Low
GSA_kwCzR0hTQS1ndjJjLTVnNzktaDczY84AA26t
Ibexa ezplatform-kernel download route allows filename change
Ecosystems: packagist
Packages: ezsystems/ezplatform-kernel
Source: GitHub Advisory Database
Published: about 1 month ago
Low
GSA_kwCzR0hTQS1nOTVjLXhjODMtODM1M84AA26s
Ibexa DXP Download route allows filename change
Ecosystems: packagist
Packages: ibexa/core
Source: GitHub Advisory Database
Published: about 1 month ago
Low
GSA_kwCzR0hTQS05NDZjLWY5dzYtMmMyNc4AA26n
Download route allows filename change in eZpublish kernel
Ecosystems: packagist
Packages: ezsystems/ezpublish-kernel
Source: GitHub Advisory Database
Published: about 1 month ago
Low
GSA_kwCzR0hTQS00N3h3LXZ3Nm0tdzlmcc4AA2wh
HashiCorp Vagrant Insecure Operation on Windows Junction / Mount Point vulnerability
Ecosystems: go
Packages: github.com/hashicorp/vagrant
Source: GitHub Advisory Database
Published: about 1 month ago
Low
GSA_kwCzR0hTQS1yODQ3LTZ3NmgtcjhnNM4AA2vp
Flyte Admin SQL Injection in List Filters
Ecosystems: go
Packages: github.com/flyteorg/flyteadmin
Source: GitHub Advisory Database
Published: about 1 month ago
Low
GSA_kwCzR0hTQS04ODU5LXY5anAtY3BoZs4AA2rz
Jenkins Multibranch Scan Webhook Trigger Plugin uses non-constant time webhook token comparison
Ecosystems: maven
Packages: igalg.jenkins.plugins:multibranch-scan-webhook-trigger
Source: GitHub Advisory Database
Published: about 1 month ago
Low
GSA_kwCzR0hTQS1ocHYzLWY1cDctcHhqOc4AA2rA
Jenkins lambdatest-automation Plugin may expose Credentials access token
Ecosystems: maven
Packages: org.jenkins-ci.plugins:lambdatest-automation
Source: GitHub Advisory Database
Published: about 1 month ago
Low
GSA_kwCzR0hTQS04ODVyLWhocHItY2M5cM4AA2rO
Jenkins Gogs Plugin uses non-constant time webhook token comparison
Ecosystems: maven
Packages: org.jenkins-ci.plugins:gogs-webhook
Source: GitHub Advisory Database
Published: about 1 month ago
Low
GSA_kwCzR0hTQS0yeHBxLTU5NTItMzh3M84AA2rM
Jenkins MSTeams Webhook Trigger Plugin uses non-constant time webhook token comparison
Ecosystems: maven
Packages: io.jenkins.plugins:teams-webhook-trigger
Source: GitHub Advisory Database
Published: about 1 month ago
Low
GSA_kwCzR0hTQS04Nmo5LTI1bTItOXc5N84AA2rS
Non-constant time webhook token hash comparison in Jenkins Zanata Plugin
Ecosystems: maven
Packages: org.jenkins-ci.plugins:zanata
Source: GitHub Advisory Database
Published: about 1 month ago
Low
GSA_kwCzR0hTQS1mZ2pqLTVqbXItZ2g4M84AA2oR
Fides JavaScript Injection Vulnerability in Privacy Center URL
Ecosystems: pypi
Packages: ethyca-fides
Source: GitHub Advisory Database
Published: about 1 month ago
Low
GSA_kwCzR0hTQS1oOW13LWdyZ3gtMmZoZs4AA2oM
sbt vulnerable to arbitrary file write via archive extraction (Zip Slip)
Ecosystems: maven
Packages: org.scala-sbt:io_3, org.scala-sbt:io_2.13, org.scala-sbt:io_2.12, org.scala-sbt:sbt
Source: GitHub Advisory Database
Published: about 1 month ago
Low
GSA_kwCzR0hTQS1jNTloLXI2cDgtcTl3Y84AA2m9
Next.js missing cache-control header may lead to CDN caching empty reply
Ecosystems: npm
Packages: next
Source: GitHub Advisory Database
Published: about 1 month ago
Low
GSA_kwCzR0hTQS05cGM4LW00dnAtZ2d2Zs4AA2kI
Artifact Hub allows unsafe rego built-in
Ecosystems: go
Packages: github.com/artifacthub/hub
Source: GitHub Advisory Database
Published: about 2 months ago
Low
GSA_kwCzR0hTQS1mYzc1LTU4cjgtcm0zaM4AA2kA
Wagtail vulnerable to disclosure of user names via admin bulk action views
Ecosystems: pypi
Packages: wagtail
Source: GitHub Advisory Database
Published: about 2 months ago
Low
GSA_kwCzR0hTQS1yZjU0LTdxcnItOTZqNs4AA2ea
vantage6 does not properly delete linked resources when deleting a collaboration
Ecosystems: pypi
Packages: vantage6
Source: GitHub Advisory Database
Published: about 2 months ago
Low
GSA_kwCzR0hTQS13cXE0LTV3cHYtbXgyZ84AA2eY
Undici's cookie header not cleared on cross-origin redirect in fetch
Ecosystems: npm
Packages: undici
Source: GitHub Advisory Database
Published: about 2 months ago
Low
GSA_kwCzR0hTQS0yYzI4LW0ybTctbWY1Nc4AA2c9
Pleroma Path Traversal vulnerability
Ecosystems: hex
Packages: pleroma
Source: GitHub Advisory Database
Published: about 2 months ago
Low
GSA_kwCzR0hTQS1wZmZnLTkyY2cteGY1Y84AA2Qs
gnark-crypto's exponentiation in the pairing target group GT using GLV can give incorrect results
Ecosystems: go
Packages: github.com/consensys/gnark-crypto
Source: GitHub Advisory Database
Published: 2 months ago
Low
GSA_kwCzR0hTQS1tNzU1LWd4eGctcjVxaM4AA2Pw
Zope management interface vulnerable to stored cross site scripting via the title property
Ecosystems: pypi
Packages: Zope
Source: GitHub Advisory Database
Published: 2 months ago
Low
GSA_kwCzR0hTQS1ocTU4LXA5bXYtMzM4Y84AA2Jf
CometBFT's default for `BlockParams.MaxBytes` consensus parameter may increase block times and affect consensus participation
Ecosystems: go
Packages: github.com/cometbft/cometbft
Source: GitHub Advisory Database
Published: 2 months ago
Low
GSA_kwCzR0hTQS1ycDY1LWpwYzctOGg4cM4AA2I7
Mattermost Incorrect Authorization vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost/server/v8
Source: GitHub Advisory Database
Published: 2 months ago
Low
GSA_kwCzR0hTQS1oOHdoLWY3Z3ctZndwcs4AA2I9
Mattermost Incorrect Authorization vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost/server/v8
Source: GitHub Advisory Database
Published: 2 months ago
Low
GSA_kwCzR0hTQS1tOTVxLTdxcDMteHY0Ms4AA2IO
Zod denial of service vulnerability
Ecosystems: npm
Packages: zod
Source: GitHub Advisory Database
Published: 2 months ago
Low
GSA_kwCzR0hTQS04OTZ2LXBoNXctMzc5aM4AA2Hj
Economizzer Insecure Direct Object Reference vulnerability
Ecosystems: packagist
Packages: gugoan/economizzer
Source: GitHub Advisory Database
Published: 2 months ago
Low
GSA_kwCzR0hTQS0yNG01LXI2aHYtY2NncM4AA2C5
Specific Cilium configurations vulnerable to DoS via Kubernetes annotations
Ecosystems: go
Packages: github.com/cilium/cilium
Source: GitHub Advisory Database
Published: 2 months ago
Low
GSA_kwCzR0hTQS03NTY1LWNxMzItdngyeM4AA2C2
matrix-synapse vulnerable to improper validation of receipts allows forged read receipts
Ecosystems: pypi
Packages: matrix-synapse
Source: GitHub Advisory Database
Published: 2 months ago
Low
GSA_kwCzR0hTQS00Zjc0LTg0djMtajlxNc4AA2C1
matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes
Ecosystems: pypi
Packages: matrix-synapse
Source: GitHub Advisory Database
Published: 2 months ago
Low
GSA_kwCzR0hTQS1oYzVjLXI4bTUtMmdmaM4AA1_4
plone.restapi vulnerable to Stored Cross Site Scripting with SVG image in user portrait
Ecosystems: pypi
Packages: plone.restapi
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS1qajdjLWpydjQtYzY1eM4AA1_2
plone.namedfile vulnerable to Stored Cross Site Scripting with SVG images
Ecosystems: pypi
Packages: plone.namedfile
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS0ycjNjLW02djctOTM1NM4AA1_x
sudo-rs Session File Relative Path Traversal vulnerability
Ecosystems: cargo
Packages: sudo-rs
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS12OGdyLW01MzMtZ2hqOc4AA1_w
Vulnerable OpenSSL included in cryptography wheels
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS13bThxLTk5NzUteGg1ds4AA1_u
Zope vulnerable to Stored Cross Site Scripting with SVG images
Ecosystems: pypi
Packages: Zope
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS1ocTg3LWg0amctdnhmd84AA1-C
Jenkins temporary uploaded file created with insecure permissions
Ecosystems: maven
Packages: org.jenkins-ci.main:jenkins-core
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS1xdjY0LXc5OWMtcWNyOc4AA1-K
Jenkins temporary uploaded file created with insecure permissions
Ecosystems: maven
Packages: org.jenkins-ci.main:jenkins-core
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS1mcnFjLWYyaDgtZmp2Zs4AA19h
Spring for GraphQL may be exposed to GraphQL context with values from a different session
Ecosystems: maven
Packages: org.springframework.graphql:spring-graphql
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS1wd2g4LTU4dnYtdnc0OM4AA15T
Jetty's OpenId Revoked authentication allows one request
Ecosystems: maven
Packages: org.eclipse.jetty:jetty-openid
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS1ndzVwLXE4bWotcDdnaM4AA14F
Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64
Ecosystems: cargo
Packages: wasmtime
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS0zZ2g2LXY1djktNnY5as4AA13n
Jetty vulnerable to errant command quoting in CGI Servlet
Ecosystems: maven
Packages: org.eclipse.jetty.ee8:jetty-ee8-servlets, org.eclipse.jetty.ee9:jetty-ee9-servlets, org.eclipse.jetty.ee10:jetty-ee10-servlets, org.eclipse.jetty:jetty-servlets
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS1wbXhxLXBqNDctajhqNM4AA1xF
Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes
Ecosystems: pypi, maven
Packages: wiremock, com.github.tomakehurst:wiremock-jre8-standalone, com.github.tomakehurst:wiremock-jre8, org.wiremock:wiremock, org.wiremock:wiremock-standalone
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS14YzI3LWY5cTMtNDQ0OM4AA1rH
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in hyper-bump-it
Ecosystems: pypi
Packages: hyper-bump-it
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS00OWhoLWZwcngtbTY4Z84AA1rB
Default functions in VolatileMemory trait lack bounds checks, potentially leading to out-of-bounds memory accesses
Ecosystems: cargo
Packages: vm-memory
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS1qNWczLTVjOHItN3FmeM4AA1lN
Prevent logging invalid header values
Ecosystems: npm
Packages: apollo-server-core, @apollo/server
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS0zN3hxLXE0MnAtcnYzcM4AA1fc
ntpd has Dependency on Vulnerable Third-Party Component
Ecosystems: cargo
Packages: ntpd
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS13cnJqLWg1N3Itdng5cM4AA1fa
Malicious dependencies can inject arbitrary JavaScript into cargo-generated timing reports
Ecosystems: cargo
Packages: cargo
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS1xNHBwLWozNmgtM2dxZ84AA1e3
Minimal `basti` IAM Policy Allows Shell Access
Ecosystems: npm
Packages: basti-cdk
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS1jcjVxLTZxOWYtcnE2cc4AA1eP
Active Support Possibly Discloses Locally Encrypted Files
Ecosystems: rubygems
Packages: activesupport
Source: GitHub Advisory Database
Published: 3 months ago
Low
GSA_kwCzR0hTQS01cjMzLW1namYtNjY1Ns4AA1Vz
Jenkins Tuleap Authentication Plugin non-constant time token comparison
Ecosystems: maven
Packages: io.jenkins.plugins:tuleap-oauth
Source: GitHub Advisory Database
Published: 4 months ago
Low
GSA_kwCzR0hTQS1nM3Y2LXI4cDktd3hnOc4AA1Pz
Mattermost fails to correctly delete attachments
Ecosystems: go
Packages: github.com/mattermost/mattermost-server/v6
Source: GitHub Advisory Database
Published: 4 months ago
Low
GSA_kwCzR0hTQS05cm1mLTZxZ2otZzN3as4AA1Og
Froxlor vulnerable to business logic errors
Ecosystems: packagist
Packages: froxlor/froxlor
Source: GitHub Advisory Database
Published: 4 months ago
Low
GSA_kwCzR0hTQS02cjc4LW02NG0tcXdjZs4AA1OC
Moq v4.20.0-rc to 4.20.1 share hashed user data
Ecosystems: nuget
Packages: moq
Source: GitHub Advisory Database
Published: 4 months ago
Low
GSA_kwCzR0hTQS1jN2hoLTN2NmMtZmo0cc4AA1De
matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms
Ecosystems: npm
Packages: matrix-appservice-irc
Source: GitHub Advisory Database
Published: 4 months ago
Low
GSA_kwCzR0hTQS1qbTc3LXFwaGYtYzR3OM4AA0_V
pyca/cryptography's wheels include vulnerable OpenSSL
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Published: 4 months ago
Low
GSA_kwCzR0hTQS0zNnh4LTd2ZjYtN212M84AA0-N
Silverstripe Framework: Members with no password can be created and bypass custom login forms
Ecosystems: packagist
Packages: silverstripe/framework
Source: GitHub Advisory Database
Published: 4 months ago
Low
GSA_kwCzR0hTQS02OHA0LTk1eGYtN2d4OM4AA08P
Denial of service from large image
Ecosystems: go
Packages: github.com/crossplane/crossplane
Source: GitHub Advisory Database
Published: 4 months ago
Low
GSA_kwCzR0hTQS1yeHZqLTVtdjYtajVtY84AA070
Cross-site Scripting in Mingsoft MCMS
Ecosystems: maven
Packages: net.mingsoft:ms-mcms
Source: GitHub Advisory Database
Published: 4 months ago
Low
GSA_kwCzR0hTQS1nY2g1LWh3cWYtbXhocM4AA069
Unsoundness in `intern` methods on `intaglio` symbol interners
Ecosystems: cargo
Packages: intaglio
Source: GitHub Advisory Database
Published: 4 months ago
Low
GSA_kwCzR0hTQS01amM1LW04N3gtODhmas4AA05e
Secret displayed without masking by Chef Identity Plugin
Ecosystems: maven
Packages: org.jenkins-ci.plugins:chef-identity
Source: GitHub Advisory Database
Published: 4 months ago
Low
GSA_kwCzR0hTQS1qcTZnLTR2NW0td205cs4AA04k
Information Disclosure due to Out-of-scope Site Resolution
Ecosystems: packagist
Packages: typo3/cms-core
Source: GitHub Advisory Database
Published: 4 months ago
Low
GSA_kwCzR0hTQS1yZmhnLXJqZnAtOXE4cc4AA03d
Potential denial of service after connection migration
Ecosystems: cargo
Packages: s2n-quic
Source: GitHub Advisory Database
Published: 4 months ago
Low
GSA_kwCzR0hTQS1wNHd3LWo0cHItcXc2cc4AA01M
RuoYi vulnerable to Cross-site Scripting
Ecosystems: maven
Packages: com.ruoyi:ruoyi
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS1nNHdnLWNmcGYtOTY4Oc4AA0zn
keylime fails to flag device as untrusted when signature does not validate
Ecosystems: pypi
Packages: keylime
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS0zcncyLXdmYzgtd21qNc4AA0xu
Fides Webserver Vulnerable to SVG Bomb File Uploads
Ecosystems: pypi
Packages: ethyca-fides
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS1nOTVjLTJqZ20taHFjNs4AA0xt
Fides Webserver Vulnerable to Zip Bomb File Uploads
Ecosystems: pypi
Packages: ethyca-fides
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS1mMnd4LXhqZncteGp2Ns4AA0vw
topgrade Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all
Ecosystems: cargo
Packages: topgrade
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS1oOXdxLXhjcXgtbXF4bc4AA0m0
Vendure Cross Site Request Forgery vulnerability impacting all API requests
Ecosystems: npm
Packages: @vendure/core
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS01OHF3LXA3cW0tNXJ2aM4AA0ib
Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations
Ecosystems: maven
Packages: org.eclipse.jetty:jetty-xml
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS1tcnI4LXY0OXctMzMzM84AA0iP
sweetalert2 v11.6.14 and above contains potentially undesirable behavior
Ecosystems: npm
Packages: sweetalert2
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS02ZzJ3LTI1N3YtM2M5Zs4AA0hB
Apache Camel information exposure vulnerability
Ecosystems: maven
Packages: org.apache.camel:camel-jira
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS13ancyLTRqN2otNmdjM84AA0fu
Winter CMS stored XSS through privileged upload of SVG file
Ecosystems: packagist
Packages: wintercms/winter
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS1mN3hqLXJnN2gtbWM4N84AA0ft
Stylelint has vulnerability in semver dependency
Ecosystems: npm
Packages: stylelint
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS13MmgzLXZ2dnEtM201M84AA0fs
Pipelines do not validate child UIDs
Ecosystems: go
Packages: github.com/tektoncd/pipeline
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS0ycTRwLWY2Z2YtbXFyNc4AA0Xn
Graylog server has partial path traversal vulnerability in Support Bundle feature
Ecosystems: maven
Packages: org.graylog2:graylog2-server
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS1nOTZjLXg3cmgtOTlyM84AA0Xm
Graylog vulnerable to insecure source port usage for DNS queries
Ecosystems: maven
Packages: org.graylog2:graylog2-server
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS0zZnFtLWZyaGctN2M4Nc4AA0Xl
Graylog user session is still usable after logout
Ecosystems: maven
Packages: org.graylog2:graylog2-server
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS1jZjZ2LTlqNTctdjZyNs4AA0Nx
code.gitea.io/gitea Open Redirect vulnerability
Ecosystems: go
Packages: code.gitea.io/gitea
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS13NXc1LTI4ODItNDdwY84AA0KY
github.com/cosmos/cosmos-sdk's x/crisis does not charge ConstantFee
Ecosystems: go
Packages: github.com/cosmos/cosmos-sdk
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS1nOTh2LWh2M2YtaGNmcs4AA0KD
atty potential unaligned read
Ecosystems: cargo
Packages: atty
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS1nbTJnLTJ4cjktcHh4as4AA0J6
Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource
Ecosystems: go
Packages: go.temporal.io/server
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS0zNzN3LXJqODQtcHY2eM4AA0In
SafeURL-Python's hostname blocklist does not block FQDNs
Ecosystems: pypi
Packages: SafeURL-Python
Source: GitHub Advisory Database
Published: 5 months ago
Low
GSA_kwCzR0hTQS1tNTRoLTV4NWYtNW02cs4AA0IM
SpiceDB's LookupResources may return partial results
Ecosystems: go
Packages: github.com/authzed/spicedb
Source: GitHub Advisory Database
Published: 5 months ago
Filter by Package
tensorflow 109 tensorflow-cpu 93 tensorflow-gpu 93 shopware/platform 12 shopware/core 10 phpmyadmin/phpmyadmin 8 org.jenkins-ci.main:jenkins-core 7 matrix-synapse 7 org.apache.tomcat:tomcat 7 sweetalert2 5 baserproject/basercms 5 ansible 5 october/backend 5 helm.sh/helm/v3 5 github.com/mattermost/mattermost-server/v6 4 typo3/cms-core 4 com.vaadin:flow-server 4 electron 4 github.com/cilium/cilium 4 actionpack 4 simplesamlphp/simplesamlphp 4 k8s.io/kubernetes 4 helm.sh/helm 4 shopware/shopware 4 moodle/moodle 4 puppet 4 typo3/cms 3 github.com/mattermost/mattermost/server/v8 3 concrete5/concrete5 3 wasmtime 3 cryptography 3 org.graylog2:graylog2-server 3 bin-links 3 plone 3 node-forge 3 ethyca-fides 3 org.apache.hive:hive 3 org.apache.hive:hive-exec 3 org.apache.hive:hive-service 3 Flask-Security-Too 3 com.vaadin:vaadin-bom 3 vyper 3 passenger 3 rack 3 com.fasterxml.woodstox:woodstox-core 3 ezsystems/ezplatform-kernel 2 ezsystems/ezpublish-kernel 2 @apollo/server 2 s2n-quic 2 org.jenkins-ci.plugins:ec2 2 github.com/ntbosscher/gobase 2 october/cms 2 cargo 2 braces 2 aiohttp 2 typo3/cms-backend 2 org.jenkins-ci.plugins:bigpanda-jenkins 2 Flask-AppBuilder 2 parse-server 2 next-auth 2 tools.devnull:build-notifications 2 org.xwiki.platform:xwiki-platform-oldcore 2 pip 2 craftcms/cms 2 personnummer 2 node-ipc 2 com.ruoyi:ruoyi 2 Pillow 2 OctoPrint 2 github.com/sigstore/cosign 2 github.com/answerdev/answer 2 wagtail 2 grumpydictator/firefly-iii 2 github.com/mutagen-io/mutagen 2 symfony/symfony 2 github.com/cosmos/cosmos-sdk 2 org.eclipse.jetty:jetty-server 2 org.jenkins-ci.plugins:repository-connector 2 github.com/opencontainers/runc 2 ckb 2 activesupport 2 org.jenkins-ci.plugins:azure-ad 2 httplib2 2 phpmailer/phpmailer 2 @openzeppelin/contracts-upgradeable 2 org.jenkins-ci.plugins:wso2id-oauth 2 silverstripe/framework 2 go.etcd.io/etcd/client/v3 2 Zope 2 org.keycloak:keycloak-services 2 undici 2 sylius/sylius 2 cli 2 org.jenkins-ci.plugins:artifactory 2 com.inedo.proget:inedo-proget 2 io.jenkins.plugins:cavisson-ns-nd-integration 1 net.sf.mpxj:mpxj 1 net.sf.mpxj 1 net.sf.mpxj-for-csharp 1 marked 1 net.sf.mpxj-for-vb 1 mpxj 1 cranelift-codegen 1 org.jenkins-ci.plugins:qmetry-for-jira-test-management 1 Azure/setup-kubectl 1 org.keycloak:keycloak-ldap-federation 1 dijit 1 saleor 1 org.postgresql:postgresql 1 remdex/livehelperchat 1 org.jenkins-ci.plugins:gitlab-plugin 1 org.apache.struts:struts2-core 1 teler.app 1 org.jenkins-ci.plugins:couchdb-statistics 1 mlflow 1 typo3/cms-install 1 @vendure/core 1 froxlor/froxlor 1 org.gradle:gradle-core 1 org.jenkins-ci.plugins:Parameterized-Remote-Trigger 1 org.jenkins-ci.plugins:quality-gates 1 personnummer 1 personnummer 1 org.jenkins-ci.plugins:application-director-plugin 1 org.jenkins-ci.plugins:assembla 1 dev.personnummer:personnummer 1 com.villagechief.codescan.jenkins:codescan 1 github.com/containerd/containerd 1 org.jenkins-ci.plugins:tfs 1 org.jenkins-ci.plugins.m2release:m2release 1 atty 1 org.jenkins-ci.plugins:testlink 1 org.jenkins-ci.plugins:zephyr-for-jira-test-management 1 octokit 1 com.dubture.jenkins:digitalocean-plugin 1 ru.yandex.jenkins.plugins.debuilder:debian-package-builder 1 go.mozilla.org/sops/v3 1 org.jenkins-ci.plugins:s3 1 org.jenkins-ci.plugins:azure-publishersettings-credentials 1 @floffah/build 1 org.jenkins-ci.plugins:aqua-microscanner 1 org.jenkins-ci.plugins:twitter 1 github.com/tektoncd/pipeline 1 @redocly/openapi-cli 1 pterodactyl/panel 1 @openzeppelin/contracts 1 github.com/opencontainers/image-spec 1 com.urbancode.ds.jenkins.plugins:sra-deploy 1 github.com/aws/aws-sdk-go 1 org.jenkins-ci.plugins:minio-storage 1 org.jenkins-ci.plugins:youtrack-plugin 1 de.e-nexus:jabber-server-plugin 1 com.cloudcoreo.plugins:cloudcoreo-deploytime 1 org.jenkins-ci.plugins:koji 1 org.jenkins-ci.plugins:sametime 1 org.jenkins-ci.plugins:aws-device-farm 1 org.jenkins-ci.plugins:veracode-scanner 1 org.jenkins-ci.plugins:audit2db 1 clean-css 1 csrf-csrf 1 sh.hyper.plugins:hyper-commons 1 com.programmingresearch:prqa-plugin 1 org.jenkins-ci.plugins:relution-publisher 1 org.jenkins-ci.plugins:credentials-binding 1 org.jenkins-ci.plugins:cloudshare-docker 1 org.jvnet.hudson.plugins:ftppublisher 1 org.jenkins-ci.plugins:bitbucket-approve 1 org.jvnet.hudson.plugins:bugzilla 1 org.jenkins-ci.plugins:netsparker-cloud-scan 1 org.jenkins-ci.plugins:zap 1 org.jenkins-ci.plugins:aws-beanstalk-publisher-plugin 1 org.jvnet.hudson.plugins:ircbot 1 org.jenkins-ci.plugins:snsnotify 1 org.bouncycastle:bcprov-jdk14 1 sqlite3 1 org.jenkins-ci.plugins:aws-cloudwatch-logs-publisher 1 git-url-parse 1 starlette 1 org.bouncycastle:bcprov-jdk15 1 Gw2Sharp 1 org.jenkins-ci.plugins:aqua-security-scanner 1 seneca 1 hudson.plugins.octopusdeploy:octopusdeploy 1 redis 1 github.com/hashicorp/nomad 1 @keystone-6/core 1 igniteui 1 glance 1 public 1 katello 1 org.jenkins-ci.plugins:weibo 1 RPLY 1 @zowe/imperative 1 github.com/containers/podman/v4 1 github.com/docker/distribution 1 com.hoiio.jenkins:sms 1 com.inflectra.spiratest.plugins:inflectra-spira-integration 1 personnummer 1 go.etcd.io/etcd 1 github.com/moby/moby 1 iodine 1 org.jenkins-ci.plugins:sonar-quality-gates 1 org.apache.storm:storm-core 1 send 1 github.com/hashicorp/vault 1 puma 1 ws 1 suds 1 connect 1 serve-static 1 google-translate-api-browser 1 rdiffweb 1 org.jenkins-ci.plugins:support-core 1 org.jenkins-ci.plugins:skytap 1 rusty-paseto 1 com.openmake:deployhub 1 flarum/core 1 org.jenkins-ci.plugins:hp-quality-center 1 org.jenkins-ci.plugins:StashBranchParameter 1 io.jenkins.plugins:s3explorer 1 facter 1 org.jenkins-ci.plugins:labmanager 1 com.rapid7:jenkinsci-appspider-plugin 1 rest-client 1 github.com/cloudflare/cfrpki 1 com.vaadin:vaadin 1 org.jenkins-ci.plugins:gogs-webhook 1 org.jenkins-ci.plugins:ec2-deployment-dashboard 1 paratrooper-newrelic 1 sqlite3-ruby 1 sensu 1 Plone 1 org.jenkins-ci.plugins:skype-notifier 1 com.datadoghq:datadog-api-client 1 sequoia-openpgp 1 buffered-reader 1 hyper 1 paratrooper-pingdom 1 github.com/cheqd/cheqd-node 1 com.geteasyqa:easyqa 1 horizon 1 nemo_toolkit 1 rubocop 1 lodash 1 org.springframework.batch:spring-batch-core 1 eslint-detailed-reporter 1 azuracast/azuracast 1 github.com/traefik/traefik/v2 1 fluture-node 1 request-util 1 opencv 1 stylelint 1 io.jenkins.plugins:tuleap-oauth 1 @aedart/support 1 loguru 1 org.wildfly.core:wildfly-server 1 eye.js 1 EnumStringValues 1 express-basic-auth 1 com.linecorp.armeria:armeria 1 serialize-to-js 1 vantage6 1 django-user-sessions 1 io.ktor:ktor-client-cio 1 io.ktor:ktor-server-cio 1 org.opencastproject:opencast-common-jpa-impl 1 dojox 1 ruby_parser 1 org.springframework.data:spring-data-rest-core 1 django-basic-auth-ip-whitelist 1 com.mtvi.plateng.hudson:ldapemail 1 org.apache.logging.log4j:log4j 1 org.apache.logging.log4j:log4j-core 1 qutebrowser 1 openapi-python-client 1 auth0-lock 1 npm 1 sequelize-cli 1 io.jenkins:configuration-as-code 1 hooka-tools 1 github.com/canonical/lxd 1 njwt 1 ascii-art 1 symfony/http-foundation 1 merge-objects 1 put 1 bigint-money 1 graphql-shield 1 apostrophe 1 express-fileupload 1 io.ratpack:ratpack-session 1 io.ratpack:ratpack-java 1 igalg.jenkins.plugins:multibranch-scan-webhook-trigger 1 govuk_tech_docs 1 github.com/argoproj/argo-cd 1 github.com/lima-vm/lima 1 personnummer 1 solidus_backend 1 xmpp-http-upload 1 com.google.crypto.tink:tink 1