Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Moderate Security Advisories

Loading...
Moderate
GSA_kwCzR0hTQS1tOGg4LTZydmctZjRtZ823Mw
Apache Tomcat Path Traversal Vulnerability
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS01NHFqLTQ4dngtY3I5Zs22-A
Django Cross-site scripting (XSS) vulnerability
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS13Y2d4LTJodngtNWN3cs216w
Apache Struts Cross-site Scripting vulnerability
Ecosystems: maven
Packages: struts:struts
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1mOThwLTlwcDYtN3E2Y821nA
Apache Tomcat Cross-site scripting (XSS) vulnerability
Ecosystems: maven
Packages: org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1ycXhwLTY5MjYtaHBocs21kg
MoinMoin vulnerable to privilege escalation
Ecosystems: pypi
Packages: moin
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS14MzM3LTQzbXItZ2czaM20wg
Ignite Realtime Openfire allows remote authenticated users to cause a denial of service
Ecosystems: maven
Packages: org.igniterealtime.openfire:openfire, org.igniterealtime.openfire:parent
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS12NzU5LTN3cjUtcDI5NM2z8Q
Moodle vulnerable to Cross-site scripting
Ecosystems: packagist
Packages: moodle/moodle
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1qNTlqLWgzZzctY3BtZs2z1Q
Roundup xml-rpc server improper check of property permissions
Ecosystems: pypi
Packages: roundup
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1jM3F2LW1mOGgtNDM0cs2z1g
Roundup vulnerability related to Cross-site scripting (XSS)
Ecosystems: pypi
Packages: roundup
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1oanA1LWh2MzMtcTU4Z82zkw
Plone credentials stored in session cookie
Ecosystems: pypi
Packages: plone
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS12djZqLTV4NTgtcTJjM82zLg
Cross-site scripting (XSS) vulnerability in Sun Java Server Faces (JSF)
Ecosystems: maven
Packages: com.sun.faces:jsf-api
Source: GitHub Advisory Database
Blast Radius: 21.4
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1xNzR4LXFxaHItZjhyeM2y9Q
Apache Tomcat Cross-site scripting (XSS) vulnerability
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS13cW1tLXE2NWctMmhxcs2vew
Paramiko Unsafe randomness usage may allow access to sensitive information
Ecosystems: pypi
Packages: paramiko
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS01eDVmLTlyNnEtcTdtaM2uaw
Apache Tomcat Sensitive Information Disclosure
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS04eGd4LTc1cXctNjI2OM2uTA
Improper privilege management in pyftpdlib
Ecosystems: pypi
Packages: pyftpdlib
Source: GitHub Advisory Database
Blast Radius: 15.8
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1jeDU5LWNwNmMtOWZyOM2uTQ
pyftpdlib vulnerable to allocation of resources without limits
Ecosystems: pypi
Packages: pyftpdlib
Source: GitHub Advisory Database
Blast Radius: 10.8
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1naDdjLWNnM3gtcG1jcs2uSA
pyftpdlib Use of Insufficiently Random Values of port selection on PASV command
Ecosystems: pypi
Packages: pyftpdlib
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS01ZjNmLXBnMmMtY3hjds2uSQ
Improper Input Validation in pyftpdlib
Ecosystems: pypi
Packages: pyftpdlib
Source: GitHub Advisory Database
Blast Radius: 13.3
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1mOHdnLTM2cjktN2Y0cc2uTg
Directory Traversal in pyftpdlib
Ecosystems: pypi
Packages: pyftpdlib
Source: GitHub Advisory Database
Blast Radius: 15.8
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1ybTI2LXcyNTMtOXF2N82uOg
Apache Struts Dojo Plugin XSS Vulnerability
Ecosystems: maven
Packages: org.apache.struts:struts2-dojo-plugin
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS00amp3LXhycjYtOXYzcM2uCQ
Mortbay Jetty Double Slash URI Information Disclosure Vulnerability
Ecosystems: maven
Packages: org.mortbay.jetty:jetty
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1tN3I2LTQzdjItNDl2Zs2t2Q
Mongrel vulnerable to directory traversal via double-encoded sequences
Ecosystems: rubygems
Packages: mongrel
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS14aDIyLWZ3NTgtNTZwcM2s8Q
Robocode Arbitrary Code Execution
Ecosystems: maven
Packages: net.sf.robocode:robocode.core
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1xcmo0LXJtcWctNGhjcM2skg
Apache Tomcat Does Not Properly Handle Empty Requests
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS05NjZyLTk2MmctMmpxNc2qSg
Mortbay Jetty CRLF Injection Vulnerability
Ecosystems: maven
Packages: org.mortbay.jetty:jetty
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS04aDc3LTl2aDUtaHc1Z82qQA
Mortbay Jetty vulnerable to Cross-site scripting
Ecosystems: maven
Packages: org.mortbay.jetty:jetty
Source: GitHub Advisory Database
Blast Radius: 22.2
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS13NjVqLWNtcWMtMzdwMs2pSg
JULI logging component in Apache Tomcat does not restrict certain permissions for web applications
Ecosystems: maven
Packages: org.apache.tomcat:tomcat-juli
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1jd3c0LXZqNXItcng1N82pTQ
Exposure of Sensitive Information in Apache Tomcat
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS13eGN3LXJxeGMtaGo4Nc2owA
FTP backend for Duplicity Discloses Passwords to Process Listing
Ecosystems: pypi
Packages: duplicity
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1nNzdnLXZqam0teDgzas2nEw
Apache Tomcat Example Application CSRF and XSS Vulnerabilities
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1oN21mLXFybTktMjg0OM2meQ
OpenSymphony XWork vulnerable to improper input validation
Ecosystems: maven
Packages: opensymphony:xwork
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1oMjJxLWcyYzctMmp3as2lHg
Joomla! vulnerable to CRLF injection
Ecosystems: packagist
Packages: joomla/application
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS0zNmhwLTR4M2ctcGhyZ82iLg
Apache Tomcat's CookieExample Vulnerable to XSS
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS13andyLTNqY2gtNDc5as2iKg
Apache Tomcat SendMailServlet XSS
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS02ajhmLTY2dmgtMzltas2iMA
Apache Tomcat Mishandles Character Sequence in Cookies
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1xZmY4LWc0OGotcHdwd82iMw
Apache Tomcat treats single quotes as delimiters in cookies
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1oYzM5LXJqd3AtcWZmcc2eqg
Apache Tomcat XSS Vulnerabilities in Examples Web Application
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS13N3gyLTU3ZjctM3AzeM2avA
Trac Cross-site Scripting (XSS) vulnerability
Ecosystems: pypi
Packages: trac
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS05Z2oyLXBoNTctNTZmNc2Y_w
MoinMoin Cross-Site Scripting (XSS) vulnerability via hitcounts and general parameters
Ecosystems: pypi
Packages: Moin
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS14cjk2LTdjY3AtcGc1Y82YIg
DotNetNuke Vulnerable to XSS in Pass-Through Values
Ecosystems: nuget
Packages: DotNetNuke.Core
Source: GitHub Advisory Database
Blast Radius: 1.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS05NXZ4LXE0YzItNjRncs2XWw
RubyGems file overwrite vulnerability
Ecosystems: rubygems
Packages: rubygems-update
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS00cHJoLWdxdzgtcmdoNc2XRQ
Apache Tomcat Directory Traversal
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1oNWptLWpqZ3gtcTJ3Zs2VbA
XWiki Remote Code Execution
Ecosystems: maven
Packages: org.xwiki.platform:xwiki-platform-oldcore
Source: GitHub Advisory Database
Blast Radius: 1.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS12N2NxLXBxN3YtbWg1ds2Vag
Apache Derby SQL Injection
Ecosystems: maven
Packages: org.apache.derby:derby
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1wNTd2LXAzZngtcWd3bc2VZA
Apache Tomcat XSS Vulnerability
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1wbTc4LXd4eGYtZnc5OM2Vdg
Cross-site scripting in Apache Tomcat
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1qZzJ4LXI2NDMtdzJjaM2Uig
Jetty Uses Predictable Session Identifiers
Ecosystems: maven
Packages: org.eclipse.jetty:jetty-server
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1ydzczLXhtcHYtajV4Ms2NbQ
CakePHP directory traversal vulnerability allows remote attackers to read arbitrary files
Ecosystems: packagist
Packages: cakephp/cakephp
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1oOXc4LTQzNzYtajM0NM2NFA
Moodle does not properly validate module instance id
Ecosystems: packagist
Packages: moodle/moodle
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS12YzI5LW12d3Ytd3Bjcc2KDg
Cross-site scripting (XSS) vulnerability in CakePHP
Ecosystems: packagist
Packages: cakephp/cakephp
Source: GitHub Advisory Database
Blast Radius: 24.3
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1jNXZ3LTM0MmgteDVyeM2Jmw
Alkacon OpenCms Exposes JSP Source Code
Ecosystems: maven
Packages: org.opencms:opencms-core
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1yNTI0LWMyZ2YtNWNocs2IuQ
Trac reStructuredText breach of privacy and denial of service vulnerability
Ecosystems: pypi
Packages: trac
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS0yd3h2LTNnNHYtcDc2cM2Hhg
phpSysInfo allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence
Ecosystems: packagist
Packages: phpsysinfo/phpsysinfo
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1xbWdqLTVoNzUtanI2N82FRA
Jetty Directory Traversal Vulnerability
Ecosystems: maven
Packages: org.mortbay.jetty:jetty
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1tcTR4LTh3aGgtang3M82FRQ
Improper Input Validation in Mortbay Jetty
Ecosystems: maven
Packages: org.mortbay.jetty:jetty
Source: GitHub Advisory Database
Blast Radius: 22.2
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1qY3doLXJqNmotdm03Nc2Bfg
Plone allows remote users to modify arbitrary portraits
Ecosystems: pypi
Packages: plone
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS12eDc3LTVwZjQtYzl3cs1-bA
CherryPy Directory traversal vulnerability
Ecosystems: pypi
Packages: cherrypy
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1mOWZyLXc1NHEtNzcyaM198g
Apache log4net format string vulnerability causes DoS
Ecosystems: nuget
Packages: log4net
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS0yanhoLTNjeDgteHc2Nc18GQ
Apache Geronimo console 1.0 vulnerable to cross-site scripting
Ecosystems: maven
Packages: geronimo:geronimo-console-standard
Source: GitHub Advisory Database
Blast Radius: 1.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1ycDdyLTc5cm0tMjc1OM17Jw
Apache Derby exposes user and password attributes
Ecosystems: maven
Packages: org.apache.derby:derby
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS14ODlyLTJ3anEtbWo3eM16gg
Apache Tomcat Discloses MS-DOS Pathname
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS02dmhwLWhwNzctNnc1Ms16SQ
Trac HTML WikiProcessor cross-site scripting (XSS) vulnerability
Ecosystems: pypi
Packages: trac
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1jd3EzLXFwOHYtdzhxM813Fw
Mortbay Jetty Discloses JSP Source Code
Ecosystems: maven
Packages: org.mortbay.jetty:jetty
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS05Y2poLXFtdngtNDM2Y813FQ
Apache Struts Cross-site scripting Vulnerability
Ecosystems: maven
Packages: org.apache.struts:struts-core
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS13ajQyLTUycHYtd2ZqMs12pg
phpMyAdmin CRLF Injection Vulnerability
Ecosystems: packagist
Packages: phpmyadmin/phpmyadmin
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1mMmdxLXA2cXYtY2N3NM1xPA
Tomcat Vulnerable to Web Cache Poisoning
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS04NmZwLWpnd20td2dqNc1mcQ
Apache Tomcat XSS Vulnerability
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS01bXE4LWg4MnAtd2pmMs1mbg
Jetty Javascript Inclusion Vulnerability
Ecosystems: maven
Packages: org.mortbay.jetty:jetty
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1qeGN2LXY4NTYtajV2Z81lCQ
Apache Tomcat Source Code Disclosure
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS14bWY0LWozajcteGo3cc1kWA
Apache Tomcat DoS Via Requests Including Null Characters
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS12d3JjLWc5cTYtZjY3Nc1jmg
Zope Server vulnerable to DoS via header injection
Ecosystems: pypi
Packages: zope
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS01OGhqLTU3NWctNWoyNc1eeQ
Apache Tomcat allows webmasters to insert xss into error messages
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS14NDQ1LW1tcHctN3I0Zs1d5A
Apache Tomcat Allows Source Disclosure
Ecosystems: maven
Packages: org.apache.tomcat:tomcat-servlet-api
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS00Z3I5LTk5ajMtdnF4ds1bag
Apache Tomcat Directory Traversal
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS03d2hyLWo4dmYtcjR3as1boA
Zope allows attackers to modify raw image and file data
Ecosystems: pypi
Packages: zope
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1xZzRnLTZqY3Etcnc5M81Z2w
Jakarta Apache Tomcat Reveals Physical Paths
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS05aGdjLXdwYzUtdjhwOc1RPw
An attacker can execute malicious javascript in Live Helper Chat
Ecosystems: packagist
Packages: remdex/livehelperchat
Source: GitHub Advisory Database
Blast Radius: 4.3
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1qdjY0LTJtM3gtNnY0cc1RHw
Subrion CMS Cross-site Scripting (XSS) vulnerability in the `contact us` plugin
Ecosystems: packagist
Packages: intelliants/subrion
Source: GitHub Advisory Database
Blast Radius: 2.9
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS02cTlnLTN2ZnEtcTJxas1RMw
Improper Authentication in moodle
Ecosystems: packagist
Packages: moodle/moodle
Source: GitHub Advisory Database
Blast Radius: 6.1
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1jNWhmLW1jODUtMmh4NM1RLg
Missing authorization in Moodle
Ecosystems: packagist
Packages: moodle/moodle
Source: GitHub Advisory Database
Blast Radius: 6.1
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1weHBmLXYzNzYtN3h4Nc1RKw
tagify can pass a malicious placeholder to initiate the cross-site scripting (XSS) payload
Ecosystems: npm
Packages: @yaireo/tagify
Source: GitHub Advisory Database
Blast Radius: 17.6
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS12bXA1LWM1aHAtNmM2Nc1RJQ
Woodpecker allows cross-site scripting (XSS) via build logs
Ecosystems: go
Packages: github.com/woodpecker-ci/woodpecker
Source: GitHub Advisory Database
Blast Radius: 3.7
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS05Mmo3LTM0eDktZjNqd81QjA
Apache James Denial of Service
Ecosystems: maven
Packages: org.apache.james:james-server
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1wNXJyLXE1ZzYtZ200Ms1PqA
Jetty HTTP Server Denial of Service vulnerability
Ecosystems: maven
Packages: org.mortbay.jetty:jetty
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1yaDZjLWpoNGMtOWZnM81K4w
mailman Cross-site scripting (XSS) vulnerability
Ecosystems: pypi
Packages: mailman
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1oajRoLXZxcHEtOTV3Z81IpA
Mailman Sensitive Information Disclosure
Ecosystems: pypi
Packages: mailman
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS03d2oyLTQ4YzQtMjY4NM1Egg
Apache Tomcat Denial of Service vulnerability in the Catalina package
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS01aGdtLXFtNW0tNXZtd81B2g
Jakarta Tomcat cross-site scripting (XSS) vulnerability
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS04MnJtLTI4cTktNDM1cM1B1w
Mailman Cross-site scripting (XSS) vulnerability
Ecosystems: pypi
Packages: mailman
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1xZncyLXd2cnctbXZ3NM1B1Q
Jakarta Tomcat Directory Listing vulnerability
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS13OTd4LXhmeGYtZjl4as1B1g
Jakarta Tomcat Denial of Service vulnerability
Ecosystems: maven
Packages: org.apache.tomcat:tomcat
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1wMnZ3LWY4N2MtcTU5N81BtQ
Improper Access Control in snipe/snipe-it
Ecosystems: packagist
Packages: snipe/snipe-it
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS0zcXJxLXI2ODgtdnZoNM1Bkg
Multiple valid tokens for password reset in Shopware
Ecosystems: packagist
Packages: shopware/shopware
Source: GitHub Advisory Database
Blast Radius: 10.6
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1tOThnLTYzcWotZnA4as1BkA
Reflected XSS on clients-registrations endpoint
Ecosystems: maven
Packages: org.keycloak:keycloak-parent
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1wZjM4LWN3M3AtMjJxOc1Bjg
Keycloak is vulnerable to IDN homograph attack
Ecosystems: maven
Packages: org.keycloak:keycloak-services
Source: GitHub Advisory Database
Blast Radius: 14.6
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS00ZzI5LWZjY3ItcDU5d81BjQ
Reflected Cross-site Scripting in Shopware storefront
Ecosystems: packagist
Packages: shopware/shopware
Source: GitHub Advisory Database
Blast Radius: 8.9
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1tMnI1LTR3OTYtcXhnNc1Biw
Arbitrary file access through XML parsing in org.xwiki.commons:xwiki-commons-xml
Ecosystems: maven
Packages: org.xwiki.commons:xwiki-commons-xml
Source: GitHub Advisory Database
Blast Radius: 9.2
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS0yN3JxLTQ5NDMtcWN3cM1Bgg
Insertion of Sensitive Information into Log File in Hashicorp go-getter
Ecosystems: go
Packages: github.com/hashicorp/go-getter
Source: GitHub Advisory Database
Blast Radius: 21.1
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS02eGozLWZocmYtcmpnY81Bgw
Cross-site Scripting in microweber
Ecosystems: packagist
Packages: microweber/microweber
Source: GitHub Advisory Database
Blast Radius: 4.4
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1jaDNoLWoydmYtOTVwds1BUQ
XSS Vulnerability in Action View tag helpers
Ecosystems: rubygems
Packages: actionview
Source: GitHub Advisory Database
Blast Radius: 35.3
Published: about 2 years ago
Statistics
Advisories: 18,390
Packages: 8,299
Repositories: 2,457
Ecosystems: 12
Filter by Package
moodle/moodle 247 tensorflow 207 tensorflow-cpu 191 tensorflow-gpu 190 org.jenkins-ci.main:jenkins-core 114 magento/community-edition 96 org.apache.tomcat:tomcat 92 pimcore/pimcore 86 typo3/cms 66 microweber/microweber 62 django 54 dolibarr/dolibarr 53 apache-airflow 52 typo3/cms-core 51 phpmyadmin/phpmyadmin 50 thorsten/phpmyfaq 45 actionpack 42 github.com/usememos/memos 42 apache-superset 39 drupal/core 36 plone 35 showdoc/showdoc 34 concrete5/concrete5 34 librenms/librenms 32 ansible 31 org.keycloak:keycloak-core 31 github.com/mattermost/mattermost-server/v6 30 Plone 28 drupal/drupal 28 intelliants/subrion 27 github.com/mattermost/mattermost/server/v8 27 symfony/symfony 27 craftcms/cms 26 com.liferay.portal:release.portal.bom 25 silverstripe/framework 25 snipe/snipe-it 24 org.elasticsearch:elasticsearch 24 github.com/grafana/grafana 23 baserproject/basercms 22 github.com/answerdev/answer 21 k8s.io/kubernetes 20 org.apache.struts:struts2-core 20 grumpydictator/firefly-iii 19 froxlor/froxlor 18 matrix-synapse 18 nilsteampassnet/teampass 18 shopware/shopware 18 rdiffweb 18 remdex/livehelperchat 18 shopware/platform 18 getkirby/cms 17 moin 16 org.apache.tomcat.embed:tomcat-embed-core 16 github.com/argoproj/argo-cd/v2 15 vyper 15 salt 14 nokogiri 14 puppet 14 yetiforce/yetiforce-crm 14 tribalsystems/zenario 14 prestashop/prestashop 14 Pillow 13 org.keycloak:keycloak-services 13 nova 13 com.jfinal:jfinal 13 mautic/core 13 io.undertow:undertow-core 13 shopware/core 13 org.xwiki.platform:xwiki-platform-oldcore 13 forkcms/forkcms 13 github.com/hashicorp/consul 12 github.com/hashicorp/vault 12 org.apache.solr:solr-core 12 Django 12 github.com/docker/docker 12 tinymce 12 org.apache.jspwiki:jspwiki-main 12 github.com/goharbor/harbor 12 com.thoughtworks.xstream:xstream 12 org.keycloak:keycloak-parent 11 pyftpdlib 11 neutron 11 getgrav/grav 11 feehi/feehicms 11 github.com/hashicorp/nomad 11 github.com/argoproj/argo-cd 11 lavalite/cms 11 github.com/cilium/cilium 11 genix/cms 11 DotNetNuke.Core 11 org.springframework:spring-core 10 org.apache.nifi:nifi 10 activesupport 10 wallabag/wallabag 10 PaddlePaddle 10 org.apache.jspwiki:jspwiki-war 10 github.com/containerd/containerd 10 typo3/cms-backend 10 github.com/mattermost/mattermost-server 10 joplin 10 com.vaadin:vaadin-bom 10 francoisjacquet/rosariosis 10 notebook 10 ec-cube/ec-cube 10 @openzeppelin/contracts-upgradeable 10 @openzeppelin/contracts 10 org.eclipse.jetty:jetty-server 10 github.com/greenpau/caddy-security 10 contao/core-bundle 10 github.com/ethereum/go-ethereum 10 rack 10 org.springframework.security:spring-security-core 10 fat_free_crm 10 helm.sh/helm/v3 10 ghost 9 directus 9 org.igniterealtime.openfire:parent 9 glance 9 tinymce/tinymce 9 TinyMCE 9 gogs.io/gogs 9 org.mortbay.jetty:jetty 9 jquery-rails 9 bolt/bolt 9 publify_core 9 ckeditor4 9 rubygems-update 9 angular 9 swagger-ui 9 cakephp/cakephp 9 code.gitea.io/gitea 9 org.jenkins-ci.plugins:script-security 9 org.opencrx:opencrx-core-models 9 org.jenkins-ci.plugins:git 9 zendframework/zendframework1 9 bootstrap 8 org.jenkins-ci.plugins:electricflow 8 wasmtime 8 github.com/openfga/openfga 8 org.bouncycastle:bcprov-jdk14 8 simplesamlphp/simplesamlphp 8 org.apache.activemq:activemq-client 8 roundup 8 electron 8 org.apache.archiva:archiva 8 centreon/centreon 8 github.com/kubeedge/kubeedge 8 silverstripe/cms 8 editor.md 8 contao/contao 8 impresscms/impresscms 8 actionview 8 Microsoft.ChakraCore 8 rails-html-sanitizer 8 rails 8 opencv-python 8 opencv-contrib-python 8 org.opencms:opencms-core 8 org.webjars.npm:jquery 8 jquery 8 io.jenkins:configuration-as-code 7 wagtail 7 org.apache.james:james-server 7 org.apache.santuario:xmlsec 7 org.webjars.npm:jquery-ui 7 org.opennms:opennms 7 jQuery.UI.Combined 7 admidio/admidio 7 vantage6 7 silverstripe/admin 7 OctoPrint 7 sylius/sylius 7 pillow 7 github.com/google/fscrypt 7 org.apache.cxf:cxf-core 7 aiohttp 7 jQuery 7 com.vaadin:flow-server 7 io.jenkins.blueocean:blueocean 7 next 7 github.com/moby/moby 7 org.jenkins-ci.plugins:email-ext 7 org.jenkins-ci.plugins:subversion 7 org.bouncycastle:bcprov-jdk15on 7 org.owasp.antisamy:antisamy 7 phpmyfaq/phpmyfaq 7 pyload-ng 7 validator 7 trytond 7 kevinpapst/kimai2 7 modoboa 7 phpbb/phpbb 7 jquery-ui 7 org.bouncycastle:bcprov-jdk15 7 keystone 7 activerecord 7 jquery-ui-rails 7 org.jenkins-ci.plugins:config-file-provider 7 ryu 6 gradio 6
Filter by Repository
https://github.com/tensorflow/tensorflow 207 https://github.com/moodle/moodle 164 https://github.com/jenkinsci/jenkins 90 https://github.com/pimcore/pimcore 83 https://github.com/microweber/microweber 58 https://github.com/apache/tomcat 53 https://github.com/apache/airflow 51 https://github.com/thorsten/phpmyfaq 45 https://github.com/django/django 43 https://github.com/usememos/memos 42 https://github.com/xwiki/xwiki-platform 38 https://github.com/rails/rails 33 https://github.com/kubernetes/kubernetes 32 https://github.com/TYPO3/typo3 32 https://github.com/star7th/showdoc 32 https://github.com/librenms/librenms 30 https://github.com/plone/Products.CMFPlone 29 https://github.com/keycloak/keycloak 27 https://github.com/ansible/ansible 26 https://github.com/phpmyadmin/phpmyadmin 22 https://github.com/symfony/symfony 22 https://github.com/craftcms/cms 21 https://github.com/answerdev/answer 21 https://github.com/spring-projects/spring-framework 21 https://github.com/Dolibarr/dolibarr 21 https://github.com/snipe/snipe-it 20 https://github.com/concretecms/concretecms 19 https://github.com/apache/activemq 19 https://github.com/firefly-iii/firefly-iii 19 https://github.com/argoproj/argo-cd 19 https://github.com/grafana/grafana 18 https://github.com/livehelperchat/livehelperchat 18 https://github.com/python-pillow/Pillow 18 https://github.com/ikus060/rdiffweb 18 https://github.com/matrix-org/synapse 17 https://github.com/shopware/platform 17 https://github.com/apache/struts 17 https://github.com/shopware/shopware 16 https://github.com/magento/magento2 16 https://github.com/CVEProject/cvelist 15 https://github.com/vyperlang/vyper 15 https://github.com/yetiforcecompany/yetiforcecrm 14 https://github.com/TYPO3/TYPO3.CMS 14 https://github.com/OpenNMS/opennms 14 https://github.com/PaddlePaddle/Paddle 14 https://github.com/froxlor/froxlor 14 https://github.com/getkirby/kirby 13 https://github.com/go-gitea/gitea 13 https://github.com/x-stream/xstream 13 https://github.com/mautic/mautic 13 https://github.com/octobercms/october 13 https://github.com/goharbor/harbor 12 https://github.com/netty/netty 12 https://github.com/tinymce/tinymce 12 https://github.com/apache/cxf 12 https://github.com/forkcms/forkcms 11 https://github.com/intelliants/subrion 11 https://github.com/contao/contao 11 https://github.com/PrestaShop/PrestaShop 11 https://github.com/cilium/cilium 11 https://github.com/silverstripe/silverstripe-framework 11 https://github.com/baserproject/basercms 10 https://github.com/containerd/containerd 10 https://github.com/OpenZeppelin/openzeppelin-contracts 10 https://github.com/moby/moby 10 https://github.com/greenpau/caddy-security 10 https://github.com/vaadin/platform 10 https://github.com/mattermost/mattermost 10 https://github.com/liufee/cms 10 https://github.com/nilsteampassnet/TeamPass 10 https://github.com/laurent22/joplin 10 https://github.com/helm/helm 10 https://github.com/ethereum/go-ethereum 10 https://github.com/jquery/jquery 10 https://github.com/saltstack/salt 10 https://github.com/github/advisory-database 9 https://github.com/puppetlabs/puppet 9 https://github.com/apache/nifi 9 https://github.com/sparklemotion/nokogiri 9 https://github.com/publify/publify 9 https://github.com/electron/electron 9 https://github.com/geoserver/geoserver 9 https://github.com/strapi/strapi 9 https://github.com/fatfreecrm/fat_free_crm 9 https://github.com/jenkinsci/git-plugin 9 https://github.com/bcgit/bc-java 8 https://github.com/bytecodealliance/wasmtime 8 https://github.com/nilsteampassnet/teampass 8 https://github.com/hashicorp/consul 8 https://github.com/rails/rails-html-sanitizer 8 https://github.com/openfga/openfga 8 https://github.com/LavaLite/cms 8 https://github.com/rack/rack 8 https://github.com/jupyter/notebook 8 https://github.com/pandao/editor.md 8 https://github.com/kubeedge/kubeedge 8 https://github.com/rubygems/rubygems 8 https://github.com/getgrav/grav 8 https://github.com/TryGhost/Ghost 8 https://github.com/swagger-api/swagger-ui 8 https://github.com/eclipse/jetty.project 8 https://github.com/wallabag/wallabag 8 https://github.com/directus/directus 8 https://github.com/ckeditor/ckeditor4 8 https://github.com/traefik/traefik 7 https://github.com/opencv/opencv 7 https://github.com/nahsra/antisamy 7 https://github.com/twbs/bootstrap 7 https://github.com/google/fscrypt 7 https://github.com/jeecgboot/jeecg-boot 7 https://github.com/pyload/pyload 7 https://github.com/aio-libs/aiohttp 7 https://github.com/vantage6/vantage6 7 https://github.com/gogs/gogs 7 https://github.com/giampaolo/pyftpdlib 7 https://github.com/kevinpapst/kimai2 7 https://github.com/wagtail/wagtail 7 https://github.com/hashicorp/vault 7 https://github.com/thorsten/phpMyFAQ 7 https://github.com/jenkinsci/blueocean-plugin 7 https://github.com/modoboa/modoboa 7 https://github.com/vaadin/flow 7 https://github.com/chakra-core/ChakraCore 7 https://github.com/dolibarr/dolibarr 7 https://github.com/apache/zeppelin 7 https://github.com/dompdf/dompdf 6 https://github.com/jenkinsci/config-file-provider-plugin 6 https://github.com/neorazorx/facturascripts 6 https://github.com/cosmos/cosmos-sdk 6 https://github.com/d4wner/Vulnerabilities-Report 6 https://github.com/jenkinsci/script-security-plugin 6 https://github.com/croogo/croogo 6 https://github.com/simplesamlphp/simplesamlphp 6 https://github.com/1Panel-dev/1Panel 6 https://github.com/faucetsdn/ryu 6 https://github.com/cloudflare/cfrpki 6 https://github.com/panva/jose 6 https://github.com/urllib3/urllib3 6 https://github.com/pimcore/customer-data-framework 6 https://github.com/opensearch-project/security 6 https://github.com/opencast/opencast 6 https://github.com/umbraco/Umbraco-CMS 6 https://github.com/igniterealtime/Openfire 6 https://github.com/dotnet/runtime 6 https://github.com/pimcore/admin-ui-classic-bundle 6 https://github.com/parse-community/parse-server 6 https://github.com/oroinc/orocommerce 6 https://github.com/jenkinsci/fortify-on-demand-uploader-plugin 6 https://github.com/onionshare/onionshare 6 https://github.com/cui2shark/security 6 https://github.com/containers/podman 6 https://github.com/jenkinsci/configuration-as-code-plugin 6 https://github.com/jquery/jquery-ui 6 https://github.com/ipython/ipython 6 https://github.com/backstage/backstage 6 https://github.com/cubefs/cubefs 6 https://github.com/sulu/sulu 5 https://github.com/unshiftio/url-parse 5 https://github.com/apache/kylin 5 https://github.com/yiisoft/yii2 5 https://github.com/apache/dolphinscheduler 5 https://github.com/vapor/vapor 5 https://github.com/xuxueli/xxl-job 5 https://github.com/lief-project/LIEF 5 https://bitbucket.org/snakeyaml/snakeyaml 5 https://github.com/zitadel/zitadel 5 https://github.com/centreon/centreon-archived 5 https://github.com/openstack/keystone 5 https://github.com/quarkusio/quarkus 5 https://github.com/NodeBB/NodeBB 5 https://github.com/undertow-io/undertow 5 https://github.com/paritytech/frontier 5 https://github.com/nodejs/undici 5 https://github.com/Amanieu/parking_lot 5 https://github.com/Sylius/Sylius 5 https://github.com/etcd-io/etcd 5 https://github.com/numpy/numpy 5 https://github.com/vercel/next.js 5 https://github.com/apache/lucene-solr 5 https://github.com/lxml/lxml 5 https://github.com/TribalSystems/Zenario 5 https://github.com/kivikakk/comrak 5 https://github.com/jenkinsci/codedx-plugin 5 https://github.com/puma/puma 5 https://github.com/apache/superset 5 https://github.com/admidio/admidio 5 https://github.com/semplon/GeniXCMS 5 https://github.com/OctoPrint/OctoPrint 5 https://github.com/jenkinsci/subversion-plugin 5 https://github.com/hyperium/hyper 5 https://github.com/hashicorp/nomad 5 https://github.com/bolt/bolt 5 https://github.com/cloudfoundry/uaa 5 https://github.com/jenkinsci/electricflow-plugin 5 https://github.com/alextselegidis/easyappointments 5 https://github.com/gradio-app/gradio 5 https://github.com/opencontainers/runc 5 https://github.com/pmmp/PocketMine-MP 5 https://github.com/nervosnetwork/ckb 5