Ecosyste.ms: OpenCollective

An open API service for software projects hosted on Open Collective.

excalidraw: GSA_kwCzR0hTQS1tNjRxLTRqcWgtZjcyZs4AA7KT

Ecosystems:
Packages:
Source:
revolution: GSA_kwCzR0hTQS1waGhtLTZwZ20tbXh3Oc4AAbJs

Ecosystems:
Packages:
Source:
phpbb: GSA_kwCzR0hTQS12ajN4LXZmbTQtaHZ4Y84AAiLR

Ecosystems:
Packages:
Source:
nunjucks: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWY3cGgtcDVydi1waHcy

Ecosystems:
Packages:
Source:
hoppscotch: GSA_kwCzR0hTQS1xbW1tLTczcjItZjh4cs4AA7PR

Ecosystems:
Packages:
Source:
scipy: GSA_kwCzR0hTQS1qcmZtLTJoODIteGcyOM4AA0e1

Ecosystems:
Packages:
Source:
Ghost: GSA_kwCzR0hTQS1mZmhxLWc4NTYtOWYycM06-g

Ecosystems:
Packages:
Source:
croogo: GSA_kwCzR0hTQS1xNWZnLXY1cDctcjQyNM4AAUT-

Ecosystems:
Packages:
Source:
bleach: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE2NW0tcHYzZi13cjVy

Ecosystems:
Packages:
Source:
litestar: GSA_kwCzR0hTQS04M3B2LXFyMzMtMnZjZs4AA7xv

Ecosystems:
Packages:
Source:
PollBot: GSA_kwCzR0hTQS12ZzI3LWhyM3YtM2Nxds0scg

Ecosystems:
Packages:
Source:
authelia: GSA_kwCzR0hTQS14ODgzLTJ2bWcteHdmN84AA7PJ

Ecosystems:
Packages:
Source:
lobe-chat: GSA_kwCzR0hTQS1teGhxLXh3M2ctcnBoY84AA74V

Ecosystems:
Packages:
Source:
borg: GSA_kwCzR0hTQS04cTh2LTI4cm0tcXc0d84AASIS

Ecosystems:
Packages:
Source:
hawk: GSA_kwCzR0hTQS00NHB3LWgyY3ctdzN2cc4AAgdL

Ecosystems:
Packages:
Source:
Slim: GSA_kwCzR0hTQS03NG1mLXZqcGctOXhoN84AAc0L

Ecosystems:
Packages:
Source:
fonttools: GSA_kwCzR0hTQS02NjczLTQ5ODMtMnZ4Nc4AA4Sn

Ecosystems:
Packages:
Source:
pdf.js: GSA_kwCzR0hTQS13Z3JtLTY3eGYtaGhwcc4AA7z7

Ecosystems:
Packages:
Source:
scipy: GSA_kwCzR0hTQS14cDc2LTM1N2ctOXdxcc3gGw

Ecosystems:
Packages:
Source:
ImageSharp: GSA_kwCzR0hTQS1nODVyLTZ4MnEtNDV3N84AA7Bf

Ecosystems:
Packages:
Source:
huntr: GSA_kwCzR0hTQS1oanI0LWZoZ3AtMjNnOc4AAnka

Ecosystems:
Packages:
Source:
celery: GSA_kwCzR0hTQS1ycGM2LWg0NTUtM3J4Nc4AAf1-

Ecosystems:
Packages:
Source:
sccache: GSA_kwCzR0hTQS14N2ZyLXBnOGYtOTNmNc4AAzhh

Ecosystems:
Packages:
Source:
node-convict: GSA_kwCzR0hTQS14Mnc1LTcyNWotZ2YyZ809pw

Ecosystems:
Packages:
Source:
bot: GSA_kwCzR0hTQS1xNWg2LTQ5Z2ctMndmZ84AAnmm

Ecosystems:
Packages:
Source:
think: GSA_kwCzR0hTQS03NWZtLTUybW0tcTVybc4AAUy_

Ecosystems:
Packages:
Source:
KumbiaPHP: GSA_kwCzR0hTQS14NmdxLXZyNTktNHE1cc4AAlAa

Ecosystems:
Packages:
Source:
thelounge: GSA_kwCzR0hTQS1nNDlxLWp3NDItNng4Nc4AA74Q

Ecosystems:
Packages:
Source:
High
wn-dusk-plugin: GSA_kwCzR0hTQS1jaGNwLWc5ajUtM3h4eM4AA6-A
Dusk plugin may allow unfettered user authentication in misconfigured installs
Ecosystems: packagist
Packages: winter/wn-dusk-plugin
Source: github
Published: about 1 month ago
Moderate
mautic: GSA_kwCzR0hTQS1tZ3Y4LXc0OWYtODIyd84AA69_
Mautic: MST-48 Server-Side Request Forgery in Asset section
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: about 1 month ago
High
mautic: GSA_kwCzR0hTQS1xangzLTJnMzUtNmh2OM4AA69Z
Mautic Sensitive Data Exposure due to inadequate user permission settings
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: about 1 month ago
Moderate
mautic: GSA_kwCzR0hTQS1qajZ3LTJjcWctN3A5NM4AA69Y
Mautic SQL Injection in dynamic Reports
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: about 1 month ago
High
mautic: GSA_kwCzR0hTQS05ZmN4LWN2NTYtdzU4cM4AA69X
Mautic vulnerable to Relative Path Traversal / Arbitrary File Deletion due to GrapesJS builder
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: about 1 month ago
High
timber: GSA_kwCzR0hTQS02MzYzLXY1bTQtZnZxM84AA68U
timber/timber vulnerable to Deserialization of Untrusted Data
Ecosystems: packagist
Packages: timber/timber
Source: github
Published: about 1 month ago
Moderate
mautic: GSA_kwCzR0hTQS1maGN4LWY3amctangzZs4AA68T
Mautic vulnerable to cross-site scripting in notifications via saving Dashboards
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: about 1 month ago
High
mautic: GSA_kwCzR0hTQS0ycmM1LTI3NTUtdjQyMs4AA671
Mautic vulnerable to stored cross-site scripting in description field
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: about 1 month ago
Low
undici: GSA_kwCzR0hTQS05cXhyLXFqNTQtaDY3Ms4AA6o2
Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect
Ecosystems: npm
Packages: undici
Source: github
Published: about 1 month ago
Low
undici: GSA_kwCzR0hTQS1tNHY4LXdxdnItcDlmN84AA6o1
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
Ecosystems: npm
Packages: undici
Source: github
Published: about 1 month ago
Moderate
vite: GSA_kwCzR0hTQS04amh3LTI4OWgtamgyZ84AA6l1
Vite's `server.fs.deny` did not deny requests for patterns with directories.
Ecosystems: npm
Packages: vite
Source: github
Published: about 1 month ago
High
packager: GSA_kwCzR0hTQS0zNGgzLThtdzQtcXc1N84AA6d1
@electron/packager's build process memory potentially leaked into final executable
Ecosystems: npm
Packages: @electron/packager
Source: github
Published: about 2 months ago
Moderate
KaTeX: GSA_kwCzR0hTQS0zd2M1LWZjdzItMjMyOc4AA6Rb
KaTeX missing normalization of the protocol in URLs allows bypassing forbidden protocols
Ecosystems: npm
Packages: katex
Source: github
Published: about 2 months ago
Moderate
KaTeX: GSA_kwCzR0hTQS1mOTh3LTdjeHItZmYyaM4AA6Ra
KaTeX's `\includegraphics` does not escape filename
Ecosystems: npm
Packages: katex
Source: github
Published: about 2 months ago
Moderate
KaTeX: GSA_kwCzR0hTQS1jdnI2LTM3Z3gtdjh3Y84AA6RZ
KaTeX's maxExpand bypassed by Unicode sub/superscripts
Ecosystems: npm
Packages: katex
Source: github
Published: about 2 months ago
Moderate
KaTeX: GSA_kwCzR0hTQS02NGZtLThodzItdjcyd84AA6RY
KaTeX's maxExpand bypassed by `\edef`
Ecosystems: npm
Packages: katex
Source: github
Published: about 2 months ago
High
grav: GSA_kwCzR0hTQS0ybTd4LWM3cHgtaHA1OM4AA6Oy
Server Side Template Injection (SSTI) via Twig escape handler
Ecosystems: packagist
Packages: getgrav/grav
Source: github
Published: about 2 months ago
High
grav: GSA_kwCzR0hTQS1yNnZ3LTh2OHItcG1wNM4AA6Ox
Server Side Template Injection (SSTI)
Ecosystems: packagist
Packages: getgrav/grav
Source: github
Published: about 2 months ago
High
grav: GSA_kwCzR0hTQS1xZnY0LXE0NHItZzdyds4AA6Ow
Server Side Template Injection (SSTI)
Ecosystems: packagist
Packages: getgrav/grav
Source: github
Published: about 2 months ago
High
grav: GSA_kwCzR0hTQS1jOWdwLTY0YzQtMnJyaM4AA6Ov
Server-Side Template Injection (SSTI) with Grav CMS security sandbox bypass
Ecosystems: packagist
Packages: getgrav/grav
Source: github
Published: about 2 months ago
High
grav: GSA_kwCzR0hTQS1tN2h4LWh3NmgtbXFtY84AA6Ou
File Upload Path Traversal
Ecosystems: packagist
Packages: getgrav/grav
Source: github
Published: about 2 months ago
High
webpack-dev-middleware: GSA_kwCzR0hTQS13cjNqLXB3ajktaHFxNs4AA6Nc
Path traversal in webpack-dev-middleware
Ecosystems: npm
Packages: webpack-dev-middleware
Source: github
Published: about 2 months ago
Critical
parse-server: GSA_kwCzR0hTQS02aGg3LTQ2cjItdmYyOc4AA6JD
Server crashes on invalid Cloud Function or Cloud Job name
Ecosystems: npm
Packages: parse-server
Source: github
Published: about 2 months ago
High
astropy: GSA_kwCzR0hTQS1oMng2LTVqeDUtNDZoZs4AA6Gg
RCE in TranformGraph().to_dot_graph function
Ecosystems: pypi
Packages: astropy
Source: github
Published: about 2 months ago
Moderate
RSSHub: GSA_kwCzR0hTQS0zcDNwLWNnajctdmd3M84AA5zO
RSSHub vulnerable to Server-Side Request Forgery
Ecosystems: npm
Packages: rsshub
Source: github
Published: 2 months ago
Moderate
RSSHub: GSA_kwCzR0hTQS0yd3F3LWhyNGYteHJoaM4AA5zN
RSSHub Cross-site Scripting vulnerability caused by internal media proxy
Ecosystems: npm
Packages: rsshub
Source: github
Published: 2 months ago
Critical
grav: GSA_kwCzR0hTQS1mNmcyLWg3cXYtM201ds4AA5zK
Remote Code Execution by uploading a phar file using frontmatter
Ecosystems: packagist
Packages: getgrav/grav
Source: github
Published: 2 months ago
High
ImageSharp: GSA_kwCzR0hTQS02NXg3LWMyNzItN2c3cs4AA5xd
Use After Free in SixLabors.ImageSharp
Ecosystems: nuget
Packages: SixLabors.ImageSharp
Source: github
Published: 2 months ago
High
mio: GSA_kwCzR0hTQS1yOHc5LTV3Y2ctdmZqN84AA5wE
Mio's tokens for named pipes may be delivered after deregistration
Ecosystems: cargo
Packages: mio
Source: github
Published: 2 months ago
High
phpseclib: GSA_kwCzR0hTQS1qcjIyLThxZ20tNHE4N84AA5s3
phpseclib does not properly limit the ASN1 OID length
Ecosystems: packagist
Packages: phpseclib/phpseclib
Source: github
Published: 2 months ago
High
phpseclib: GSA_kwCzR0hTQS1oZzM1LW1wMjUtcWY2aM4AA5sw
phpseclib a large prime can cause a denial of service
Ecosystems: packagist
Packages: phpseclib/phpseclib
Source: github
Published: 2 months ago
Critical
parse-server: GSA_kwCzR0hTQS02OTI3LTN2cjktZnhmMs4AA5sK
ZDI-CAN-19105: Parse Server literalizeRegexPart SQL Injection
Ecosystems: npm
Packages: parse-server
Source: github
Published: 2 months ago
Moderate
bagisto: GSA_kwCzR0hTQS13NW14LTMzNGotNmZ3ds4AA5r1
Bagist Cross-site Scripting vulnerability
Ecosystems: packagist
Packages: bagisto/bagisto
Source: github
Published: 2 months ago
Moderate
livehelperchat: GSA_kwCzR0hTQS12NGNwLTJxN3YtaGc5cc4AA5pT
livehelperchat Server-Side Template Injection
Ecosystems: packagist
Packages: remdex/livehelperchat
Source: github
Published: 2 months ago
Moderate
magento-lts: GSA_kwCzR0hTQS1ncDZtLWZxNmgtY2pjeM4AA5jQ
Magento LTS vulnerable to stored XSS in admin file form
Ecosystems: packagist
Packages: openmage/magento-lts
Source: github
Published: 3 months ago
Moderate
subrion: GSA_kwCzR0hTQS14eGY4LWZwbXItZnc3ds4AA5ib
Subrion CMS vulnerable to SQL Injection
Ecosystems: packagist
Packages: intelliants/subrion
Source: github
Published: 3 months ago
Critical
fiber: GSA_kwCzR0hTQS1mbWc0LXg4cHctaGpoZ84AA5dK
Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials
Ecosystems: go
Packages: github.com/gofiber/fiber/v2
Source: github
Published: 3 months ago
Moderate
decidim: GSA_kwCzR0hTQS05dzk5LTc4cmotaG14cc4AA5Zn
Cross-site scripting (XSS) in the dynamic file uploads
Ecosystems: rubygems
Packages: decidim-core, decidim
Source: github
Published: 3 months ago
Moderate
decidim: GSA_kwCzR0hTQS13M3E4LW00OTItNHB3cM4AA5Zd
Possibility to circumvent the invitation token expiry period
Ecosystems: rubygems
Packages: decidim-system, decidim-admin, decidim, devise_invitable
Source: github
Published: 3 months ago
Moderate
decidim: GSA_kwCzR0hTQS1mM3FtLXZmYzMtamc2ds4AA5ZJ
Possible CSRF attack at questionnaire templates preview
Ecosystems: rubygems
Packages: decidim-templates
Source: github
Published: 3 months ago
Low
decidim: GSA_kwCzR0hTQS1yMjc1LWo1N2MtN21mMs4AA5ZI
Race condition in Endorsements
Ecosystems: rubygems
Packages: decidim
Source: github
Published: 3 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS1yOTY5LTc4M2YtNmpxcs4AA5Wp
Improper Neutralization of HTTP Headers in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 3 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS04aHAzLXJtcjcteGg4OM4AA5Wv
Open Redirect in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 3 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS05M3g4LTY2ajItd3dyNc4AA5Wo
Server-Side Request Forgery in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 3 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS12ZnBoLWhqZnYtY3B2Ms4AA5Wx
Improper Restriction of Excessive Authentication Attempts in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 3 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS1jN3ZmLW0zOTQtbTR4NM4AA5Wn
Use of Insufficiently Random Values in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 3 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS1mZjcyLWZmNDItYzNnd84AA5Wm
Cross-site Scripting in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 3 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS04aDk1LWpjcDUtcGpwcs4AA5Wt
Improper Validation of Array Index in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 3 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS12cDY2LWdmN3ctOW00eM4AA5Wu
Insufficient Session Expiration in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 3 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS12ajM2LTNjY3ItNjU2M84AA5Wr
Authentication Bypass by Spoofing in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 3 months ago
Low
undici: GSA_kwCzR0hTQS0zNzg3LTZwcnYtaDl3M84AA5Vg
Undici proxy-authorization header not cleared on cross-origin redirect in fetch
Ecosystems: npm
Packages: undici
Source: github
Published: 3 months ago
Moderate
undici: GSA_kwCzR0hTQS05ZjI0LWpxaG0tamZjd84AA5Vf
fetch(url) leads to a memory leak in undici
Ecosystems: npm
Packages: undici
Source: github
Published: 3 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS14d212LWN4N3AtZnFmY84AA5Oo
caddy-security plugin for Caddy vulnerable to reflected Cross-site Scripting
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 3 months ago
Critical
pixelfed: GSA_kwCzR0hTQS1nY2NxLWgzeGotamd2Zs4AA5N1
Pixelfed doesn't check OAuth Scopes in API routes, giving elevated permissions
Ecosystems: packagist
Packages: pixelfed/pixelfed
Source: github
Published: 3 months ago
Moderate
Ghost: GSA_kwCzR0hTQS05OXZjLXh3OGotcGhqbc4AA5M7
Ghost has possible Cross-site Scripting issue
Ecosystems: npm
Packages: ghost
Source: github
Published: 3 months ago
Moderate
nonebot2: GSA_kwCzR0hTQS01OWo4LTc3NnYteHh4Z84AA5Lo
NoneBot Potential Information Leak in User-Constructed Message Templates
Ecosystems: pypi
Packages: nonebot2
Source: github
Published: 3 months ago
High
yarn: GSA_kwCzR0hTQS1tcHdqLWZjcjYteDM0Y84AA5DS
Yarn untrusted search path vulnerability
Ecosystems: npm
Packages: yarn
Source: github
Published: 3 months ago
High
pulse-binding-rust: GSA_kwCzR0hTQS1mNTZnLWNocXAtMjJtOc4AA5Ct
Use after free in libpulse-binding
Ecosystems: cargo
Packages: libpulse-binding
Source: github
Published: 3 months ago
Moderate
lobe-chat: GSA_kwCzR0hTQS1wZjU1LWZqOTYteGYzN84AA499
@lobehub/chat vulnerable to unauthorized access to plugins
Ecosystems: npm
Packages: @lobehub/chat
Source: github
Published: 3 months ago
Moderate
goreleaser: GSA_kwCzR0hTQS1oM3EyLTh3aHgtYzI5aM4AA485
`goreleaser release --debug` shows secrets
Ecosystems: go
Packages: github.com/goreleaser/goreleaser
Source: github
Published: 3 months ago
High
urql: GSA_kwCzR0hTQS1xaGpmLWhtNWotMzM1d84AA483
@urql/next Cross-site Scripting vulnerability
Ecosystems: npm
Packages: @urql/next
Source: github
Published: 3 months ago
High
lemmy: GSA_kwCzR0hTQS1yNjRyLTVoNDMtMjZxds4AA42n
Any authenticated user may obtain private message details from other users on the same instance
Ecosystems: cargo
Packages: lemmy_server
Source: github
Published: 4 months ago
High
kit: GSA_kwCzR0hTQS1nNW02LWh4cHAtZmM0Oc4AA4qX
Sending a GET or HEAD request with a body crashes SvelteKit
Ecosystems: npm
Packages: @sveltejs/adapter-node, @sveltejs/kit
Source: github
Published: 4 months ago
Moderate
Ghost: GSA_kwCzR0hTQS1maDM4LTlmZ3ItNDU0d84AA4mG
Cross-site Scripting in Ghost
Ecosystems: npm
Packages: ghost
Source: github
Published: 4 months ago
High
vite: GSA_kwCzR0hTQS1jMjR2LThyZmMtdzh2d84AA4lu
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
Ecosystems: npm
Packages: vite
Source: github
Published: 4 months ago
Moderate
tracing: GSA_kwCzR0hTQS04ZjI0LTZtMjktd20ycs4AA4ih
use-after-free in tracing
Ecosystems: cargo
Packages: tracing
Source: github
Published: 4 months ago
Moderate
bagisto: GSA_kwCzR0hTQS1jOTYyLWc1MzMtODIzZs4AA4gW
Cross-site Scripting in Bagisto
Ecosystems: packagist
Packages: bagisto/bagisto
Source: github
Published: 4 months ago
High
evershop: GSA_kwCzR0hTQS1nZ3BtLTlxZngtbWh3Z84AA4bk
EverShop vulnerable to improper authorization in GraphQL endpoints
Ecosystems: npm
Packages: @evershop/evershop
Source: github
Published: 4 months ago
High
evershop: GSA_kwCzR0hTQS0zMnIzLTU3aHAtY2dmd84AA4bm
EverShop at risk to unauthorized access via weak HMAC secret
Ecosystems: npm
Packages: @evershop/evershop
Source: github
Published: 4 months ago
Low
framework: GSA_kwCzR0hTQS03MzNyLTh4Y3Atdzltcs4AA4N5
Flarum's logout Route allows open redirects
Ecosystems: packagist
Packages: flarum/framework, flarum/core
Source: github
Published: 4 months ago
High
verify-changed-files: GSA_kwCzR0hTQS1naG0yLXJxOHEtd3JoY84AA4Jn
Potential Actions command injection in output filenames (GHSL-2023-275)
Ecosystems: actions
Packages: tj-actions/verify-changed-files
Source: github
Published: 4 months ago
High
changed-files: GSA_kwCzR0hTQS1tY3BoLW0yNWotOGo2M84AA4Jm
tj-actions/changed-files has Potential Actions command injection in output filenames (GHSL-2023-271)
Ecosystems: actions
Packages: tj-actions/changed-files
Source: github
Published: 4 months ago