Ecosyste.ms: OpenCollective

An open API service for software projects hosted on Open Collective.

TShock: GSA_kwCzR0hTQS1odm05LXdjOGotbWdyY84ABCjN

Ecosystems:
Packages:
Source:
jquery: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpwY3EtY2d3Ni12NGo2

Ecosystems:
Packages:
Source:
simplexlsx: GSA_kwCzR0hTQS14Nm1oLXJqd20tOHBoN84ABCXl

Ecosystems:
Packages:
Source:
jquery: GSA_kwCzR0hTQS0yNTdxLXB2ODktdjN4ds4AA0D1

Ecosystems:
Packages:
Source:
http4k: GSA_kwCzR0hTQS03bWo1LWhqamotOHJnd84ABCXi

Ecosystems:
Packages:
Source:
jquery: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVjcDQteG1ydy01OXdm

Ecosystems:
Packages:
Source:
jquery: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1ocHAtODc1dy05Y3B2

Ecosystems:
Packages:
Source:
pnpm: GSA_kwCzR0hTQS12bTMyLTlycWYtcmgzcs4ABCQL

Ecosystems:
Packages:
Source:
jquery: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE0bTMtMmo3aC1mN3h3

Ecosystems:
Packages:
Source:
High
lobe-chat: GSA_kwCzR0hTQS0yeGNjLXZtM2YtbThyd84ABByj
@lobehub/chat Server Side Request Forgery vulnerability
Ecosystems: npm
Packages: @lobehub/chat
Source: github
Published: 25 days ago
Low
kit: GSA_kwCzR0hTQS1yamp2LTg3bXgtNngzaM4ABBvG
@sveltejs/kit vulnerable to on dev mode 404 page
Ecosystems: npm
Packages: @sveltejs/kit
Source: github
Published: 26 days ago
Low
kit: GSA_kwCzR0hTQS1taDJ4LWZjcWgtZm1xds4ABBvF
@sveltejs/kit has unescaped error message included on error page
Ecosystems: npm
Packages: @sveltejs/kit
Source: github
Published: 26 days ago
High
litestar: GSA_kwCzR0hTQS1namNjLWp2Z3ctd3Z3as4ABBmv
Litestar allows unbounded resource consumption (DoS vulnerability)
Ecosystems: pypi
Packages: starlite, litestar
Source: github
Published: about 1 month ago
Moderate
cert-manager: GSA_kwCzR0hTQS1yNHBnLXZnNTQtd3h4NM4ABBmY
cert-manager ha a potential slowdown / DoS when parsing specially crafted PEM inputs
Ecosystems: go
Packages: github.com/cert-manager/cert-manager
Source: github
Published: about 1 month ago
Critical
cobbler: GSA_kwCzR0hTQS1tMjZjLWZjZ2gtY3A2aM4ABBeO
cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes
Ecosystems: pypi
Packages: cobbler
Source: github
Published: about 1 month ago
High
librenms: GSA_kwCzR0hTQS04Zmg0LTk0MnItamYyZ84ABBab
LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/services.inc.php
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 month ago
Low
rewrite: GSA_kwCzR0hTQS03cTdnLTR4bTgtODljcc4ABBaa
Regular Expression Denial of Service (ReDoS) in @eslint/plugin-kit
Ecosystems: npm
Packages: @eslint/plugin-kit
Source: github
Published: about 1 month ago
Critical
librenms: GSA_kwCzR0hTQS14NjQ1LTZwZjkteHd4d84ABBZK
LibreNMS has an Authenticated OS Command Injection
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 month ago
High
librenms: GSA_kwCzR0hTQS1ndjRtLWY2ZngtODU5eM4ABBZJ
LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/print-customoid.php
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 month ago
High
librenms: GSA_kwCzR0hTQS0yOHA3LWY2aDYtM2poM84ABBZI
LibreNMS has a Reflected XSS ('Cross-site Scripting') in librenms/includes/html/pages/wireless.inc.php
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 month ago
High
librenms: GSA_kwCzR0hTQS1wNjZxLXBwd3ItcTVqOM4ABBZH
LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/dev-overview-data.inc.php
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 month ago
High
librenms: GSA_kwCzR0hTQS03NjYzLTM3cmctYzM3N84ABBZG
LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsController.php
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 month ago
High
librenms: GSA_kwCzR0hTQS00bTVyLXcycnEtcTU0cc4ABBZF
LibreNMS has a Persistent XSS from Insecure Input Sanitization Affects Multiple Endpoints
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 month ago
High
librenms: GSA_kwCzR0hTQS1xcjhmLTVxcWctajN3Z84ABBZE
LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/overview/services.inc.php
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 month ago
High
librenms: GSA_kwCzR0hTQS12N3c5LTYzeGgtNnIzd84ABBZD
LibreNMS has a Reflected XSS ('Cross-site Scripting') in librenms/includes/functions.php
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 month ago
High
librenms: GSA_kwCzR0hTQS14aDRnLWM5cDYtNWp4Z84ABBY1
LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsController.php
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 month ago
High
librenms: GSA_kwCzR0hTQS1ybXI0LXg2YzktamM2OM4ABBY0
LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/capture.inc.php
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 month ago
High
librenms: GSA_kwCzR0hTQS04ODhqLXBqcWgtZng1OM4ABBYz
Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/edituser.inc.php
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 month ago
Moderate
librenms: GSA_kwCzR0hTQS1jODZxLXJqMzctOGY4Nc4ABBYy
LibreNMS has a stored XSS in ExamplePlugin with Device's Notes
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 month ago
High
librenms: GSA_kwCzR0hTQS1nZndyLXhxbWotajI3ds4ABBYx
LibreNMS has a stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/api-access.inc.php
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 month ago
Moderate
wallabag: GSA_kwCzR0hTQS05OXc4LWM1ZjYtOTZwcM4ABBYh
CSRF leading to delete account in wallabag/wallabag
Ecosystems: packagist
Packages: wallabag/wallabag
Source: github
Published: about 1 month ago
Moderate
memos: GSA_kwCzR0hTQS01cjJnLTU5cHgtM3E5d84ABBYl
Stored XSS using two files in usememos/memos
Ecosystems: go
Packages: github.com/usememos/memos
Source: github
Published: about 1 month ago
Moderate
decidim: GSA_kwCzR0hTQS1qNGg2LWdjajctN3Y5ds4ABBTI
decidim-meetings Cross-site scripting vulnerability in the online or hybrid meeting embeds
Ecosystems: rubygems
Packages: decidim-meetings
Source: github
Published: about 1 month ago
Moderate
platform: GSA_kwCzR0hTQS1jbTQ2LWdxZjQtbXY0Zs4ABBP3
Orchid Platform has Method Exposure Vulnerability in Modals
Ecosystems: packagist
Packages: orchid/platform
Source: github
Published: about 1 month ago
Critical
osmedeus: GSA_kwCzR0hTQS13dnY3LXdtNXYtdzJnds4ABA-U
Osmedeus Web Server Vulnerable to Stored XSS, Leading to RCE
Ecosystems: go
Packages: github.com/j3ssie/osmedeus
Source: github
Published: about 2 months ago
Critical
refit: GSA_kwCzR0hTQS0zaHhnLWZ4d20tOGdmN84ABA9E
CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes
Ecosystems: nuget
Packages: Refit
Source: github
Published: about 2 months ago
Moderate
ash_postgres: GSA_kwCzR0hTQS1oZjU5LTdyd3EtNzg1bc4ABAmD
In AshPostgres, empty, atomic, non-bulk actions, policy bypass for side-effects vulnerability.
Ecosystems: hex
Packages: ash_postgres
Source: github
Published: about 2 months ago
Critical
vendure: GSA_kwCzR0hTQS1yOW1xLTNjOXItZm1qcc4ABARd
Vendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategy
Ecosystems: npm
Packages: @vendure/asset-server-plugin
Source: github
Published: 2 months ago
Moderate
markdown-to-jsx: GSA_kwCzR0hTQS00d3gzLTU0Z2gtOWZyOc4ABAQx
Cross site scripting in markdown-to-jsx
Ecosystems: npm
Packages: markdown-to-jsx
Source: github
Published: 2 months ago
Moderate
astro: GSA_kwCzR0hTQS1tODV3LTNoOTUtaGNmOc4ABAQP
DOM Clobbering Gadget found in astro's client-side router that leads to XSS
Ecosystems: npm
Packages: astro
Source: github
Published: 2 months ago
Moderate
kubesphere: GSA_kwCzR0hTQS1wMjZyLWdmZ2MtYzQ3aM4ABAQI
KubeSphere IDOR vulnerability
Ecosystems: go
Packages: github.com/kubesphere/kubesphere
Source: github
Published: 2 months ago
Moderate
saltcorn: GSA_kwCzR0hTQS1wZjU2LWg5cWYtcnhxNM4ABAA4
Saltcorn Server Stored Cross-Site Scripting (XSS) in event logs page
Ecosystems: npm
Packages: @saltcorn/server
Source: github
Published: 3 months ago
High
saltcorn: GSA_kwCzR0hTQS00M2YzLWg2M3ctcDZmNs4ABAA3
Saltcorn Server allows logged-in users to delete arbitrary files because of a path traversal vulnerability
Ecosystems: npm
Packages: @saltcorn/server
Source: github
Published: 3 months ago
High
parse-server: GSA_kwCzR0hTQS04eHE5LWc3Y2gtMzVoZ84AA_9o
Parse Server's custom object ID allows to acquire role privileges
Ecosystems: npm
Packages: parse-server
Source: github
Published: 3 months ago
High
saltcorn: GSA_kwCzR0hTQS1mbTc2LXc4ancteGY4bc4AA_8h
@saltcorn/plugins-loader unsanitized plugin name leads to a remote code execution (RCE) vulnerability when creating plugins using git source
Ecosystems: npm
Packages: @saltcorn/plugins-loader
Source: github
Published: 3 months ago
Low
express: GSA_kwCzR0hTQS1qajc4LTVmbXYtbXYyOM4AA_8a
Express Open Redirect vulnerability
Ecosystems: npm
Packages: express
Source: github
Published: 3 months ago
High
saltcorn: GSA_kwCzR0hTQS03OHAzLWZ3Y3EtNjJjMs4AA_8Q
@saltcorn/server Remote Code Execution (RCE) / SQL injection via prototype pollution by manipulating `lang` and `defstring` parameters when setting localizer strings
Ecosystems: npm
Packages: @saltcorn/server
Source: github
Published: 3 months ago
Moderate
saltcorn: GSA_kwCzR0hTQS1jZnF4LWY0M20tdmZoN84AA_8P
@saltcorn/server arbitrary file and directory listing when accessing build mobile app results
Ecosystems: npm
Packages: @saltcorn/server
Source: github
Published: 3 months ago
Moderate
saltcorn: GSA_kwCzR0hTQS0yNzdoLXB4NG0tNjJxOM4AA_8O
@saltcorn/server arbitrary file zip read and download when downloading auto backups
Ecosystems: npm
Packages: @saltcorn/server
Source: github
Published: 3 months ago
Low
librenms: GSA_kwCzR0hTQS14OGdtLWozNnAtZnBwZs4AA_6E
LibreNMS vulnerable to Stored Cross-site Scripting via File Upload
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: 3 months ago
Moderate
librenms: GSA_kwCzR0hTQS03Zjg0LTI4cWgtOTQ4Ns4AA_52
LibreNMS has Stored Cross-site Scripting vulnerability in "Alert Transports" feature
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: 3 months ago
High
librenms: GSA_kwCzR0hTQS1mYzM4LTIyNTQtNDhnN84AA_51
LibreNMS has Stored Cross-site Scripting vulnerability in "Device Group" Name
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: 3 months ago
Moderate
librenms: GSA_kwCzR0hTQS1qMmo5LTdwcjYteHF3ds4AA_50
LibreNMS has Stored Cross-site Scripting vulnerability in "Alert Rules" feature
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: 3 months ago
Low
librenms: GSA_kwCzR0hTQS1nY2dwLXEyanEtZnc1Ms4AA_5z
LibreNMS has Stored Cross-site Scripting vulnerability in "Alert Templates" feature
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: 3 months ago
Moderate
librenms: GSA_kwCzR0hTQS1yd3djLTJ2OHEtZ2M5ds4AA_5y
LibreNMS has Stored Cross-site Scripting vulnerability in "Device Dependencies" feature
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: 3 months ago
High
decidim: GSA_kwCzR0hTQS1jYzRnLW0zZzcteG13OM4AA_5i
Decidim has a cross-site scripting vulnerability in the version control page
Ecosystems: rubygems
Packages: decidim
Source: github
Published: 3 months ago
Moderate
layui: GSA_kwCzR0hTQS1qODI3LTZyZ2YtOTYyOc4AA_zC
Layui has DOM Clobbering gadgets that leads to Cross-site Scripting
Ecosystems: npm
Packages: layui
Source: github
Published: 3 months ago
Moderate
kratos: GSA_kwCzR0hTQS13YzQzLTczdzcteDJmNc4AA_zB
Ory Kratos's setting required_aal `highest_available` does not properly respect code + mfa credentials
Ecosystems: go
Packages: github.com/ory/kratos
Source: github
Published: 3 months ago
Moderate
strawberry: GSA_kwCzR0hTQS03OWdwLXE0d3YtMzNmcs4AA_xi
Cross-Site Request Forgery (CSRF) in strawberry-graphql
Ecosystems: pypi
Packages: strawberry-graphql
Source: github
Published: 3 months ago
High
rollup: GSA_kwCzR0hTQS1nY3g0LW13NjItZzh3bc4AA_u0
DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS
Ecosystems: npm
Packages: rollup
Source: github
Published: 3 months ago
Moderate
lobe-chat: GSA_kwCzR0hTQS0zZmM4LTJyM2YtOHdyZ84AA_um
lobe-chat implemented an insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
Ecosystems: npm
Packages: @lobehub/chat
Source: github
Published: 3 months ago
Moderate
rspack: GSA_kwCzR0hTQS04NGp3LWc0M3YtOGdqbc4AA_sX
DOM Clobbering Gadget found in Rspack's AutoPublicPathRuntimeModule that leads to XSS
Ecosystems: npm
Packages: @rspack/core
Source: github
Published: 3 months ago
High
mautic: GSA_kwCzR0hTQS01aGM1LWZ4cjktNWZyY84AA_rw
Mautic has insufficient authentication in upgrade flow
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: 3 months ago
Moderate
mautic: GSA_kwCzR0hTQS04dmZmLTM1cW0tcWp2ds4AA_rk
Mautic allows users enumeration due to weak password login
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: 3 months ago
Moderate
mautic: GSA_kwCzR0hTQS1xZjZtLTZtNGctcm1yY84AA_rj
Mautic has insufficient authentication in upgrade flow
Ecosystems: packagist
Packages: mautic/core-lib, mautic/core
Source: github
Published: 3 months ago
Moderate
mautic: GSA_kwCzR0hTQS14cGM1LXJyMzktdjh2Ms4AA_ri
Mautic has an XSS in contact tracking and page hits report
Ecosystems: packagist
Packages: mautic/core, mautic/core-lib
Source: github
Published: 3 months ago
Moderate
mautic: GSA_kwCzR0hTQS03M2dyLTMyd2ctcWhoN84AA_rh
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Ecosystems: packagist
Packages: mautic/core-lib, mautic/core
Source: github
Published: 3 months ago
Moderate
mautic: GSA_kwCzR0hTQS14djY4LXJybXctOXh3Zs4AA_rg
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Ecosystems: packagist
Packages: mautic/core-lib, mautic/core
Source: github
Published: 3 months ago
High
mautic: GSA_kwCzR0hTQS14M2p4LTV3Nm0tcTJmY84AA_rI
Mautic vulnerable to Improper Access Control in UI upgrade process
Ecosystems: packagist
Packages: mautic/core, mautic/core-lib
Source: github
Published: 3 months ago
Moderate
vite: GSA_kwCzR0hTQS02NHZyLWc0NTItcXZwM84AA_m5
Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS
Ecosystems: npm
Packages: vite
Source: github
Published: 3 months ago
Moderate
vite: GSA_kwCzR0hTQS05Y3d4LTI4ODMtNHdmeM4AA_m4
Vite's `server.fs.deny` is bypassed when using `?import&raw`
Ecosystems: npm
Packages: vite
Source: github
Published: 3 months ago
Moderate
vllm: GSA_kwCzR0hTQS13YzM2LTk2OTQtZjlyZs4AA_mw
vLLM Denial of Service via the best_of parameter
Ecosystems: pypi
Packages: vllm
Source: github
Published: 3 months ago
High
vllm: GSA_kwCzR0hTQS13MnI3LTk1NzktMjdoZs4AA_m0
vLLM denial of service vulnerability
Ecosystems: pypi
Packages: vllm
Source: github
Published: 3 months ago
Moderate
decidim: GSA_kwCzR0hTQS12dnF3LWZxd3gtbXFtbc4AA_kB
Decidim::Admin vulnerable to cross-site scripting (XSS) in the admin panel with QuillJS WYSWYG editor
Ecosystems: rubygems
Packages: decidim
Source: github
Published: 3 months ago
Moderate
decidim: GSA_kwCzR0hTQS1yeDlmLTVnZ3YtNXJoNs4AA_kA
Decidim::Admin vulnerable to cross-site scripting (XSS) in the admin activity log
Ecosystems: rubygems
Packages: decidim-admin
Source: github
Published: 3 months ago
Low
express: GSA_kwCzR0hTQS1xdzZoLXZnaDktajZ3eM4AA_cW
express vulnerable to XSS via response.redirect()
Ecosystems: npm
Packages: express
Source: github
Published: 3 months ago
High
external-secrets: GSA_kwCzR0hTQS1xd2djLXJyMzUtaDR4Oc4AA_YS
External Secrets Operator vulnerable to privilege escalation
Ecosystems: go
Packages: github.com/external-secrets/external-secrets
Source: github
Published: 3 months ago
High
quinn: GSA_kwCzR0hTQS12cjI2LWpjcTUtZmpqOM4AA_QI
Denial of service in quinn-proto when using `Endpoint::retry()`
Ecosystems: cargo
Packages: quinn-proto
Source: github
Published: 4 months ago
Moderate
svelte: GSA_kwCzR0hTQS04MjY2LTg0d3Atd3Y1Y84AA_Dj
Svelte has a potential mXSS vulnerability due to improper HTML escaping
Ecosystems: npm
Packages: svelte
Source: github
Published: 4 months ago
Moderate
RestSharp: GSA_kwCzR0hTQS00cnI2LTJ2OXYtd2NwY84AA_CY
CRLF Injection in RestSharp's `RestRequest.AddHeader` method
Ecosystems: nuget
Packages: RestSharp
Source: github
Published: 4 months ago
Moderate
webpack: GSA_kwCzR0hTQS00dnZqLTRjcHItcDk4Ns4AA--k
Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS
Ecosystems: npm
Packages: webpack
Source: github
Published: 4 months ago
High
memos: GSA_kwCzR0hTQS1wNGZ4LXFmMmgtanBtas4AA-4e
memos CORS Misconfiguration in server.go (GHSL-2024-034)
Ecosystems: go
Packages: github.com/usememos/memos
Source: github
Published: 4 months ago
Moderate
casdoor: GSA_kwCzR0hTQS1ndjJwLTRtdmctZzMyaM4AA-4d
Casdoor has reflected XSS in QrCodePage.js (GHSL-2024-036)
Ecosystems: go
Packages: github.com/casdoor/casdoor
Source: github
Published: 4 months ago
High
casdoor: GSA_kwCzR0hTQS1tY2h4LTdqNjctOG1jZs4AA-4c
Casdoor CORS misconfiguration (GHSL-2024-035)
Ecosystems: go
Packages: github.com/casdoor/casdoor
Source: github
Published: 4 months ago
Moderate
Ghost: GSA_kwCzR0hTQS03OHgyLWN3cDktNWo0Ms4AA-0D
Ghost's improper authentication allows access to member information and actions
Ecosystems: npm
Packages: @tryghost/portal, ghost
Source: github
Published: 4 months ago
Moderate
apollo: GSA_kwCzR0hTQS1jNmMzLWg0ZjctMzk2Ms4AA-0A
apollo-portal has potential unauthorized access issue
Ecosystems: maven
Packages: com.ctrip.framework.apollo:apollo
Source: github
Published: 4 months ago
High
microcks: GSA_kwCzR0hTQS1yNnBoLTVmcDItM3cyds4AA-xK
Microcks's POST /api/import and POST /api/export endpoints allow non-administrator access
Ecosystems: maven
Packages: io.github.microcks:microcks-app
Source: github
Published: 4 months ago
Critical
stash: GSA_kwCzR0hTQS03NWpmLTUyamctcXFoNM4AA-se
SQL injection in github.com/stashapp/stash
Ecosystems: go
Packages: github.com/stashapp/stash
Source: github
Published: 4 months ago
High
boa: GSA_kwCzR0hTQS1mNjdxLXdyNnctMjNqcc4AA-q9
Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objects
Ecosystems: cargo
Packages: boa_engine
Source: github
Published: 4 months ago
High
axios: GSA_kwCzR0hTQS04aGM0LXZoNjQtY3htas4AA-hD
Server-Side Request Forgery in axios
Ecosystems: npm
Packages: axios
Source: github
Published: 4 months ago
High
litestar: GSA_kwCzR0hTQS00aHEyLXJwZ2MtcjhyN84AA-gk
Withdrawn Advisory: Litestar has an environment Variable injection in `docs-preview.yml` workflow
Ecosystems: pypi
Packages: litestar
Source: github
Published: 4 months ago
Moderate
gorush: GSA_kwCzR0hTQS1wM3BmLW1mZjgtM2g0N84AA-bg
Gorush uses deprecated TLS versions
Ecosystems: go
Packages: github.com/appleboy/gorush
Source: github
Published: 5 months ago
Moderate
qwik: GSA_kwCzR0hTQS0ycndqLTd4cTgtNGd4NM4AA-a5
Qwik has a potential mXSS vulnerability due to improper HTML escaping
Ecosystems: npm
Packages: @builder.io/qwik
Source: github
Published: 5 months ago
Moderate
microweber: GSA_kwCzR0hTQS1tOTl2LW1tZzItNjZ2Zs4AA-aj
Microweber Reflected Cross-site scripting (XSS) vulnerability
Ecosystems: packagist
Packages: microweber/microweber
Source: github
Published: 5 months ago
Critical
gitea: GSA_kwCzR0hTQS00aDRwLTU1M20tNDZxaM4AA-Zk
Gitea Cross-site Scripting Vulnerability
Ecosystems: go
Packages: code.gitea.io/gitea
Source: github
Published: 5 months ago
Moderate
owncast: GSA_kwCzR0hTQS05MzU1LTI3bTgtaDc0ds4AA-Yv
Owncast Path Traversal vulnerability
Ecosystems: go
Packages: github.com/owncast/owncast
Source: github
Published: 5 months ago
Moderate
memos: GSA_kwCzR0hTQS05Y3FtLW1ndjktdnY5as4AA-Yt
memos vulnerable to Server-Side Request Forgery and Cross-site Scripting
Ecosystems: go
Packages: github.com/usememos/memos
Source: github
Published: 5 months ago
Moderate
memos: GSA_kwCzR0hTQS02ZmNmLWczbXAteGoyeM4AA-Yq
memos vulnerable to Server-Side Request Forgery in /o/get/httpmeta
Ecosystems: go
Packages: github.com/usememos/memos
Source: github
Published: 5 months ago
Moderate
memos: GSA_kwCzR0hTQS02NWZtLTJqZ3Itajdxcc4AA-Yu
memos vulnerable to Server-Side Request Forgery in /api/resource
Ecosystems: go
Packages: github.com/usememos/memos
Source: github
Published: 5 months ago
High
owncast: GSA_kwCzR0hTQS12OTl3LXI1NmgtZzIzds4AA-Yr
Owncast Cross-Site Request Forgery vulnerability
Ecosystems: go
Packages: github.com/owncast/owncast
Source: github
Published: 5 months ago