Ecosyste.ms: OpenCollective

An open API service for software projects hosted on Open Collective.

High
omero-web: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWdmcDItdzVqbS05NTVx
OMERO.web exposes some unnecessary session information in the page
Ecosystems: pypi
Packages: omero-web
Source: github
Published: over 3 years ago
High
is-svg: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTdyMjgtM20zZi1yMnBy
Regular Expression Denial of Service (ReDoS)
Ecosystems: npm
Packages: is-svg
Source: github
Published: almost 4 years ago
Moderate
urllib3: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVwaGYtcHA3cC12YzJy
Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection
Ecosystems: pypi
Packages: urllib3
Source: github
Published: almost 4 years ago
High
madge: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTc1M2MtcGhoZy1jajI5
Madge vulnerable to command injection
Ecosystems: npm
Packages: madge
Source: github
Published: almost 4 years ago
Moderate
create-react-app: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVxNm0tM2g2NS13NTN4
react-dev-utils OS Command Injection in function `getProcessForPort`
Ecosystems: npm
Packages: react-dev-utils
Source: github
Published: almost 4 years ago
Low
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhoZngtaGdtZi12NnZw
Potential Host Header Poisoning on misconfigured servers
Ecosystems: packagist
Packages: october/backend
Source: github
Published: almost 4 years ago
High
pug: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA0OTMtNjM1cS1yNmdy
Remote code execution via the `pretty` option.
Ecosystems: npm
Packages: pug-code-gen, pug
Source: github
Published: almost 4 years ago
Moderate
docsify: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTJtbTktYzJmeC1jN200
Docsify XSS Vulnerability
Ecosystems: npm
Packages: docsify
Source: github
Published: almost 4 years ago
Moderate
eslint: GSA_kwCzR0hTQS1qY2dxLXhoMmYtMmhmbc4AAuAl
Regular Expression Denial of Service
Ecosystems: npm
Packages: eslint
Source: github
Published: almost 4 years ago
Low
next-auth: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXBnNTMtNTZjZy00bThx
Token verification bug in next-auth
Ecosystems: npm
Packages: next-auth
Source: github
Published: almost 4 years ago
Critical
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTdnZ3ctaDhwcC1yOTVy
October CMS Session ID not invalidated after logout
Ecosystems: packagist
Packages: october/rain
Source: github
Published: almost 4 years ago
High
dynamoose: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJycW0tcDIyMi04cGgy
Prototype Pollution in Dynamoose
Ecosystems: npm
Packages: dynamoose
Source: github
Published: almost 4 years ago
Moderate
bleach: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZ2MngtdnJwai1xcXBx
Cross-site scripting in Bleach
Ecosystems: pypi
Packages: bleach
Source: github
Published: almost 4 years ago
High
uap-core: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA0cGotbWc0ci14NnY0
Denial of Service in uap-core
Ecosystems: npm
Packages: uap-core
Source: github
Published: almost 4 years ago
High
mautic: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA3djQtZ202ai1jdzlt
XSS in Mautic
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: almost 4 years ago
Moderate
sticky: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWgzZ2ctN3d4Mi1jcTNo
XSS in Flarum Sticky extension
Ecosystems: packagist
Packages: flarum/sticky
Source: github
Published: almost 4 years ago
Moderate
tags: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTMyd3gtNGd4eC1oNDhm
Users can edit the tags of any discussion
Ecosystems: packagist
Packages: flarum/tags
Source: github
Published: almost 4 years ago
Moderate
electron: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWh2ZjgtaDJxaC0zN205
IPC messages delivered to the wrong frame in Electron
Ecosystems: npm
Packages: electron
Source: github
Published: almost 4 years ago
High
immer: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlxbWgtMjc2Zy14NXBq
Prototype Pollution in immer
Ecosystems: npm
Packages: immer
Source: github
Published: almost 4 years ago
Moderate
socket.io: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZ4d2YtNHJxaC12OGcz
CORS misconfiguration in socket.io
Ecosystems: npm
Packages: socket.io
Source: github
Published: almost 4 years ago
Moderate
mautic: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTI5djktMmZweC1qNWc5
CSV Injection vulnerability with exported contact lists in Mautic
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: almost 4 years ago
Moderate
mautic: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTloeDctcmc3dy14bTc5
XSS vulnerability in company name field in Mautic
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: almost 4 years ago
Moderate
mautic: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFqaHItYzIzZi13NzZx
Inline JS XSS vulnerability in Mautic
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: almost 4 years ago
High
mautic: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZmeGotcWc5My03d3dj
Mautic Sessions could be hijacked due to tracking contacts by an auto-incremented ID
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: almost 4 years ago
High
mautic: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZ4OTgtZng5ai03Yzc4
Disabled users able to log in with third party SSO plugin
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: almost 4 years ago
Moderate
mautic: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTV3NzQtang3bS14Nmh2
XSS vulnerability in theme config file in Mautic
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: almost 4 years ago
Moderate
mautic: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhjZjctY2o4cS1wY2pt
XSS vulnerability in Author URL of themes in Mautic
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: almost 4 years ago
Moderate
mautic: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFwZ3ctMmM3Mi00Yzg5
Mautic users able to download any files from server using filemanager
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: almost 4 years ago
Critical
mautic: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTM5d2otajNqYy04NTht
XSS vulnerability leveraged through referrers could allow un-authorized admin access in Mautic
Ecosystems: packagist
Packages: mautic/core
Source: github
Published: almost 4 years ago
Moderate
axios: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTR3MnYtcTIzNS12cDk5
Axios vulnerable to Server-Side Request Forgery
Ecosystems: npm
Packages: axios
Source: github
Published: almost 4 years ago
Low
parse-server: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTR3NDYtdzQ0bS0zanEz
Parse Server stores password in plain text
Ecosystems: npm
Packages: parse-server
Source: github
Published: almost 4 years ago
Moderate
grav: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWN2bXItNjQyOC04N3c5
Cross-Site Scripting in Grav
Ecosystems: packagist
Packages: getgrav/grav
Source: github
Published: about 4 years ago
Moderate
groovy: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJjamotaDZnaC1qZjNy
Information Disclosure in Apache Groovy
Ecosystems: maven
Packages: org.codehaus.groovy:groovy-all, org.codehaus.groovy:groovy
Source: github
Published: about 4 years ago
Moderate
highlight.js: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTd3d3Ytdmgzdi04OWNx
ReDOS vulnerabities: multiple grammars
Ecosystems: npm
Packages: @highlightjs/cdn-assets, highlight.js
Source: github
Published: about 4 years ago
Moderate
highlight.js: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZmcmMtN3I3Yy13OW14
Prototype Pollution in highlight.js
Ecosystems: npm
Packages: highlight.js
Source: github
Published: about 4 years ago
Low
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXI4OXYtY2d2Ny0zamh4
Bypass of fix for CVE-2020-15247, Twig sandbox escape
Ecosystems: packagist
Packages: october/cms
Source: github
Published: about 4 years ago
Moderate
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTk0dnAtcm1xdi01ODc1
Twig Sandbox Escape by authenticated users with access to editing CMS templates when safemode is enabled.
Ecosystems: packagist
Packages: october/cms
Source: github
Published: about 4 years ago
High
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXh3anItNmZqNy1mYzZo
Local File Inclusion by unauthenticated users
Ecosystems: packagist
Packages: october/cms
Source: github
Published: about 4 years ago
Low
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZ4M3YtNTUzeC0zYzRx
Stored XSS by authenticated backend user with access to upload files
Ecosystems: packagist
Packages: october/backend
Source: github
Published: about 4 years ago
Low
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJmamMteHJtZi01dnZ3
Privilege escalation by backend users assigned to the default "Publisher" system role
Ecosystems: packagist
Packages: october/backend
Source: github
Published: about 4 years ago
High
semantic-release: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXIyajYtcDY3aC1xNjM5
Secret disclosure when containing characters that become URI encoded
Ecosystems: npm
Packages: semantic-release
Source: github
Published: about 4 years ago
High
magento-lts: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpyZ2YtdmZ3Mi1oajI2
RCE via PHP Object injection via SOAP Requests
Ecosystems: packagist
Packages: openmage/magento-lts
Source: github
Published: about 4 years ago
Moderate
strapi: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXF2cDUtbW03di00ZjM2
Cross-site Scripting in Strapi
Ecosystems: npm
Packages: strapi-plugin-content-manager
Source: github
Published: about 4 years ago
High
strapi: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTRwNTUteGozNy1meDdn
Improper Authorization in Strapi
Ecosystems: npm
Packages: strapi-plugin-content-type-builder
Source: github
Published: about 4 years ago
Moderate
parse-server: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTJ4bTIteGoycS1xZ3Bq
receiving subscription objects with deleted session
Ecosystems: npm
Packages: parse-server
Source: github
Published: about 4 years ago
High
platform: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTU4OXctaGNjbS0yNjV4
Inline attribute values were not processed.
Ecosystems: packagist
Packages: orchid/platform
Source: github
Published: about 4 years ago
Low
electron: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTU2cGMtNmpxcC14cWo4
Context isolation bypass in Electron
Ecosystems: npm
Packages: electron
Source: github
Published: about 4 years ago
High
electron: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTJxNGctdzQ3Yy00Njc0
Unpreventable top-level navigation
Ecosystems: npm
Packages: electron
Source: github
Published: about 4 years ago
Moderate
shrine: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVqanYteDRmcS1xandw
Possible timing attack in derivation_endpoint
Ecosystems: rubygems
Packages: shrine
Source: github
Published: about 4 years ago
High
yii2: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTY5OXEtd2NmZi1nOW1q
Unsafe deserialization in Yii 2
Ecosystems: packagist
Packages: yiisoft/yii2
Source: github
Published: over 4 years ago
Moderate
node-sass: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTl2NjItMjRjci01OGN4
Denial of Service in node-sass
Ecosystems: npm
Packages: node-sass
Source: github
Published: over 4 years ago
Low
node-fetch: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXc3cmMtcnd2Zi04cTVy
The `size` option isn't honored after following a redirect in node-fetch
Ecosystems: npm
Packages: node-fetch
Source: github
Published: over 4 years ago
Moderate
boom: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTJnZ3EtdmZjcC1nd2hq
Cross-Site Scripting in @hapi/boom
Ecosystems: npm
Packages: @hapi/boom
Source: github
Published: over 4 years ago
Low
type-graphql: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhmNjQtMmY5cC02cHFx
Information Exposure in type-graphql
Ecosystems: npm
Packages: type-graphql
Source: github
Published: over 4 years ago
Critical
babel-loader: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFwNm0tanFmci0yZjd2
Malicious Package in babel-laoder
Ecosystems: npm
Packages: babel-laoder
Source: github
Published: over 4 years ago
High
subtext: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTJtdnEteHA0OC00Yzc3
Denial of Service in subtext
Ecosystems: npm
Packages: subtext
Source: github
Published: over 4 years ago
High
subtext: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZ2d3ItaDl4aC1tNndj
Denial of Service in @commercial/subtext
Ecosystems: npm
Packages: @commercial/subtext
Source: github
Published: over 4 years ago
High
subtext: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTRyZ2otOG1xMy1oZ2dq
Denial of Service in @hapi/subtext
Ecosystems: npm
Packages: @hapi/subtext
Source: github
Published: over 4 years ago
Moderate
sequelize: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZ3NHAtMzZqOS1ycmoz
Denial of Service in sequelize
Ecosystems: npm
Packages: sequelize
Source: github
Published: over 4 years ago
High
ngx-md: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlyN2gtNjYzOS12NW13
Cross-Site Scripting in bootstrap-select
Ecosystems: npm
Packages: bootstrap-select
Source: github
Published: over 4 years ago
High
ngx-md: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhyNTMtbTkzNy1qcjlj
Cross-Site Scripting in ngx-md
Ecosystems: npm
Packages: ngx-md
Source: github
Published: over 4 years ago
High
bootstrap-vue: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWM3cHAteDczaC00bTJ2
Cross-Site Scripting in bootstrap-vue
Ecosystems: npm
Packages: bootstrap-vue
Source: github
Published: over 4 years ago
Critical
windows-cpu: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTYzbTQtZmhmMi1jbWY3
Command Execution in windows-cpu
Ecosystems: npm
Packages: windows-cpu
Source: github
Published: over 4 years ago
Critical
sequelize: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTV2OWgtcTNnai1jMzJ4
SQL Injection via GeoJSON in sequelize
Ecosystems: npm
Packages: sequelize
Source: github
Published: over 4 years ago
Moderate
hapi: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWozZzItbTVqai02MzM2
Unsafe Merging of CORS Configuration Conflict in hapi
Ecosystems: npm
Packages: hapi
Source: github
Published: over 4 years ago
Moderate
inert: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc0eHAtMzZjMy1mN21y
Hidden Directories Always Served in inert
Ecosystems: npm
Packages: inert
Source: github
Published: over 4 years ago
High
magento-lts: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNyZjIteG02eC00NnA2
Observable Timing Discrepancy in OpenMage LTS
Ecosystems: packagist
Packages: openmage/magento-lts
Source: github
Published: over 4 years ago
Moderate
playframework: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNmOGotNjRoOS02cTU4
CSRF in Play Framework
Ecosystems: maven
Packages: com.typesafe.play:play_2.12
Source: github
Published: over 4 years ago
Moderate
fastify: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXh3NXAtaHc2ci0yajk4
Denial of service in fastify
Ecosystems: npm
Packages: fastify
Source: github
Published: over 4 years ago
Moderate
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTU1bW0tNTM5OS03cjYz
Reliance on Cookies without validation in OctoberCMS
Ecosystems: packagist
Packages: october/rain
Source: github
Published: over 4 years ago
Low
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXc0cGotN3A2OC0zdmd2
Stored XSS in October
Ecosystems: packagist
Packages: october/backend
Source: github
Published: over 4 years ago
Moderate
solidus: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTNtdmctcnJydy1tN3Bo
Ability to change order address without triggering address validations in solidus
Ecosystems: rubygems
Packages: solidus_api, solidus_frontend
Source: github
Published: over 4 years ago
High
dot-prop: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZmN3gtcXJnNy1xZ2dt
dot-prop Prototype Pollution vulnerability
Ecosystems: npm
Packages: dot-prop
Source: github
Published: over 4 years ago
Moderate
Parse-SDK-JS: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXd2aDctNXAzOC0ycWZj
Storing Password in Local Storage
Ecosystems: npm
Packages: parse
Source: github
Published: over 4 years ago
Moderate
parse-server: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTIzNmgtcnF2OC04cTcz
GraphQL: Security breach on Viewer query
Ecosystems: npm
Packages: parse-server
Source: github
Published: over 4 years ago
High
wagtail: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTI0NzMtOWhncS1qN3h3
Cross-Site Scripting in Wagtail
Ecosystems: pypi
Packages: wagtail
Source: github
Published: over 4 years ago
Moderate
electron: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWY5bXEtanBoNi05bWht
Arbitrary file read via window-open IPC in Electron
Ecosystems: npm
Packages: electron
Source: github
Published: over 4 years ago
High
electron: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg5amMtMjg0aC01MzNn
Context isolation bypass via contextBridge in Electron
Ecosystems: npm
Packages: electron
Source: github
Published: over 4 years ago
High
electron: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW05M3YtOXFqYy0zZzc5
Context isolation bypass via leaked cross-context objects in Electron
Ecosystems: npm
Packages: electron
Source: github
Published: over 4 years ago
Low
electron: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZ2cnYtOTRqdi1jcnJn
Context isolation bypass via Promise in Electron
Ecosystems: npm
Packages: electron
Source: github
Published: over 4 years ago
Low
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTNwYzItZm03cC1xMnZn
Cross-site Scripting in October
Ecosystems: packagist
Packages: october/backend
Source: github
Published: over 4 years ago
Critical
jhipster-kotlin: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWozcmgtOHZ3cS13aDg0
JHipster Kotlin using insecure source of randomness `RandomStringUtils` before v1.2.0
Ecosystems: npm
Packages: generator-jhipster-kotlin
Source: github
Published: over 4 years ago
Moderate
jhipster-kotlin: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXBmeGYtd2g5Ni1mdmpj
Log Forging in generator-jhipster-kotlin
Ecosystems: npm
Packages: generator-jhipster-kotlin
Source: github
Published: over 4 years ago
High
ssb-db: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1wZ3ItMmN4OS0zMjdo
Information disclosure in SSB-DB
Ecosystems: npm
Packages: ssb-db
Source: github
Published: over 4 years ago
Moderate
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXY3M3ctcjl4Zy03Y3I5
Use of insecure jQuery version in OctoberCMS
Ecosystems: packagist
Packages: october/system, october/october
Source: github
Published: over 4 years ago
Moderate
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTRyaG0tbTJmcC1oeDdx
Potential CSV Injection vector in OctoberCMS
Ecosystems: packagist
Packages: october/backend
Source: github
Published: over 4 years ago
Moderate
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWdnNngteHg3OC00NDhj
Reflected XSS when importing CSV in OctoberCMS
Ecosystems: packagist
Packages: october/backend
Source: github
Published: over 4 years ago
Low
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTk3MjItcnI2OC1yZnBn
Upload whitelisted files to any directory in OctoberCMS
Ecosystems: packagist
Packages: october/cms
Source: github
Published: over 4 years ago
Moderate
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWp2NnYtZnZ2eC00OTMy
Arbitrary File Deletion vulnerability in OctoberCMS
Ecosystems: packagist
Packages: october/cms
Source: github
Published: over 4 years ago
Moderate
october: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXIyM2YtYzJqNS1yeDJm
Local File read vulnerability in OctoberCMS
Ecosystems: packagist
Packages: october/cms
Source: github
Published: over 4 years ago
Moderate
dolibarr: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWN4dnItcjkybS1xOWh3
XSS in Dolibarr
Ecosystems: packagist
Packages: dolibarr/dolibarr
Source: github
Published: over 4 years ago
High
doorkeeper: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo3dngtOG1xai1jcXA5
Exposure of Sensitive Information to an Unauthorized Actor in Doorkeeper
Ecosystems: rubygems
Packages: doorkeeper
Source: github
Published: over 4 years ago
Moderate
wagtail: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpqanItM2pjdy1mOHY2
Potential Observable Timing Discrepancy in Wagtail
Ecosystems: pypi
Packages: wagtail
Source: github
Published: over 4 years ago
Moderate
wagtail: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXYyd2MtcGZxMi01Y202
Possible XSS attack in Wagtail
Ecosystems: pypi
Packages: wagtail
Source: github
Published: over 4 years ago
High
bleach: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZxaHAtY3hnYy02d21t
regular expression denial-of-service (ReDoS) in Bleach
Ecosystems: pypi
Packages: bleach
Source: github
Published: over 4 years ago
Moderate
bleach: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW02eGYtZnE3cS04NzQz
Bleach vulnerable to mutation XSS via whitelisted math or svg and raw tag
Ecosystems: pypi
Packages: bleach
Source: github
Published: over 4 years ago
High
psutil: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFmYzUtbWN3cS0yNnE4
Double Free in psutil
Ecosystems: pypi
Packages: psutil
Source: github
Published: almost 5 years ago
High
uap-ruby: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXBjcXEtNTk2Mi1odmN3
Denial of Service in uap-core when processing crafted User-Agent strings
Ecosystems: rubygems
Packages: user_agent_parser
Source: github
Published: almost 5 years ago
High
parse-server: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg0bWYtNzVoZi02N3c0
Information disclosure in parse-server
Ecosystems: npm
Packages: parse-server
Source: github
Published: almost 5 years ago
Moderate
bleach: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE2NW0tcHYzZi13cjVy
XSS in Bleach when noscript and raw tag whitelisted
Ecosystems: pypi
Packages: bleach
Source: github
Published: almost 5 years ago