Ecosyste.ms: OpenCollective

An open API service for software projects hosted on Open Collective.

Moderate
dcat-admin: GSA_kwCzR0hTQS1tcjI0LWNmNjktNWNocc4AA6SW
dcat-admin Cross Site Scripting vulnerability
Ecosystems: packagist
Packages: dcat/laravel-admin
Source: github
Published: 9 months ago
Moderate
express: GSA_kwCzR0hTQS1ydjk1LTg5NmgtYzJ2Y84AA6Rd
Express.js Open Redirect in malformed URLs
Ecosystems: npm
Packages: express
Source: github
Published: 9 months ago
Moderate
KaTeX: GSA_kwCzR0hTQS0zd2M1LWZjdzItMjMyOc4AA6Rb
KaTeX missing normalization of the protocol in URLs allows bypassing forbidden protocols
Ecosystems: npm
Packages: katex
Source: github
Published: 9 months ago
Moderate
KaTeX: GSA_kwCzR0hTQS1mOTh3LTdjeHItZmYyaM4AA6Ra
KaTeX's `\includegraphics` does not escape filename
Ecosystems: npm
Packages: katex
Source: github
Published: 9 months ago
Moderate
KaTeX: GSA_kwCzR0hTQS1jdnI2LTM3Z3gtdjh3Y84AA6RZ
KaTeX's maxExpand bypassed by Unicode sub/superscripts
Ecosystems: npm
Packages: katex
Source: github
Published: 9 months ago
Moderate
KaTeX: GSA_kwCzR0hTQS02NGZtLThodzItdjcyd84AA6RY
KaTeX's maxExpand bypassed by `\edef`
Ecosystems: npm
Packages: katex
Source: github
Published: 9 months ago
High
grav: GSA_kwCzR0hTQS0ybTd4LWM3cHgtaHA1OM4AA6Oy
Server Side Template Injection (SSTI) via Twig escape handler
Ecosystems: packagist
Packages: getgrav/grav
Source: github
Published: 9 months ago
High
grav: GSA_kwCzR0hTQS1yNnZ3LTh2OHItcG1wNM4AA6Ox
Server Side Template Injection (SSTI)
Ecosystems: packagist
Packages: getgrav/grav
Source: github
Published: 9 months ago
High
grav: GSA_kwCzR0hTQS1xZnY0LXE0NHItZzdyds4AA6Ow
Server Side Template Injection (SSTI)
Ecosystems: packagist
Packages: getgrav/grav
Source: github
Published: 9 months ago
High
grav: GSA_kwCzR0hTQS1jOWdwLTY0YzQtMnJyaM4AA6Ov
Server-Side Template Injection (SSTI) with Grav CMS security sandbox bypass
Ecosystems: packagist
Packages: getgrav/grav
Source: github
Published: 9 months ago
High
grav: GSA_kwCzR0hTQS1tN2h4LWh3NmgtbXFtY84AA6Ou
Grav File Upload Path Traversal
Ecosystems: packagist
Packages: getgrav/grav
Source: github
Published: 9 months ago
Moderate
VvvebJs: GSA_kwCzR0hTQS1wbW0zLTY4cTktNTdqZ84AA6OK
VvvebJs Arbitrary File Upload vulnerability
Ecosystems: npm
Packages: vvvebJs
Source: github
Published: 9 months ago
Moderate
VvvebJs: GSA_kwCzR0hTQS1wYzk1LTN3Z20teDI4cM4AA6OJ
VvvebJs Reflected Cross-Site Scripting (XSS) vulnerability
Ecosystems: npm
Packages: vvvebjs
Source: github
Published: 9 months ago
High
webpack-dev-middleware: GSA_kwCzR0hTQS13cjNqLXB3ajktaHFxNs4AA6Nc
Path traversal in webpack-dev-middleware
Ecosystems: npm
Packages: webpack-dev-middleware
Source: github
Published: 9 months ago
Critical
parse-server: GSA_kwCzR0hTQS02aGg3LTQ2cjItdmYyOc4AA6JD
Server crashes on invalid Cloud Function or Cloud Job name
Ecosystems: npm
Packages: parse-server
Source: github
Published: 9 months ago
High
astropy: GSA_kwCzR0hTQS1oMng2LTVqeDUtNDZoZs4AA6Gg
RCE in TranformGraph().to_dot_graph function
Ecosystems: pypi
Packages: astropy
Source: github
Published: 9 months ago
High
raspap-webgui: GSA_kwCzR0hTQS12YzlmLW1neHItaDMycs4AA53D
raspap-webgui vulnerable to denial of service
Ecosystems: packagist
Packages: billz/raspap-webgui
Source: github
Published: 10 months ago
Moderate
RSSHub: GSA_kwCzR0hTQS0zcDNwLWNnajctdmd3M84AA5zO
RSSHub vulnerable to Server-Side Request Forgery
Ecosystems: npm
Packages: rsshub
Source: github
Published: 10 months ago
Moderate
RSSHub: GSA_kwCzR0hTQS0yd3F3LWhyNGYteHJoaM4AA5zN
RSSHub Cross-site Scripting vulnerability caused by internal media proxy
Ecosystems: npm
Packages: rsshub
Source: github
Published: 10 months ago
Critical
grav: GSA_kwCzR0hTQS1mNmcyLWg3cXYtM201ds4AA5zK
Remote Code Execution by uploading a phar file using frontmatter
Ecosystems: packagist
Packages: getgrav/grav
Source: github
Published: 10 months ago
High
ImageSharp: GSA_kwCzR0hTQS02NXg3LWMyNzItN2c3cs4AA5xd
Use After Free in SixLabors.ImageSharp
Ecosystems: nuget
Packages: SixLabors.ImageSharp
Source: github
Published: 10 months ago
High
mio: GSA_kwCzR0hTQS1yOHc5LTV3Y2ctdmZqN84AA5wE
Mio's tokens for named pipes may be delivered after deregistration
Ecosystems: cargo
Packages: mio
Source: github
Published: 10 months ago
High
phpseclib: GSA_kwCzR0hTQS1qcjIyLThxZ20tNHE4N84AA5s3
phpseclib does not properly limit the ASN1 OID length
Ecosystems: packagist
Packages: phpseclib/phpseclib
Source: github
Published: 10 months ago
High
phpseclib: GSA_kwCzR0hTQS1oZzM1LW1wMjUtcWY2aM4AA5sw
phpseclib a large prime can cause a denial of service
Ecosystems: packagist
Packages: phpseclib/phpseclib
Source: github
Published: 10 months ago
Critical
parse-server: GSA_kwCzR0hTQS02OTI3LTN2cjktZnhmMs4AA5sK
ZDI-CAN-19105: Parse Server literalizeRegexPart SQL Injection
Ecosystems: npm
Packages: parse-server
Source: github
Published: 10 months ago
Moderate
bagisto: GSA_kwCzR0hTQS13NW14LTMzNGotNmZ3ds4AA5r1
Bagist Cross-site Scripting vulnerability
Ecosystems: packagist
Packages: bagisto/bagisto
Source: github
Published: 10 months ago
Moderate
livehelperchat: GSA_kwCzR0hTQS12NGNwLTJxN3YtaGc5cc4AA5pT
livehelperchat Server-Side Template Injection
Ecosystems: packagist
Packages: remdex/livehelperchat
Source: github
Published: 10 months ago
Moderate
magento-lts: GSA_kwCzR0hTQS1ncDZtLWZxNmgtY2pjeM4AA5jQ
Magento LTS vulnerable to stored XSS in admin file form
Ecosystems: packagist
Packages: openmage/magento-lts
Source: github
Published: 10 months ago
Moderate
subrion: GSA_kwCzR0hTQS14eGY4LWZwbXItZnc3ds4AA5ib
Withdrawn Advisory: Subrion CMS vulnerable to SQL Injection
Ecosystems: packagist
Packages: intelliants/subrion
Source: github
Published: 10 months ago
Critical
fiber: GSA_kwCzR0hTQS1mbWc0LXg4cHctaGpoZ84AA5dK
Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials
Ecosystems: go
Packages: github.com/gofiber/fiber/v2
Source: github
Published: 10 months ago
Moderate
decidim: GSA_kwCzR0hTQS05dzk5LTc4cmotaG14cc4AA5Zn
Cross-site scripting (XSS) in the dynamic file uploads
Ecosystems: rubygems
Packages: decidim-core, decidim
Source: github
Published: 10 months ago
Moderate
decidim: GSA_kwCzR0hTQS13M3E4LW00OTItNHB3cM4AA5Zd
Possibility to circumvent the invitation token expiry period
Ecosystems: rubygems
Packages: decidim-system, decidim-admin, decidim, devise_invitable
Source: github
Published: 10 months ago
Moderate
decidim: GSA_kwCzR0hTQS1mM3FtLXZmYzMtamc2ds4AA5ZJ
Possible CSRF attack at questionnaire templates preview
Ecosystems: rubygems
Packages: decidim-templates
Source: github
Published: 10 months ago
Low
decidim: GSA_kwCzR0hTQS1yMjc1LWo1N2MtN21mMs4AA5ZI
Race condition in Endorsements
Ecosystems: rubygems
Packages: decidim
Source: github
Published: 10 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS1yOTY5LTc4M2YtNmpxcs4AA5Wp
Improper Neutralization of HTTP Headers in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 10 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS12ZnBoLWhqZnYtY3B2Ms4AA5Wx
Improper Restriction of Excessive Authentication Attempts in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 10 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS05M3g4LTY2ajItd3dyNc4AA5Wo
Server-Side Request Forgery in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 10 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS04aHAzLXJtcjcteGg4OM4AA5Wv
Open Redirect in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 10 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS12ajM2LTNjY3ItNjU2M84AA5Wr
Authentication Bypass by Spoofing in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 10 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS1jN3ZmLW0zOTQtbTR4NM4AA5Wn
Use of Insufficiently Random Values in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 10 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS1mZjcyLWZmNDItYzNnd84AA5Wm
Cross-site Scripting in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 10 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS12cDY2LWdmN3ctOW00eM4AA5Wu
Insufficient Session Expiration in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 10 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS04aDk1LWpjcDUtcGpwcs4AA5Wt
Improper Validation of Array Index in github.com/greenpau/caddy-security
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 10 months ago
Low
undici: GSA_kwCzR0hTQS0zNzg3LTZwcnYtaDl3M84AA5Vg
Undici proxy-authorization header not cleared on cross-origin redirect in fetch
Ecosystems: npm
Packages: undici
Source: github
Published: 10 months ago
Moderate
undici: GSA_kwCzR0hTQS05ZjI0LWpxaG0tamZjd84AA5Vf
fetch(url) leads to a memory leak in undici
Ecosystems: npm
Packages: undici
Source: github
Published: 10 months ago
Moderate
caddy-security: GSA_kwCzR0hTQS14d212LWN4N3AtZnFmY84AA5Oo
caddy-security plugin for Caddy vulnerable to reflected Cross-site Scripting
Ecosystems: go
Packages: github.com/greenpau/caddy-security
Source: github
Published: 10 months ago
Critical
pixelfed: GSA_kwCzR0hTQS1nY2NxLWgzeGotamd2Zs4AA5N1
Pixelfed doesn't check OAuth Scopes in API routes, giving elevated permissions
Ecosystems: packagist
Packages: pixelfed/pixelfed
Source: github
Published: 10 months ago
Moderate
Ghost: GSA_kwCzR0hTQS05OXZjLXh3OGotcGhqbc4AA5M7
Ghost has possible Cross-site Scripting issue
Ecosystems: npm
Packages: ghost
Source: github
Published: 10 months ago
Moderate
nonebot2: GSA_kwCzR0hTQS01OWo4LTc3NnYteHh4Z84AA5Lo
NoneBot Potential Information Leak in User-Constructed Message Templates
Ecosystems: pypi
Packages: nonebot2
Source: github
Published: 11 months ago
High
yarn: GSA_kwCzR0hTQS1tcHdqLWZjcjYteDM0Y84AA5DS
Yarn untrusted search path vulnerability
Ecosystems: npm
Packages: yarn
Source: github
Published: 11 months ago
Moderate
pulse-binding-rust: GSA_kwCzR0hTQS1mNTZnLWNocXAtMjJtOc4AA5Ct
Use after free in libpulse-binding
Ecosystems: cargo
Packages: libpulse-binding
Source: github
Published: 11 months ago
Moderate
lobe-chat: GSA_kwCzR0hTQS1wZjU1LWZqOTYteGYzN84AA499
@lobehub/chat vulnerable to unauthorized access to plugins
Ecosystems: npm
Packages: @lobehub/chat
Source: github
Published: 11 months ago
Moderate
goreleaser: GSA_kwCzR0hTQS1oM3EyLTh3aHgtYzI5aM4AA485
`goreleaser release --debug` shows secrets
Ecosystems: go
Packages: github.com/goreleaser/goreleaser
Source: github
Published: 11 months ago
High
urql: GSA_kwCzR0hTQS1xaGpmLWhtNWotMzM1d84AA483
@urql/next Cross-site Scripting vulnerability
Ecosystems: npm
Packages: @urql/next
Source: github
Published: 11 months ago
High
lemmy: GSA_kwCzR0hTQS1yNjRyLTVoNDMtMjZxds4AA42n
Any authenticated user may obtain private message details from other users on the same instance
Ecosystems: cargo
Packages: lemmy_server
Source: github
Published: 11 months ago
High
kit: GSA_kwCzR0hTQS1nNW02LWh4cHAtZmM0Oc4AA4qX
Sending a GET or HEAD request with a body crashes SvelteKit
Ecosystems: npm
Packages: @sveltejs/adapter-node, @sveltejs/kit
Source: github
Published: 11 months ago
Moderate
Ghost: GSA_kwCzR0hTQS1maDM4LTlmZ3ItNDU0d84AA4mG
Cross-site Scripting in Ghost
Ecosystems: npm
Packages: ghost
Source: github
Published: 11 months ago
High
vite: GSA_kwCzR0hTQS1jMjR2LThyZmMtdzh2d84AA4lu
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
Ecosystems: npm
Packages: vite
Source: github
Published: 11 months ago
Moderate
tracing: GSA_kwCzR0hTQS04ZjI0LTZtMjktd20ycs4AA4ih
use-after-free in tracing
Ecosystems: cargo
Packages: tracing
Source: github
Published: 11 months ago
Moderate
bagisto: GSA_kwCzR0hTQS1jOTYyLWc1MzMtODIzZs4AA4gW
Cross-site Scripting in Bagisto
Ecosystems: packagist
Packages: bagisto/bagisto
Source: github
Published: 11 months ago
High
evershop: GSA_kwCzR0hTQS1nZ3BtLTlxZngtbWh3Z84AA4bk
EverShop vulnerable to improper authorization in GraphQL endpoints
Ecosystems: npm
Packages: @evershop/evershop
Source: github
Published: 11 months ago
Critical
evershop: GSA_kwCzR0hTQS0zMnIzLTU3aHAtY2dmd84AA4bm
EverShop at risk to unauthorized access via weak HMAC secret
Ecosystems: npm
Packages: @evershop/evershop
Source: github
Published: 11 months ago
High
fonttools: GSA_kwCzR0hTQS02NjczLTQ5ODMtMnZ4Nc4AA4Sn
fonttools XML External Entity Injection (XXE) Vulnerability
Ecosystems: pypi
Packages: fonttools
Source: github
Published: 12 months ago
Low
framework: GSA_kwCzR0hTQS03MzNyLTh4Y3Atdzltcs4AA4N5
Flarum's logout Route allows open redirects
Ecosystems: packagist
Packages: flarum/framework, flarum/core
Source: github
Published: 12 months ago
High
verify-changed-files: GSA_kwCzR0hTQS1naG0yLXJxOHEtd3JoY84AA4Jn
Potential Actions command injection in output filenames (GHSL-2023-275)
Ecosystems: actions
Packages: tj-actions/verify-changed-files
Source: github
Published: 12 months ago
High
changed-files: GSA_kwCzR0hTQS1tY3BoLW0yNWotOGo2M84AA4Jm
tj-actions/changed-files has Potential Actions command injection in output filenames (GHSL-2023-271)
Ecosystems: actions
Packages: tj-actions/changed-files
Source: github
Published: 12 months ago
Low
winter: GSA_kwCzR0hTQS0yeDdyLTkzd3ctY3hycc4AA4Je
Winter CMS Local File Inclusion through Server Side Template Injection
Ecosystems: packagist
Packages: winter/wn-backend-module
Source: github
Published: 12 months ago
Low
winter: GSA_kwCzR0hTQS00M3c0LTRqM2MtangyOc4AA4EN
Winter CMS Stored XSS through Backend ColorPicker FormWidget
Ecosystems: packagist
Packages: winter/wn-backend-module
Source: github
Published: 12 months ago
Low
winter: GSA_kwCzR0hTQS00d3Z3LTc1cWgtZnFqcM4AA4EM
Winter CMS Stored XSS through privileged upload of Media Manager file followed by renaming
Ecosystems: packagist
Packages: winter/wn-system-module
Source: github
Published: 12 months ago
Moderate
activeadmin: GSA_kwCzR0hTQS14aHZ2LTNqd3ctYzQ4N84AA4D6
ActiveAdmin CSV Injection leading to sensitive information disclosure
Ecosystems: rubygems
Packages: activeadmin
Source: github
Published: 12 months ago
High
activeadmin: GSA_kwCzR0hTQS1ycXhjLTlwOGgteHFncc4AA4Ap
Duplicate Advisory: ActiveAdmin vulnerable to CSV injection
Ecosystems: rubygems
Packages: activeadmin
Source: github
Published: 12 months ago
Moderate
grails-core: GSA_kwCzR0hTQS0zcGp2LXI3dzQtMmNmNc4AA38i
Grails data binding causes JVM crash and/or other denial of service
Ecosystems: maven
Packages: org.grails:grails-databinding
Source: github
Published: about 1 year ago
High
grackle: GSA_kwCzR0hTQS1nNTZ4LTdqNnctZzhyOM4AA34j
Grackle has StackOverflowError in GraphQL query processing
Ecosystems: maven
Packages: edu.gemini:gsp-graphql-core_native0.4_3, edu.gemini:gsp-graphql-core_native0.4_2.13, edu.gemini:gsp-graphql-core_sjs1_3, edu.gemini:gsp-graphql-core_sjs1_2.13, edu.gemini:gsp-graphql-core_3, edu.gemini:gsp-graphql-core_2.13, org.typelevel:grackle-core_native0.4_3, org.typelevel:grackle-core_native0.4_2.13, org.typelevel:grackle-core_sjs1_3, org.typelevel:grackle-core_sjs1_2.13, org.typelevel:grackle-core_3, org.typelevel:grackle-core_2.13
Source: github
Published: about 1 year ago
Low
yii2-authclient: GSA_kwCzR0hTQS13OHZoLXA3NGoteDl4cM4AA34Q
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
Ecosystems: packagist
Packages: yiisoft/yii2-authclient
Source: github
Published: about 1 year ago
Moderate
yii2-authclient: GSA_kwCzR0hTQS1ydzU0LTY4MjYtYzhqNc4AA34O
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
Ecosystems: packagist
Packages: yiisoft/yii2-authclient
Source: github
Published: about 1 year ago
High
activeadmin: GSA_kwCzR0hTQS0zNTZqLWhnNDUteDUyNc4AA323
Potential CSV export data leak
Ecosystems: rubygems
Packages: activeadmin
Source: github
Published: about 1 year ago
Moderate
microweber: GSA_kwCzR0hTQS1xamZ4LWZ2eDctM3d2d84AA3yi
Business Logic Errors in microweber/microweber
Ecosystems: packagist
Packages: microweber/microweber
Source: github
Published: about 1 year ago
Moderate
uptime-kuma: GSA_kwCzR0hTQS04OGo0LXBjeDgtcTRxM84AA3q_
Password Change Vulnerability
Ecosystems: npm
Packages: uptime-kuma
Source: github
Published: about 1 year ago
High
cors: GSA_kwCzR0hTQS1xeHJqLWh4MjMteHA4Ms4AA3qz
Overly permissive origin policy
Ecosystems: npm
Packages: @koa/cors
Source: github
Published: about 1 year ago
Moderate
SemanticMediaWiki: GSA_kwCzR0hTQS1oajRjLXZmYzQtNWY5Y84AA3qO
Cross-site Scripting in Semantic MediaWiki
Ecosystems: packagist
Packages: mediawiki/semantic-media-wiki
Source: github
Published: about 1 year ago
Critical
evershop: GSA_kwCzR0hTQS01bW1yLTlxeDMtM3BmOc4AA3pb
Code execution in evershop
Ecosystems: npm
Packages: @evershop/evershop
Source: github
Published: about 1 year ago
Moderate
evershop: GSA_kwCzR0hTQS00d3JtLXFtcTItNWZqeM4AA3pc
Directory Traversal in evershop
Ecosystems: npm
Packages: @evershop/evershop
Source: github
Published: about 1 year ago
Moderate
evershop: GSA_kwCzR0hTQS03NDQzLTU5NjItd3A0cs4AA3pf
Directory Traversal in evershop
Ecosystems: npm
Packages: @evershop/evershop
Source: github
Published: about 1 year ago
Moderate
evershop: GSA_kwCzR0hTQS0yeGNqLTU1N2MtaGY4cs4AA3pd
Cross-site Scripting in evershop
Ecosystems: npm
Packages: @evershop/evershop
Source: github
Published: about 1 year ago
High
evershop: GSA_kwCzR0hTQS1yd2YzLXc0anEtZjRjbc4AA3pe
Directory Traversal in evershop
Ecosystems: npm
Packages: @evershop/evershop
Source: github
Published: about 1 year ago
Moderate
evershop: GSA_kwCzR0hTQS1namo4LW04M2MtcXY5aM4AA3pY
Cross-site Scripting in evershop
Ecosystems: npm
Packages: @evershop/evershop
Source: github
Published: about 1 year ago
Moderate
evershop: GSA_kwCzR0hTQS1tNnZtLWZmOXYtanAzcs4AA3pZ
Cross Site Scripting in evershop
Ecosystems: npm
Packages: @evershop/evershop
Source: github
Published: about 1 year ago
Low
dbt-core: GSA_kwCzR0hTQS1qNGczLTNxOHgtanhxcM4AA3ow
dbt-core's secret env vars written to package-lock.json in plaintext
Ecosystems: pypi
Packages: dbt-core
Source: github
Published: about 1 year ago
High
magento-lts: GSA_kwCzR0hTQS05ajV3LTJjcWMtY3dqOc4AA3oh
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
Ecosystems: packagist
Packages: openmage/magento-lts
Source: github
Published: about 1 year ago
High
microweber: GSA_kwCzR0hTQS1wOHE2LXFyZ2otN2d4Ms4AA3oa
Microweber allows a remote attacker to obtain sensitive information via the HTTP GET method
Ecosystems: packagist
Packages: microweber/microweber
Source: github
Published: about 1 year ago
Low
microweber: GSA_kwCzR0hTQS05cjZwLWhnNGctNWd4cM4AA3oU
Microweber missing standardized error handling mechanism
Ecosystems: packagist
Packages: microweber/microweber
Source: github
Published: about 1 year ago
Moderate
microweber: GSA_kwCzR0hTQS0zcnB4LXBnbWYtajk2aM4AA3mF
Microweber Business Logic Errors
Ecosystems: packagist
Packages: microweber/microweber
Source: github
Published: about 1 year ago
Moderate
vite: GSA_kwCzR0hTQS05MnIzLW0ybWctcGo5N84AA3lD
Vite XSS vulnerability in `server.transformIndexHtml` via URL payload
Ecosystems: npm
Packages: vite
Source: github
Published: about 1 year ago
Critical
branch-names: GSA_kwCzR0hTQS04djh3LXY4eGctNzlyZs4AA3lB
tj-actions/branch-names's Improper Sanitization of Branch Name Leads to Arbitrary Code Injection
Ecosystems: actions
Packages: tj-actions/branch-names
Source: github
Published: about 1 year ago
Moderate
electron: GSA_kwCzR0hTQS03bTQ4LXdjOTMtOWc4Nc4AA3e-
ASAR Integrity bypass via filetype confusion in electron
Ecosystems: npm
Packages: electron
Source: github
Published: about 1 year ago
Moderate
october: GSA_kwCzR0hTQS1ydng4LXAzeHAtZmozcM4AA3a4
October CMS stored XSS by authenticated backend user with improper configuration
Ecosystems: packagist
Packages: october/system
Source: github
Published: about 1 year ago
Critical
october: GSA_kwCzR0hTQS1wOHEzLWg2NTItNjV2eM4AA3a2
October CMS safe mode bypass using Twig sandbox escape
Ecosystems: packagist
Packages: october/system
Source: github
Published: about 1 year ago
Moderate
october: GSA_kwCzR0hTQS1xMjJqLTVyM2ctOWhtaM4AA3a1
October CMS safe mode bypass using Page template injection
Ecosystems: packagist
Packages: october/system
Source: github
Published: about 1 year ago
Moderate
RSA: GSA_kwCzR0hTQS1jMzh3LTc0cGctMzZocs4AA3Z_
Marvin Attack: potential key recovery through timing sidechannels
Ecosystems: cargo
Packages: rsa
Source: github
Published: about 1 year ago
Moderate
RSA: GSA_kwCzR0hTQS00Z3J4LTJ4OXctNTk2Y84AA3Z-
Marvin Attack: potential key recovery through timing sidechannels
Ecosystems: cargo
Packages: rsa
Source: github
Published: about 1 year ago