Ecosyste.ms: OpenCollective
An open API service for software projects hosted on Open Collective.
High
Ecosystems: packagist
Packages: phpseclib/phpseclib
Source: github
Published: about 1 year ago
phpseclib: GSA_kwCzR0hTQS1qcHI3LXE1MjMtaHgyNc4AA3X2
phpseclib vulnerable to denial of serviceEcosystems: packagist
Packages: phpseclib/phpseclib
Source: github
Published: about 1 year ago
Moderate
Ecosystems: npm
Packages: uptime-kuma
Source: github
Published: about 1 year ago
uptime-kuma: GSA_kwCzR0hTQS1oZnhoLXJqdjctMjM2Oc4AA3Xr
Uptime Kuma Authenticated remote code execution via TailscalePingEcosystems: npm
Packages: uptime-kuma
Source: github
Published: about 1 year ago
Moderate
Ecosystems: npm
Packages: uptime-kuma
Source: github
Published: about 1 year ago
uptime-kuma: GSA_kwCzR0hTQS12NHYyLThoODgtNjVxas4AA3W6
Attribute Injection leading to XSS(Cross-Site-Scripting)Ecosystems: npm
Packages: uptime-kuma
Source: github
Published: about 1 year ago
Moderate
Ecosystems: maven
Packages: org.bouncycastle:bcprov-jdk15on, org.bouncycastle:bcprov-jdk16, org.bouncycastle:bcprov-jdk15to18, org.bouncycastle:bcprov-jdk15, org.bouncycastle:bcprov-jdk14, org.bouncycastle:bcprov-ext-jdk16, org.bouncycastle:bcprov-ext-jdk15on, org.bouncycastle:bcpkix-jdk18on, org.bouncycastle:bcprov-jdk18on
Source: github
Published: about 1 year ago
bc-java: GSA_kwCzR0hTQS13anhqLTVtN2ctbWc3cc4AA3WZ
Bouncy Castle Denial of Service (DoS)Ecosystems: maven
Packages: org.bouncycastle:bcprov-jdk15on, org.bouncycastle:bcprov-jdk16, org.bouncycastle:bcprov-jdk15to18, org.bouncycastle:bcprov-jdk15, org.bouncycastle:bcprov-jdk14, org.bouncycastle:bcprov-ext-jdk16, org.bouncycastle:bcprov-ext-jdk15on, org.bouncycastle:bcpkix-jdk18on, org.bouncycastle:bcprov-jdk18on
Source: github
Published: about 1 year ago
Moderate
Ecosystems: npm
Packages: next-auth
Source: github
Published: about 1 year ago
next-auth: GSA_kwCzR0hTQS12NjR3LTQ5eHctcXE4Oc4AA3R1
Possible user mocking that bypasses basic authenticationEcosystems: npm
Packages: next-auth
Source: github
Published: about 1 year ago
Moderate
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 year ago
librenms: GSA_kwCzR0hTQS1mcHE1LTR2d20tNzh4NM4AA3P3
LibreNMS has Broken Access control on Graphs FeatureEcosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 year ago
Moderate
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 year ago
librenms: GSA_kwCzR0hTQS04cGhyLTYzN2ctcHhyZ84AA3P2
LibreNMS Cross-site Scripting at Device groups Deletion featureEcosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 year ago
Moderate
Ecosystems: npm
Packages: @vendure/core
Source: github
Published: about 1 year ago
vendure: GSA_kwCzR0hTQS13bTYzLTc2MjctY2gzM84AA3P1
@vendure/core's insecure currencyCode handling allows wrong payment amountsEcosystems: npm
Packages: @vendure/core
Source: github
Published: about 1 year ago
Moderate
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 year ago
librenms: GSA_kwCzR0hTQS1ycTQyLTU4cWYtdjNxeM4AA3Pz
LibreNMS vulnerable to rate limiting bypass on login pageEcosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 year ago
High
Ecosystems: packagist
Packages: yiisoft/yii
Source: github
Published: about 1 year ago
yii: GSA_kwCzR0hTQS1tdzJ3LTJoajItZmc4cc4AA3Kz
yiisoft/yii deserializing untrusted user input can lead to remote code executionEcosystems: packagist
Packages: yiisoft/yii
Source: github
Published: about 1 year ago
Moderate
Ecosystems: packagist
Packages: microweber/microweber
Source: github
Published: about 1 year ago
microweber: GSA_kwCzR0hTQS1xNTdnLTM4cGMtand2OM4AA3IQ
Microweber Improper Access Control vulnerabilityEcosystems: packagist
Packages: microweber/microweber
Source: github
Published: about 1 year ago
Moderate
Ecosystems: npm
Packages: axios
Source: github
Published: about 1 year ago
axios: GSA_kwCzR0hTQS13ZjVwLWc2dnctcmh4eM4AA2_y
Axios Cross-Site Request Forgery VulnerabilityEcosystems: npm
Packages: axios
Source: github
Published: about 1 year ago
Moderate
Ecosystems: packagist
Packages: microweber/microweber
Source: github
Published: about 1 year ago
microweber: GSA_kwCzR0hTQS1qbXdtLXcycm0tcHJ2Oc4AA2_o
Microweber Cross-site Scripting vulnerabilityEcosystems: packagist
Packages: microweber/microweber
Source: github
Published: about 1 year ago
High
Ecosystems: npm
Packages: @strapi/strapi, @strapi/plugin-users-permissions
Source: github
Published: about 1 year ago
strapi: GSA_kwCzR0hTQS1nYzdwLWo1eG0teHhoMs4AA26o
Unauthorized Access to Private Fields in User Registration APIEcosystems: npm
Packages: @strapi/strapi, @strapi/plugin-users-permissions
Source: github
Published: about 1 year ago
High
Ecosystems: packagist
Packages: intelliants/subrion
Source: github
Published: about 1 year ago
subrion: GSA_kwCzR0hTQS0yeDI4LWM3ajctMjNnds4AA26P
Subrion remote command execution vulnerabilityEcosystems: packagist
Packages: intelliants/subrion
Source: github
Published: about 1 year ago
Moderate
Ecosystems: packagist
Packages: phpbb/phpbb
Source: github
Published: about 1 year ago
phpbb: GSA_kwCzR0hTQS1nbXg4LThyZmYtcXY2cc4AA231
phpBB's Smiley Pack acp_icons.php main pack vulnerable to cross site scriptingEcosystems: packagist
Packages: phpbb/phpbb
Source: github
Published: about 1 year ago
High
Ecosystems: packagist
Packages: dolibarr/dolibarr
Source: github
Published: about 1 year ago
dolibarr: GSA_kwCzR0hTQS1yOWNtLXB3OWotM2ZweM4AA21l
Dolibarr Improper Input Validation vulnerabilityEcosystems: packagist
Packages: dolibarr/dolibarr
Source: github
Published: about 1 year ago
Moderate
Ecosystems: packagist
Packages: dolibarr/dolibarr
Source: github
Published: about 1 year ago
dolibarr: GSA_kwCzR0hTQS00OHYyLTU5NngtNGpyOc4AA21m
Dolibarr Improper Input Validation vulnerabilityEcosystems: packagist
Packages: dolibarr/dolibarr
Source: github
Published: about 1 year ago
Moderate
Ecosystems: pypi
Packages: pypdf
Source: github
Published: about 1 year ago
pypdf: GSA_kwCzR0hTQS13amNjLWNxNzktcDYzZs4AA21E
Possible Infinite Loop when PdfWriter(clone_from) is used with a PDFEcosystems: pypi
Packages: pypdf
Source: github
Published: about 1 year ago
High
Ecosystems: npm
Packages: generator-jhipster
Source: github
Published: about 1 year ago
generator-jhipster: GSA_kwCzR0hTQS00Z3BtLXIyM2gtZ3Byd84AA2zp
generator-jhipster allows a timing attack against validateToken due to a string comparison that stops at the first characterEcosystems: npm
Packages: generator-jhipster
Source: github
Published: about 1 year ago
Moderate
Ecosystems: packagist
Packages: microweber/microweber
Source: github
Published: about 1 year ago
microweber: GSA_kwCzR0hTQS03cTVmLTI5Z3gtNTdmZs4AA2zg
Cross-site Scripting (XSS) in microweber/microweberEcosystems: packagist
Packages: microweber/microweber
Source: github
Published: about 1 year ago
Moderate
Ecosystems: go
Packages: github.com/jumpserver/koko
Source: github
Published: about 1 year ago
jumpserver: GSA_kwCzR0hTQS00cjV4LXgyODMtd205Ns4AA2oW
Jumpserver Koko vulnerable to remote code execution on the host system via MongoDB shellEcosystems: go
Packages: github.com/jumpserver/koko
Source: github
Published: about 1 year ago
High
Ecosystems: npm
Packages: parse-server
Source: github
Published: about 1 year ago
parse-server: GSA_kwCzR0hTQS03OTJxLXE2N2gtdzU3Oc4AA2oK
Parse Server may crash when uploading file without extensionEcosystems: npm
Packages: parse-server
Source: github
Published: about 1 year ago
High
Ecosystems: pypi
Packages: pdm
Source: github
Published: about 1 year ago
pdm: GSA_kwCzR0hTQS1qNDR2LW1tZjIteHZtOc4AA2mh
PDM Trojan LockfileEcosystems: pypi
Packages: pdm
Source: github
Published: about 1 year ago
High
Ecosystems: cargo, npm
Packages: tauri-cli, @tauri-apps/cli
Source: github
Published: about 1 year ago
tauri: GSA_kwCzR0hTQS0ycmNwLWp2cjQtcjI1Oc4AA2mV
Tauri's Updater Private Keys Possibly Leaked via Vite Environment VariablesEcosystems: cargo, npm
Packages: tauri-cli, @tauri-apps/cli
Source: github
Published: about 1 year ago
Low
Ecosystems: pypi
Packages: wagtail
Source: github
Published: about 1 year ago
wagtail: GSA_kwCzR0hTQS1mYzc1LTU4cjgtcm0zaM4AA2kA
Wagtail vulnerable to disclosure of user names via admin bulk action viewsEcosystems: pypi
Packages: wagtail
Source: github
Published: about 1 year ago
Moderate
Ecosystems: pypi
Packages: urllib3
Source: github
Published: about 1 year ago
urllib3: GSA_kwCzR0hTQS1nNG14LXE5dmctMjdwNM4AA2gt
urllib3's request body not stripped after redirect from 303 status changes request method to GETEcosystems: pypi
Packages: urllib3
Source: github
Published: about 1 year ago
High
Ecosystems: go
Packages: github.com/gofiber/fiber/v2
Source: github
Published: about 1 year ago
fiber: GSA_kwCzR0hTQS1tdjczLWY2OXgtNDQ0cM4AA2gQ
Go Fiber CSRF Token Validation VulnerabilityEcosystems: go
Packages: github.com/gofiber/fiber/v2
Source: github
Published: about 1 year ago
Critical
Ecosystems: go
Packages: github.com/gofiber/fiber/v2
Source: github
Published: about 1 year ago
fiber: GSA_kwCzR0hTQS05NHc5LTk3cDMtcDM2OM4AA2gP
CSRF Token Reuse VulnerabilityEcosystems: go
Packages: github.com/gofiber/fiber/v2
Source: github
Published: about 1 year ago
Low
Ecosystems: npm
Packages: undici
Source: github
Published: about 1 year ago
undici: GSA_kwCzR0hTQS13cXE0LTV3cHYtbXgyZ84AA2eY
Undici's cookie header not cleared on cross-origin redirect in fetchEcosystems: npm
Packages: undici
Source: github
Published: about 1 year ago
Critical
Ecosystems: npm
Packages: babel-traverse, @babel/traverse
Source: github
Published: about 1 year ago
babel: GSA_kwCzR0hTQS02N2h4LTZ4NTMtanc5Ms4AA2eW
Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeEcosystems: npm
Packages: babel-traverse, @babel/traverse
Source: github
Published: about 1 year ago
High
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 year ago
librenms: GSA_kwCzR0hTQS1tcjZoLTd4Mm0tcmdtcc4AA2dG
SQL injection in librenms/librenmsEcosystems: packagist
Packages: librenms/librenms
Source: github
Published: about 1 year ago
Moderate
Ecosystems: pypi
Packages: urllib3
Source: github
Published: about 1 year ago
urllib3: GSA_kwCzR0hTQS1nd3ZtLTQ1Z3gtM2NmOM4AA2c6
Authorization Header forwarded on redirectEcosystems: pypi
Packages: urllib3
Source: github
Published: about 1 year ago
High
Ecosystems: npm
Packages: uptime-kuma
Source: github
Published: about 1 year ago
uptime-kuma: GSA_kwCzR0hTQS1nOXYyLXdxY2otajk5Z84AA2X4
Uptime Kuma has Persistentent User SessionsEcosystems: npm
Packages: uptime-kuma
Source: github
Published: about 1 year ago
High
Ecosystems: rubygems
Packages: decidim, decidim-templates
Source: github
Published: about 1 year ago
decidim: GSA_kwCzR0hTQS02MzloLTg2aHctcWNqcc4AA2Qo
Decidim has broken access control in templatesEcosystems: rubygems
Packages: decidim, decidim-templates
Source: github
Published: about 1 year ago
High
Ecosystems: pypi
Packages: urllib3
Source: github
Published: about 1 year ago
urllib3: GSA_kwCzR0hTQS12ODQ1LWp4eDUtdmM5Zs4AA2MD
`Cookie` HTTP header isn't stripped on cross-origin redirectsEcosystems: pypi
Packages: urllib3
Source: github
Published: about 1 year ago
Moderate
Ecosystems: packagist
Packages: wallabag/wallabag
Source: github
Published: about 1 year ago
wallabag: GSA_kwCzR0hTQS01NmZtLWhmcDMteDN3M84AA2MC
Wallabag user can disable 2FA unintentionallyEcosystems: packagist
Packages: wallabag/wallabag
Source: github
Published: about 1 year ago
Moderate
Ecosystems: packagist
Packages: microweber/microweber
Source: github
Published: about 1 year ago
microweber: GSA_kwCzR0hTQS1yNjU3LTN3cWgtZzJ4Oc4AA2Jx
Microweber uses hard coded credentialsEcosystems: packagist
Packages: microweber/microweber
Source: github
Published: about 1 year ago
Moderate
Ecosystems: npm
Packages: postcss
Source: github
Published: about 1 year ago
postcss: GSA_kwCzR0hTQS03Zmg1LTY0cDItM3Yyas4AA2Js
PostCSS line return parsing errorEcosystems: npm
Packages: postcss
Source: github
Published: about 1 year ago
High
Ecosystems: npm
Packages: electron
Source: github
Published: about 1 year ago
electron: GSA_kwCzR0hTQS1xcXZxLTZ4Z2otanc4Z84AA2IC
Electron affected by libvpx's heap buffer overflow in vp8 encodingEcosystems: npm
Packages: electron
Source: github
Published: about 1 year ago
Moderate
Ecosystems: packagist
Packages: microweber/microweber
Source: github
Published: about 1 year ago
microweber: GSA_kwCzR0hTQS1yZ2Y5LWo3Z3YtcnEyMs4AA2HZ
Microweber Cross-site Scripting vulnerabilityEcosystems: packagist
Packages: microweber/microweber
Source: github
Published: about 1 year ago
Critical
Ecosystems: go
Packages: github.com/sagernet/sing, github.com/sagernet/sing-box
Source: github
Published: about 1 year ago
sing-box: GSA_kwCzR0hTQS1yNWhtLW1wM2otMjg1Z84AA2C4
sing-box vulnerable to improper authentication in the SOCKS inboundEcosystems: go
Packages: github.com/sagernet/sing, github.com/sagernet/sing-box
Source: github
Published: about 1 year ago
Moderate
Ecosystems: cargo
Packages: aes-gcm
Source: github
Published: about 1 year ago
AEADs: GSA_kwCzR0hTQS00MjN3LXAydzktcjd2cc4AA2An
AEADs/aes-gcm: Plaintext exposed in decrypt_in_place_detached even on tag verification failureEcosystems: cargo
Packages: aes-gcm
Source: github
Published: about 1 year ago
High
Ecosystems: cargo
Packages: quinn-proto
Source: github
Published: about 1 year ago
quinn: GSA_kwCzR0hTQS1xOHdjLWo1bTktMjd3M84AA1_5
Denial of Service issue in quinn-protoEcosystems: cargo
Packages: quinn-proto
Source: github
Published: about 1 year ago
High
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: over 1 year ago
librenms: GSA_kwCzR0hTQS0ycThjLWdxZjQtbWczds4AA17s
Cross site scripting in librenmsEcosystems: packagist
Packages: librenms/librenms
Source: github
Published: over 1 year ago
High
Ecosystems: go
Packages: github.com/usememos/memos
Source: github
Published: over 1 year ago
memos: GSA_kwCzR0hTQS0yZzdyLTl4cTUtYzZods4AA167
Cross-Site Request Forgery (CSRF) in usememos/memosEcosystems: go
Packages: github.com/usememos/memos
Source: github
Published: over 1 year ago
Moderate
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: over 1 year ago
librenms: GSA_kwCzR0hTQS01N20yLW1wYzctZ3dneM4AA14x
LibreNMS Code Injection vulnerabilityEcosystems: packagist
Packages: librenms/librenms
Source: github
Published: over 1 year ago
Moderate
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: over 1 year ago
librenms: GSA_kwCzR0hTQS1xeHJxLTM3NnEtcDM5aM4AA14y
LibreNMS Cross-site Scripting vulnerabilityEcosystems: packagist
Packages: librenms/librenms
Source: github
Published: over 1 year ago
Moderate
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: over 1 year ago
librenms: GSA_kwCzR0hTQS1xanB3LXJnNTYtamg4ds4AA143
LibreNMS Cross-site Scripting vulnerabilityEcosystems: packagist
Packages: librenms/librenms
Source: github
Published: over 1 year ago
Moderate
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: over 1 year ago
librenms: GSA_kwCzR0hTQS1qcDNjLWc0NnYtamcyY84AA14w
LibreNMS Cross-site Scripting vulnerabilityEcosystems: packagist
Packages: librenms/librenms
Source: github
Published: over 1 year ago
Moderate
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: over 1 year ago
librenms: GSA_kwCzR0hTQS01amptLXFwNDgtcXA4Ns4AA144
LibreNMS Cross-site Scripting vulnerabilityEcosystems: packagist
Packages: librenms/librenms
Source: github
Published: over 1 year ago
Moderate
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: over 1 year ago
librenms: GSA_kwCzR0hTQS1tNmpqLWZnbWgtM3A4cs4AA145
LibreNMS Cross-site Scripting vulnerabilityEcosystems: packagist
Packages: librenms/librenms
Source: github
Published: over 1 year ago
High
Ecosystems: npm
Packages: @strapi/plugin-users-permissions, @strapi/admin
Source: github
Published: over 1 year ago
strapi: GSA_kwCzR0hTQS0yNHEyLTU5aG0tcmg5cs4AA12t
Strapi Improper Rate Limiting vulnerabilityEcosystems: npm
Packages: @strapi/plugin-users-permissions, @strapi/admin
Source: github
Published: over 1 year ago
Moderate
Ecosystems: npm
Packages: @strapi/plugin-content-manager
Source: github
Published: over 1 year ago
strapi: GSA_kwCzR0hTQS1tMjg0LTg1bWYtY2dyY84AA12s
Strapi's field level permissions not being respected in relationship titleEcosystems: npm
Packages: @strapi/plugin-content-manager
Source: github
Published: over 1 year ago
Moderate
Ecosystems: npm
Packages: @strapi/utils, @strapi/admin, @strapi/plugin-content-manager
Source: github
Published: over 1 year ago
strapi: GSA_kwCzR0hTQS12OGdnLTRtcTItODhxNM4AA12r
Strapi may leak sensitive user information, user reset password, tokens via content-manager viewsEcosystems: npm
Packages: @strapi/utils, @strapi/admin, @strapi/plugin-content-manager
Source: github
Published: over 1 year ago
High
Ecosystems: packagist
Packages: openmage/magento-lts
Source: github
Published: over 1 year ago
magento-lts: GSA_kwCzR0hTQS05MzU4LWNwdngtYzJxcM4AA1zS
Magento LTS's guest order "protect code" can be brute-forced too easilyEcosystems: packagist
Packages: openmage/magento-lts
Source: github
Published: over 1 year ago
Moderate
Ecosystems: go
Packages: github.com/gofiber/fiber/v2, github.com/gofiber/fiber
Source: github
Published: over 1 year ago
fiber: GSA_kwCzR0hTQS0zcTVwLTM1NTgtMzY0Zs4AA1xI
Fiber unauthorized access vulnerability in `ctx.IsFromLocal()`Ecosystems: go
Packages: github.com/gofiber/fiber/v2, github.com/gofiber/fiber
Source: github
Published: over 1 year ago
Moderate
Ecosystems: npm
Packages: electron
Source: github
Published: over 1 year ago
electron: GSA_kwCzR0hTQS03eDk3LWozNzMtODV4Nc4AA1vg
Electron vulnerable to out-of-package code execution when launched with arbitrary cwdEcosystems: npm
Packages: electron
Source: github
Published: over 1 year ago
Moderate
Ecosystems: npm
Packages: electron
Source: github
Published: over 1 year ago
electron: GSA_kwCzR0hTQS1wN3YyLXA5bTgtcXFnN84AA1vf
Electron context isolation bypass via nested unserializable return valueEcosystems: npm
Packages: electron
Source: github
Published: over 1 year ago
High
Ecosystems: npm
Packages: electron
Source: github
Published: over 1 year ago
electron: GSA_kwCzR0hTQS1neGg3LXd2OXEtZndmcs4AA1vc
Electron's Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabledEcosystems: npm
Packages: electron
Source: github
Published: over 1 year ago
High
Ecosystems: npm
Packages: parse-server
Source: github
Published: over 1 year ago
parse-server: GSA_kwCzR0hTQS1mY3Y2LWZnNXItam05cc4AA1rK
Trigger `beforeFind` not invoked in internal query pipeline when fetching pointerEcosystems: npm
Packages: parse-server
Source: github
Published: over 1 year ago
High
Ecosystems: go
Packages: github.com/usememos/memos
Source: github
Published: over 1 year ago
memos: GSA_kwCzR0hTQS01ajZwLTU5Y2otajZjcM4AA1nE
usememos/memos vulnerable to privilege escalationEcosystems: go
Packages: github.com/usememos/memos
Source: github
Published: over 1 year ago
High
Ecosystems: go
Packages: github.com/usememos/memos
Source: github
Published: over 1 year ago
memos: GSA_kwCzR0hTQS05NmdxLTZjaDUtbW01NM4AA1nF
usememos/memos vulnerable to improper input validationEcosystems: go
Packages: github.com/usememos/memos
Source: github
Published: over 1 year ago
Critical
Ecosystems: go
Packages: github.com/usememos/memos
Source: github
Published: over 1 year ago
memos: GSA_kwCzR0hTQS1qMmdqLWczcDktN21ycs4AA1nC
Account TakeOver Due to Improper Handling of JWT Tokens in usememos/memosEcosystems: go
Packages: github.com/usememos/memos
Source: github
Published: over 1 year ago
Moderate
Ecosystems: pypi
Packages: borgbackup
Source: github
Published: over 1 year ago
borg: GSA_kwCzR0hTQS04ZmpyLWhnaHItNG05Oc4AA1lJ
Archive spoofing vulnerability in borgbackupEcosystems: pypi
Packages: borgbackup
Source: github
Published: over 1 year ago
Moderate
Ecosystems: packagist
Packages: wallabag/wallabag
Source: github
Published: over 1 year ago
wallabag: GSA_kwCzR0hTQS1wOGdwLTg5OWMtanZxOc4AA1aY
Wallabag user can reset data unintentionallyEcosystems: packagist
Packages: wallabag/wallabag
Source: github
Published: over 1 year ago
Moderate
Ecosystems: packagist
Packages: wallabag/wallabag
Source: github
Published: over 1 year ago
wallabag: GSA_kwCzR0hTQS1nanZjLTU1ZnctdjZ2cc4AA1aX
Wallabag user can delete own API client unintentionallyEcosystems: packagist
Packages: wallabag/wallabag
Source: github
Published: over 1 year ago
Moderate
Ecosystems: packagist
Packages: wallabag/wallabag
Source: github
Published: over 1 year ago
wallabag: GSA_kwCzR0hTQS1ndnZ4LWZjNnAtMmg5eM4AA1Z-
Duplicate Advisory: Wallabag user can delete own API client unintentionallyEcosystems: packagist
Packages: wallabag/wallabag
Source: github
Published: over 1 year ago
Moderate
Ecosystems: packagist
Packages: wallabag/wallabag
Source: github
Published: over 1 year ago
wallabag: GSA_kwCzR0hTQS1yd3BnLTRjNGMtdjNyNM4AA1Z8
Duplicate Advisory: Wallabag user can reset data unintentionallyEcosystems: packagist
Packages: wallabag/wallabag
Source: github
Published: over 1 year ago
High
Ecosystems: packagist
Packages: flarum/framework, flarum/core
Source: github
Published: over 1 year ago
framework: GSA_kwCzR0hTQS02N2M2LXE0ajQtaGNjZ84AA1WM
Flarum vulnerable to LFI and Blind SSRF via Avatar uploadEcosystems: packagist
Packages: flarum/framework, flarum/core
Source: github
Published: over 1 year ago
High
Ecosystems: go
Packages: github.com/woodpecker-ci/woodpecker
Source: github
Published: over 1 year ago
woodpecker: GSA_kwCzR0hTQS00Z2NmLTVtMzktOThtY84AA1WL
Woodpecker does not validate webhook before changing any dataEcosystems: go
Packages: github.com/woodpecker-ci/woodpecker
Source: github
Published: over 1 year ago
Moderate
Ecosystems: npm
Packages: @excalidraw/excalidraw
Source: github
Published: over 1 year ago
excalidraw: GSA_kwCzR0hTQS12N3Y4LWdqdjctZmZtcs4AA1WK
@excalidraw/excalidraw Cross-site Scripting vulnerabilityEcosystems: npm
Packages: @excalidraw/excalidraw
Source: github
Published: over 1 year ago
Moderate
Ecosystems: npm
Packages: @excalidraw/excalidraw
Source: github
Published: over 1 year ago
excalidraw: GSA_kwCzR0hTQS1mcjlnLTJtMmgtYzI3as4AA1VN
Duplicate Advisory: @excalidraw/excalidraw Cross-site Scripting vulnerabilityEcosystems: npm
Packages: @excalidraw/excalidraw
Source: github
Published: over 1 year ago
Moderate
Ecosystems: npm
Packages: ghost
Source: github
Published: over 1 year ago
Ghost: GSA_kwCzR0hTQS05Yzl2LXcyMjUtdjVyZ84AA1Uk
Ghost vulnerable to arbitrary file read via symlinks in content importEcosystems: npm
Packages: ghost
Source: github
Published: over 1 year ago
High
Ecosystems: packagist
Packages: librenms/librenms
Source: github
Published: over 1 year ago
librenms: GSA_kwCzR0hTQS1tNnBmLWNtM2YtNzg3Ns4AA1Tn
LibreNMS Cross-site Scripting vulnerabilityEcosystems: packagist
Packages: librenms/librenms
Source: github
Published: over 1 year ago
Moderate
Ecosystems: rubygems
Packages: commonmarker
Source: github
Published: over 1 year ago
commonmarker: GSA_kwCzR0hTQS03dmg3LWZ3ODgtd2o4N84AA1Il
Several quadratic complexity bugs may lead to denial of service in CommonmarkerEcosystems: rubygems
Packages: commonmarker
Source: github
Published: over 1 year ago
Moderate
Ecosystems: go
Packages: code.gitea.io/gitea
Source: github
Published: over 1 year ago
gitea: GSA_kwCzR0hTQS04ajN2LTY4dzMtMzg0OM4AA1Fj
Gitea erroneous repo clonesEcosystems: go
Packages: code.gitea.io/gitea
Source: github
Published: over 1 year ago
Critical
Ecosystems: npm
Packages: @soketi/soketi
Source: github
Published: over 1 year ago
soketi: GSA_kwCzR0hTQS1nNnc2LWg5MzMtNHJjNc4AA1Cn
Soketi was exposed to Sandbox Escape vulnerability via vm2Ecosystems: npm
Packages: @soketi/soketi
Source: github
Published: over 1 year ago
High
Ecosystems: npm
Packages: @pnpm/win-x64, @pnpm/macos-x64, @pnpm/macos-arm64, @pnpm/linuxstatic-arm64, @pnpm/linux-x64, @pnpm/linux-arm64, @pnpm/exe, pnpm, @pnpm/cafs
Source: github
Published: over 1 year ago
pnpm: GSA_kwCzR0hTQS01cjk4LWYzM2otZzhoN84AA0-_
pnpm incorrectly parses tar archives relative to specificationEcosystems: npm
Packages: @pnpm/win-x64, @pnpm/macos-x64, @pnpm/macos-arm64, @pnpm/linuxstatic-arm64, @pnpm/linux-x64, @pnpm/linux-arm64, @pnpm/exe, pnpm, @pnpm/cafs
Source: github
Published: over 1 year ago
Critical
Ecosystems: packagist
Packages: billz/raspap-webgui
Source: github
Published: over 1 year ago
raspap-webgui: GSA_kwCzR0hTQS03YzI4LXdnN3ItcGc2Zs4AA0-u
RaspAP Command Injection vulnerabilityEcosystems: packagist
Packages: billz/raspap-webgui
Source: github
Published: over 1 year ago
High
Ecosystems: packagist
Packages: billz/raspap-webgui
Source: github
Published: over 1 year ago
raspap-webgui: GSA_kwCzR0hTQS03cjg4LXdqaGotanI4bc4AA0-w
RaspAP Command Injection vulnerabilityEcosystems: packagist
Packages: billz/raspap-webgui
Source: github
Published: over 1 year ago
Critical
Ecosystems: maven
Packages: tech.powerjob:powerjob-common
Source: github
Published: over 1 year ago
PowerJob: GSA_kwCzR0hTQS0yaDI2LXFmeG0tcjNwcc4AA08E
Code injection in PowerJobEcosystems: maven
Packages: tech.powerjob:powerjob-common
Source: github
Published: over 1 year ago
High
Ecosystems: npm
Packages: @saltcorn/cli
Source: github
Published: over 1 year ago
saltcorn: GSA_kwCzR0hTQS13eGYzLTRmdmotdnFxeM4AA067
Unsafe plugins can be installed via pack import by tenant adminsEcosystems: npm
Packages: @saltcorn/cli
Source: github
Published: over 1 year ago
High
Ecosystems: npm
Packages: @strapi/utils, @strapi/database
Source: github
Published: over 1 year ago
strapi: GSA_kwCzR0hTQS05eGc0LTNxZm0tOXc4Zs4AA04c
Leaking sensitive user information still possible by filtering on private with prefix fieldsEcosystems: npm
Packages: @strapi/utils, @strapi/database
Source: github
Published: over 1 year ago
Moderate
Ecosystems: npm
Packages: @strapi/database, @strapi/utils, @strapi/strapi
Source: github
Published: over 1 year ago
strapi: GSA_kwCzR0hTQS1jaG1yLXJnMmYtOWptZs4AA04b
Making all attributes on a content-type public without noticing itEcosystems: npm
Packages: @strapi/database, @strapi/utils, @strapi/strapi
Source: github
Published: over 1 year ago
High
Ecosystems: npm
Packages: @feathersjs/transport-commons, @feathersjs/socketio
Source: github
Published: over 1 year ago
feathers: GSA_kwCzR0hTQS1oaHI5LXJoMjUtaHZmOc4AA00L
Feathers socket handler allows abusing implicit toStringEcosystems: npm
Packages: @feathersjs/transport-commons, @feathersjs/socketio
Source: github
Published: over 1 year ago
High
Ecosystems: packagist
Packages: getgrav/grav
Source: github
Published: over 1 year ago
grav: GSA_kwCzR0hTQS05NDM2LTNnbXAtNGY1M84AA0zw
grav Server-side Template Injection (SSTI) mitigation bypassEcosystems: packagist
Packages: getgrav/grav
Source: github
Published: over 1 year ago
Moderate
Ecosystems: rubygems
Packages: decidim-core, decidim
Source: github
Published: over 1 year ago
decidim: GSA_kwCzR0hTQS00NjloLW1xZzgtNTM1cs4AA0m3
Decidim Cross-site Scripting vulnerability in the external link redirectionsEcosystems: rubygems
Packages: decidim-core, decidim
Source: github
Published: over 1 year ago
High
Ecosystems: rubygems
Packages: decidim-core, decidim
Source: github
Published: over 1 year ago
decidim: GSA_kwCzR0hTQS01NjUyLTkycjktM2Z4Oc4AA0m4
Decidim Cross-site Scripting vulnerability in the processes filterEcosystems: rubygems
Packages: decidim-core, decidim
Source: github
Published: over 1 year ago
High
Ecosystems: rubygems
Packages: decidim-meetings, decidim
Source: github
Published: over 1 year ago
decidim: GSA_kwCzR0hTQS1qbTc5LTlwbTQtdnJ3Oc4AA0m2
Decidim vulnerable to sensitive data disclosureEcosystems: rubygems
Packages: decidim-meetings, decidim
Source: github
Published: over 1 year ago
Critical
Ecosystems: packagist
Packages: orchid/platform
Source: github
Published: over 1 year ago
platform: GSA_kwCzR0hTQS1waDZnLXA3MnYtcGMzcM4AA0m1
Orchid Deserialization of Untrusted Data vulnerability leads to Remote Code ExecutionEcosystems: packagist
Packages: orchid/platform
Source: github
Published: over 1 year ago
Low
Ecosystems: npm
Packages: @vendure/core
Source: github
Published: over 1 year ago
vendure: GSA_kwCzR0hTQS1oOXdxLXhjcXgtbXF4bc4AA0m0
Vendure Cross Site Request Forgery vulnerability impacting all API requestsEcosystems: npm
Packages: @vendure/core
Source: github
Published: over 1 year ago
Low
Ecosystems: packagist
Packages: wintercms/winter
Source: github
Published: over 1 year ago
winter: GSA_kwCzR0hTQS13ancyLTRqN2otNmdjM84AA0fu
Winter CMS stored XSS through privileged upload of SVG fileEcosystems: packagist
Packages: wintercms/winter
Source: github
Published: over 1 year ago
Low
Ecosystems: npm
Packages: stylelint
Source: github
Published: over 1 year ago
stylelint: GSA_kwCzR0hTQS1mN3hqLXJnN2gtbWM4N84AA0ft
Stylelint has vulnerability in semver dependencyEcosystems: npm
Packages: stylelint
Source: github
Published: over 1 year ago
Critical
Ecosystems: pypi
Packages: scipy
Source: github
Published: over 1 year ago
scipy: GSA_kwCzR0hTQS1qcmZtLTJoODIteGcyOM4AA0e1
Withdrawn: Use after free in SciPyEcosystems: pypi
Packages: scipy
Source: github
Published: over 1 year ago
Critical
Ecosystems: maven
Packages: org.apache.streampark:streampark
Source: github
Published: over 1 year ago
incubator-streampark: GSA_kwCzR0hTQS1tNWg4LTJwanctdmczas4AA0XS
Apache StreamPark Improper Input Validation vulnerabilityEcosystems: maven
Packages: org.apache.streampark:streampark
Source: github
Published: over 1 year ago
Critical
Ecosystems: maven
Packages: org.apache.streampark:streampark-common_2.11, org.apache.streampark:streampark-common_2.12
Source: github
Published: over 1 year ago
incubator-streampark: GSA_kwCzR0hTQS02ODc0LTI4OWctZjdoN84AA0XW
Apache StreamPark Path Traversal vulnerabilityEcosystems: maven
Packages: org.apache.streampark:streampark-common_2.11, org.apache.streampark:streampark-common_2.12
Source: github
Published: over 1 year ago
Moderate
Ecosystems: npm
Packages: @vendure/admin-ui-plugin
Source: github
Published: over 1 year ago
vendure: GSA_kwCzR0hTQS1nbTY4LTU3MnAtcTI4cs4AA0Q9
@vendure/admin-ui-plugin authenticated Cross-site Scripting vulnerabilityEcosystems: npm
Packages: @vendure/admin-ui-plugin
Source: github
Published: over 1 year ago
High
Ecosystems: pypi
Packages: kiwitcms
Source: github
Published: over 1 year ago
Kiwi: GSA_kwCzR0hTQS1qcGd3LTJyOW0tOHFmd84AA0OU
Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with FirefoxEcosystems: pypi
Packages: kiwitcms
Source: github
Published: over 1 year ago
Moderate
Ecosystems: pypi
Packages: scipy
Source: github
Published: over 1 year ago
scipy: GSA_kwCzR0hTQS05ang1LTZwZ2YtY3JycM4AA0N8
Withdrawn: scipy memory leak vulnerabilityEcosystems: pypi
Packages: scipy
Source: github
Published: over 1 year ago