Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-m9c2-85gv-8xr5
  • Maven/org.graylog2:graylog2-server
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards 17 hours ago
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-7952-gx68-cjqr
  • Maven/net.sf.mpxj:mpxj
  • NuGet/MPXJ.Net
  • NuGet/net.sf.mpxj
  • NuGet/net.sf.mpxj-for-csharp
  • NuGet/net.sf.mpxj-for-vb
  • ... 2 more
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers 17 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-5vvx-3h34-f3gj
  • Maven/net.sf.mpxj:mpxj
  • NuGet/MPXJ.Net
  • NuGet/net.sf.mpxj
  • NuGet/net.sf.mpxj-for-csharp
  • NuGet/net.sf.mpxj-for-vb
  • ... 2 more
MPXJ: XXE Vulnerability in MerlinReader 17 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-9jjc-fw8x-fmwx
  • Maven/io.moquette:moquette-broker
io.moquette:moquette-broker has a Missing Authorization issue 4 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-26vp-8gxg-v4pg
  • Maven/org.xwiki.rendering:xwiki-rendering-xml
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue 4 days ago
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-m6c8-jcw2-5r25
  • Maven/org.opencastproject:opencast-engage-paella-player-7
  • npm/paella-core
Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text 5 days ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-gq9c-wmrm-5hvr
  • Maven/ca.uhn.hapi.fhir:org.hl7.fhir.r5
  • Maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation
  • Maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service 5 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-3w98-rrpr-fprr
  • Maven/ca.uhn.hapi.fhir:org.hl7.fhir.r5
  • Maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation
  • Maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service 5 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-f8m2-889x-vw4x
  • Maven/org.asynchttpclient:async-http-client
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target 5 days ago
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-xr57-gcx8-52hf
  • Maven/org.asynchttpclient:async-http-client
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request 5 days ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-7grg-jcf7-rpmx
  • Maven/org.asynchttpclient:async-http-client
AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service 5 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-fj9w-c36g-h5x8
  • Maven/org.asynchttpclient:async-http-client
AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses 5 days ago
  • Fix available
  • Severity - 3.7 (Low)
GHSA-hpj9-grjp-7vc7
  • Maven/io.kestra:kestra
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth 5 days ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-r56g-q4p6-m3p6
  • Maven/io.kestra:core
  • Maven/io.kestra:kestra-core
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata 5 days ago
  • Fix available
  • Severity - 8.6 (High)
GHSA-89m4-43j5-vhhx
  • Maven/com.github.junrar:junrar
Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root 5 days ago
  • Fix available
  • Severity - 3.7 (Low)
GHSA-wxmm-q36w-r9xj
  • Maven/org.mariadb.jdbc:mariadb-java-client
MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests 5 days ago
  • Fix available
  • Severity - 3.7 (Low)