Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2235459
AlmaLinux
5947
Alpaquita
15755
Alpine
4608
Android
2912
Azure Linux
17629
BellSoft Hardened Containers
746
Bitnami
9306
Chainguard
1023658
CleanStart
3591
CRAN
14
crates.io
2732
Debian
68345
Docker Hardened Images
1
Echo
3914
GHC
3
GIT
105984
GitHub Actions
55
Go
9205
Hackage
32
Hex
361
Julia
1713
Linux
29206
Mageia
6227
Maven
7040
MinimOS
144127
npm
228732
NuGet
1869
opam
29
openEuler
8800
openSUSE
14458
OSS-Fuzz
4003
Packagist
7101
Pub
11
PyPI
25159
Red Hat
23327
Rocky Linux
4295
Root
19535
RubyGems
5326
SUSE
23080
SwiftURL
60
TuxCare
9624
Ubuntu
65379
VSCode
21
Wolfi
331539
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-cjx3-73hr-rpw7
Maven/org.http4s:http4s-scala-xml_2.12
Maven/org.http4s:http4s-scala-xml_2.13
Maven/org.http4s:http4s-scala-xml_3
http4s-scala-xml has an XML External Entity (XXE) processing issue
2 days ago
Fix available
Severity - 9.3 (Critical)
GHSA-w4cm-gvhj-cgw6
Maven/org.typelevel:jawn-parser_2.12
Maven/org.typelevel:jawn-parser_2.13
Maven/org.typelevel:jawn-parser_3
Jawn: Quadratic parsing effort in AsyncParser
3 days ago
Fix available
Severity - 7.5 (High)
GHSA-cc4v-rvgp-2pf3
Maven/org.typelevel:jawn-parser_2.12
Maven/org.typelevel:jawn-parser_2.13
Maven/org.typelevel:jawn-parser_3
Jawn: Uncontrolled nesting depth in JSON parser
3 days ago
Fix available
Severity - 7.5 (High)
GHSA-ph9c-7hw9-vhhw
Maven/org.jline:jline-builtins
JLine: ReDoS in Nano Editor Regex Search Mode
3 days ago
Fix available
Severity - 6.5 (Medium)
GHSA-r2xf-8xr9-62gw
Maven/org.jline:jline-builtins
JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping
3 days ago
Fix available
Severity - 7.5 (High)
GHSA-5q95-hrpc-m3w3
Maven/org.jline:jline-reader
JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable
3 days ago
Fix available
Severity - 5.5 (Medium)
GHSA-5f42-97gr-vfhq
Maven/io.moquette:moquette-broker
Moquette: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bug
3 days ago
Fix available
Severity - 9.6 (Critical)
GHSA-m9c2-85gv-8xr5
Maven/org.graylog2:graylog2-server
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards
4 days ago
Fix available
Severity - 6.3 (Medium)
GHSA-7952-gx68-cjqr
Maven/net.sf.mpxj:mpxj
NuGet/MPXJ.Net
NuGet/net.sf.mpxj
NuGet/net.sf.mpxj-for-csharp
NuGet/net.sf.mpxj-for-vb
... 2 more
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
4 days ago
Fix available
Severity - 5.3 (Medium)
GHSA-5vvx-3h34-f3gj
Maven/net.sf.mpxj:mpxj
NuGet/MPXJ.Net
NuGet/net.sf.mpxj
NuGet/net.sf.mpxj-for-csharp
NuGet/net.sf.mpxj-for-vb
... 2 more
MPXJ: XXE Vulnerability in MerlinReader
4 days ago
Fix available
Severity - 7.5 (High)
GHSA-9jjc-fw8x-fmwx
Maven/io.moquette:moquette-broker
io.moquette:moquette-broker has a Missing Authorization issue
18 Sep
Fix available
Severity - 7.5 (High)
GHSA-26vp-8gxg-v4pg
Maven/org.xwiki.rendering:xwiki-rendering-xml
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue
18 Sep
Fix available
Severity - 9.9 (Critical)
GHSA-m6c8-jcw2-5r25
Maven/org.opencastproject:opencast-engage-paella-player-7
npm/paella-core
Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text
18 Sep
Fix available
Severity - 8.7 (High)
GHSA-gq9c-wmrm-5hvr
Maven/ca.uhn.hapi.fhir:org.hl7.fhir.r5
Maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation
Maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-3w98-rrpr-fprr
Maven/ca.uhn.hapi.fhir:org.hl7.fhir.r5
Maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation
Maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-f8m2-889x-vw4x
Maven/org.asynchttpclient:async-http-client
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target
17 Sep
Fix available
Severity - 6.8 (Medium)
Load more...
Maven - OSV