GitHub Advisory Database
2,024 advisories
Filter by severity
modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leadi...
CVE-2017-1002157
(Low severity)
was published Jan 17, 2019
•
modulemd
(pip)
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
CVE-2018-20677
(Low severity)
was published Jan 17, 2019
•
bootstrap
(npm)
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
CVE-2018-20676
(Low severity)
was published Jan 17, 2019
•
bootstrap
(npm)
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-targe...
CVE-2016-10735
(Low severity)
was published Jan 17, 2019
•
bootstrap
(npm)
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined...
CVE-2018-11798
(Moderate severity)
was published Jan 17, 2019
•
org.apache.thrift:libthrift
(Maven)
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isCom...
CVE-2018-1320
(Moderate severity)
was published Jan 17, 2019
•
org.apache.thrift:libthrift
(Maven)
privacyIDEA version 2.23.1 and earlier contains a Improper Input Validation vulnerability in toke...
CVE-2018-1000809
(High severity)
was published Jan 14, 2019
•
privacyIDEA
(pip)
A remote code execution vulnerability exists in Xterm.js when the component mishandles special ch...
CVE-2019-0542
(Low severity)
was published Jan 14, 2019
•
xterm
(npm)
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutral...
CVE-2019-3498
(Low severity)
was published Jan 14, 2019
•
django
(pip)
In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in...
CVE-2018-11787
(Moderate severity)
was published Jan 7, 2019
•
org.apache.karaf:apache-karaf
(Maven)
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigX...
CVE-2018-20433
(Moderate severity)
was published Jan 7, 2019
•
com.mchange:c3p0
(Maven)
Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid ...
CVE-2017-18352
(Moderate severity)
was published Jan 7, 2019
•
rendertron
(npm)
Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by d...
CVE-2018-11788
(Moderate severity)
was published Jan 7, 2019
•
org.apache.karaf:karaf
(Maven)
Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDA...
CVE-2016-8750
(Moderate severity)
was published Jan 7, 2019
•
org.apache.karaf:apache-karaf
(Maven)
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary cod...
CVE-2018-14719
(High severity)
was published Jan 4, 2019
•
com.fasterxml.jackson.core:jackson-databind
(Maven)
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity ...
CVE-2018-14720
(High severity)
was published Jan 4, 2019
•
com.fasterxml.jackson.core:jackson-databind
(Maven)
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary cod...
CVE-2018-14718
(High severity)
was published Jan 4, 2019
•
com.fasterxml.jackson.core:jackson-databind
(Maven)
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by l...
CVE-2018-19360
(High severity)
was published Jan 4, 2019
•
com.fasterxml.jackson.core:jackson-databind
(Maven)
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by l...
CVE-2018-19361
(High severity)
was published Jan 4, 2019
•
com.fasterxml.jackson.core:jackson-databind
(Maven)
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by l...
CVE-2018-19362
(High severity)
was published Jan 4, 2019
•
com.fasterxml.jackson.core:jackson-databind
(Maven)
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side r...
CVE-2018-14721
(High severity)
was published Jan 4, 2019
•
com.fasterxml.jackson.core:jackson-databind
(Maven)
React applications which rendered to HTML using the ReactDOMServer API were not escaping user-sup...
CVE-2018-6341
(Low severity)
was published Jan 4, 2019
•
react-dom
(npm)
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. I...
CVE-2018-7537
(Moderate severity)
was published Jan 4, 2019
•
django
(pip)
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. T...
CVE-2018-7536
(Moderate severity)
was published Jan 4, 2019
•
django
(pip)
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8....
CVE-2017-7234
(Moderate severity)
was published Jan 4, 2019
•
django
(pip)
ProTip! Advisories are also available from the
GraphQL API.