Skip to content

GitHub Advisory Database

2,024 advisories

modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leadi...
CVE-2017-1002157 (Low severity) was published Jan 17, 2019 modulemd (pip)
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
CVE-2018-20677 (Low severity) was published Jan 17, 2019 bootstrap (npm)
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
CVE-2018-20676 (Low severity) was published Jan 17, 2019 bootstrap (npm)
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-targe...
CVE-2016-10735 (Low severity) was published Jan 17, 2019 bootstrap (npm)
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined...
CVE-2018-11798 (Moderate severity) was published Jan 17, 2019 org.apache.thrift:libthrift (Maven)
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isCom...
CVE-2018-1320 (Moderate severity) was published Jan 17, 2019 org.apache.thrift:libthrift (Maven)
privacyIDEA version 2.23.1 and earlier contains a Improper Input Validation vulnerability in toke...
CVE-2018-1000809 (High severity) was published Jan 14, 2019 privacyIDEA (pip)
A remote code execution vulnerability exists in Xterm.js when the component mishandles special ch...
CVE-2019-0542 (Low severity) was published Jan 14, 2019 xterm (npm)
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutral...
CVE-2019-3498 (Low severity) was published Jan 14, 2019 django (pip)
In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in...
CVE-2018-11787 (Moderate severity) was published Jan 7, 2019 org.apache.karaf:apache-karaf (Maven)
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigX...
CVE-2018-20433 (Moderate severity) was published Jan 7, 2019 com.mchange:c3p0 (Maven)
Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid ...
CVE-2017-18352 (Moderate severity) was published Jan 7, 2019 rendertron (npm)
Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by d...
CVE-2018-11788 (Moderate severity) was published Jan 7, 2019 org.apache.karaf:karaf (Maven)
Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDA...
CVE-2016-8750 (Moderate severity) was published Jan 7, 2019 org.apache.karaf:apache-karaf (Maven)
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary cod...
CVE-2018-14719 (High severity) was published Jan 4, 2019 com.fasterxml.jackson.core:jackson-databind (Maven)
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity ...
CVE-2018-14720 (High severity) was published Jan 4, 2019 com.fasterxml.jackson.core:jackson-databind (Maven)
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary cod...
CVE-2018-14718 (High severity) was published Jan 4, 2019 com.fasterxml.jackson.core:jackson-databind (Maven)
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by l...
CVE-2018-19360 (High severity) was published Jan 4, 2019 com.fasterxml.jackson.core:jackson-databind (Maven)
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by l...
CVE-2018-19361 (High severity) was published Jan 4, 2019 com.fasterxml.jackson.core:jackson-databind (Maven)
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by l...
CVE-2018-19362 (High severity) was published Jan 4, 2019 com.fasterxml.jackson.core:jackson-databind (Maven)
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side r...
CVE-2018-14721 (High severity) was published Jan 4, 2019 com.fasterxml.jackson.core:jackson-databind (Maven)
React applications which rendered to HTML using the ReactDOMServer API were not escaping user-sup...
CVE-2018-6341 (Low severity) was published Jan 4, 2019 react-dom (npm)
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. I...
CVE-2018-7537 (Moderate severity) was published Jan 4, 2019 django (pip)
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. T...
CVE-2018-7536 (Moderate severity) was published Jan 4, 2019 django (pip)
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8....
CVE-2017-7234 (Moderate severity) was published Jan 4, 2019 django (pip)
ProTip! Advisories are also available from the GraphQL API.
You can’t perform that action at this time.