Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
860216
AlmaLinux
5665
Alpaquita
13868
Alpine
4468
Android
3402
Azure Linux
15406
BellSoft Hardened Containers
656
Bitnami
9028
Chainguard
10160
CleanStart
1987
CRAN
14
crates.io
2672
Debian
64689
Echo
8348
GHC
3
GIT
101472
GitHub Actions
55
Go
8867
Hackage
32
Hex
249
Julia
1713
Linux
27860
Mageia
6109
Maven
6949
MinimOS
129562
npm
227708
NuGet
1844
opam
26
openEuler
8163
openSUSE
14053
OSS-Fuzz
3983
Packagist
6922
Pub
11
PyPI
24598
Red Hat
22454
Rocky Linux
4033
Root
19004
RubyGems
4592
SUSE
22508
SwiftURL
59
TuxCare
8594
Ubuntu
61195
VSCode
20
Wolfi
7215
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-c857-9x2m-cvh2
Maven/org.mariadb:r2dbc-mariadb
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
12 hours ago
Fix available
Severity - 5.9 (Medium)
GHSA-5rqc-86vf-g8r2
Maven/org.mariadb:r2dbc-mariadb
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output
12 hours ago
Fix available
Severity - 5.9 (Medium)
GHSA-xvr9-35cr-46v9
Maven/org.mariadb.jdbc:mariadb-java-client
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context
12 hours ago
Fix available
Severity - 5.9 (Medium)
GHSA-qxvw-fvwx-5cp7
Maven/org.mariadb.jdbc:mariadb-java-client
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
12 hours ago
Fix available
Severity - 5.9 (Medium)
GHSA-g9jj-cgmh-9f38
Maven/org.mariadb.jdbc:mariadb-java-client
MariaDB has cleartext password disclosure to a MITM on the initial-handshake
12 hours ago
Fix available
Severity - 5.9 (Medium)
GHSA-5v29-34h8-v68r
Maven/org.mapfish.print:print-lib
Maven/org.mapfish.print:print-servlet
Maven/org.mapfish:print.print-servlet
MapFish Print has XXE that allows reading arbitrary files of certain types
12 hours ago
Fix available
Severity - 8.6 (High)
GHSA-j769-9gv9-65gr
Maven/org.graylog2:graylog2-server
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
13 hours ago
Fix available
Severity - 5.3 (Medium)
GHSA-gqr6-r77p-c2pj
Maven/org.graylog2:graylog2-server
Fortigate syslog message parser can be exploited to modify or delete fields from the original message
13 hours ago
Fix available
Severity - 7.5 (High)
GHSA-jqvf-j3ww-r8c7
Maven/com.powsybl:powsybl-computation-local
PowSyBl Core has Command Injection in LocalCommandExecutor-s
16 hours ago
Fix available
Severity - 7.1 (High)
GHSA-p68j-q7hf-3qcp
Maven/io.spinnaker.rosco:rosco-manifests
Spinnaker: Improper yaml processing on kustomize bake operations
16 hours ago
Fix available
Severity - 7.5 (High)
GHSA-q79r-r9xg-r863
Maven/org.graylog2:graylog2-server
Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields
17 hours ago
Fix available
Severity - 5.0 (Medium)
GHSA-9272-wg2r-7xmx
Maven/org.yamcs:yamcs-core
Yamcs has DOM XSS in Extension Routing
17 hours ago
Fix available
Severity - 4.3 (Medium)
GHSA-c64q-hj4j-375f
Maven/org.yamcs:yamcs-core
Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
17 hours ago
Fix available
Severity - 9.9 (Critical)
GHSA-73mf-m39p-wpm9
Maven/org.yamcs:yamcs-core
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
17 hours ago
Fix available
Severity - 9.8 (Critical)
GHSA-9jg3-g3wh-w9pj
Maven/org.yamcs:yamcs-core
Yamcs has Unauthenticated Directory Traversal
17 hours ago
Fix available
Severity - 7.5 (High)
GHSA-rxpg-wjf8-qv9c
Maven/org.yamcs:yamcs-core
Yamcs has Reflected XSS in the URL of the Authorize Endpoint
18 hours ago
Fix available
Severity - 6.5 (Medium)
Load more...
Maven - OSV