Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-c857-9x2m-cvh2
  • Maven/org.mariadb:r2dbc-mariadb
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport) 12 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-5rqc-86vf-g8r2
  • Maven/org.mariadb:r2dbc-mariadb
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output 12 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-xvr9-35cr-46v9
  • Maven/org.mariadb.jdbc:mariadb-java-client
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context 12 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-qxvw-fvwx-5cp7
  • Maven/org.mariadb.jdbc:mariadb-java-client
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials 12 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-g9jj-cgmh-9f38
  • Maven/org.mariadb.jdbc:mariadb-java-client
MariaDB has cleartext password disclosure to a MITM on the initial-handshake 12 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-5v29-34h8-v68r
  • Maven/org.mapfish.print:print-lib
  • Maven/org.mapfish.print:print-servlet
  • Maven/org.mapfish:print.print-servlet
MapFish Print has XXE that allows reading arbitrary files of certain types 12 hours ago
  • Fix available
  • Severity - 8.6 (High)
GHSA-j769-9gv9-65gr
  • Maven/org.graylog2:graylog2-server
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens 13 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-gqr6-r77p-c2pj
  • Maven/org.graylog2:graylog2-server
Fortigate syslog message parser can be exploited to modify or delete fields from the original message 13 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-jqvf-j3ww-r8c7
  • Maven/com.powsybl:powsybl-computation-local
PowSyBl Core has Command Injection in LocalCommandExecutor-s 16 hours ago
  • Fix available
  • Severity - 7.1 (High)
GHSA-p68j-q7hf-3qcp
  • Maven/io.spinnaker.rosco:rosco-manifests
Spinnaker: Improper yaml processing on kustomize bake operations 16 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-q79r-r9xg-r863
  • Maven/org.graylog2:graylog2-server
Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields 17 hours ago
  • Fix available
  • Severity - 5.0 (Medium)
GHSA-9272-wg2r-7xmx
  • Maven/org.yamcs:yamcs-core
Yamcs has DOM XSS in Extension Routing 17 hours ago
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-c64q-hj4j-375f
  • Maven/org.yamcs:yamcs-core
Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`) 17 hours ago
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-73mf-m39p-wpm9
  • Maven/org.yamcs:yamcs-core
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance) 17 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-9jg3-g3wh-w9pj
  • Maven/org.yamcs:yamcs-core
Yamcs has Unauthenticated Directory Traversal 17 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-rxpg-wjf8-qv9c
  • Maven/org.yamcs:yamcs-core
Yamcs has Reflected XSS in the URL of the Authorize Endpoint 18 hours ago
  • Fix available
  • Severity - 6.5 (Medium)