Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2243552
AlmaLinux
5993
Alpaquita
16181
Alpine
4655
Android
3707
Azure Linux
17973
BellSoft Hardened Containers
771
Bitnami
9525
Chainguard
1048774
CleanStart
5459
CRAN
14
crates.io
2768
Debian
69220
Echo
7791
GHC
3
GIT
109201
GitHub Actions
55
Go
9333
Hackage
33
Hex
367
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148847
npm
229281
NuGet
1872
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4020
Packagist
7103
Pub
11
PyPI
25502
Red Hat
23557
Rocky Linux
4362
Root
19705
RubyGems
5369
SUSE
23469
SwiftURL
61
TuxCare
10025
Ubuntu
66123
VSCode
21
Wolfi
293845
ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-49832
github.com/dspace/dspace
DSpace: Remote Code Execution (RCE) possible in Velocity Templates used by LDN
02 Sep
Fix available
Severity - 8.0 (High)
CVE-2026-49833
github.com/dspace/dspace
DSpace: Path Traversal possible in LDN message generation
02 Sep
Fix available
Severity - 5.5 (Medium)
CVE-2026-49831
github.com/dspace/dspace
DSpace: Curation Task Reporter output path is not restricted to trusted directories (Path Traversal Vulnerability)
02 Sep
Fix available
Severity - 5.5 (Medium)
CVE-2026-49830
github.com/dspace/dspace
DSpace: ORE resource URI does not validate scheme for non-web resources
02 Sep
Fix available
Severity - 4.4 (Medium)
GHSA-9qm4-rh6w-pq5x
Maven/org.dspace:dspace-api
DSpace: Path Traversal is possible through LDN message generation
08 Jul
Fix available
Severity - 5.5 (Medium)
GHSA-c827-pw3m-67w7
Maven/org.dspace:dspace-api
DSpace: ORE resource URI does not validate scheme for non-web resources
08 Jul
Fix available
Severity - 4.4 (Medium)
GHSA-v66x-68f2-pxf5
Maven/org.dspace:dspace-api
DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path
08 Jul
Fix available
Severity - 5.5 (Medium)
GHSA-9x82-rm84-c6x7
Maven/org.dspace:dspace-api
DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN
08 Jul
Fix available
Severity - 8.0 (High)
GHSA-vhvx-8xgc-99wf
Maven/org.dspace:dspace-api
DSpace is vulnerable to Path Traversal attacks when importing packages using Simple Archive Format
15 Jul 2025
Fix available
Severity - 5.2 (Medium)
GHSA-jjwr-5cfh-7xwh
Maven/org.dspace:dspace-api
DSpace is vulnerable to XML External Entity injection during archive imports
15 Jul 2025
Fix available
Severity - 6.9 (Medium)
CVE-2025-53622
github.com/dspace/dspace
DSpace has path traversal vulnerability in Simple Archive Format (SAF) package import via contents file
15 Jul 2025
Fix available
Severity - 5.2 (Medium)
CVE-2025-53621
github.com/dspace/dspace
DSpace vulnerable to XML External Entity (XXE) injection in import via Simple Archive Format (SAF) or import from external sources
15 Jul 2025
Fix available
Severity - 6.9 (Medium)
CVE-2024-38364
github.com/dspace/dspace
DSpace Cross Site Scripting (XSS) via a deposited HTML/XML document
25 Jun 2024
Fix available
Severity - 2.6 (Low)
GHSA-94cc-xjxr-pwvf
Maven/org.dspace:dspace-server-webapp
DSpace Cross Site Scripting (XSS) via a deposited HTML/XML document
25 Jun 2024
Fix available
Severity - 2.6 (Low)
GHSA-8rmh-55h4-93h5
Maven/org.dspace:dspace-api
DSpace ItemImportService API Vulnerable to Path Traversal in Simple Archive Format Package Import
06 Aug 2022
Fix available
Severity - 7.2 (High)
GHSA-qp5m-c3m9-8q2p
Maven/org.dspace:dspace-jspui
JSPUI vulnerable to path traversal in submission (resumable) upload
06 Aug 2022
Fix available
Severity - 8.2 (High)
Load more...
Vulnerability Database - OSV