Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2024-45304 Cairo-Contracts are OpenZeppelin Contracts written in Cairo for Starknet, a decentralized ZK Rollup. This vulnerability can lead to unauthorized owne… Contracts 0.16.0+ Fix from $1,6002024-08-31 HIGH 7.4 CVE-2024-27094 OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes` input by iterating over it … Contracts 4.9.6 / 5.0.2+ Fix from $1,9502024-03-21 HIGH 7.5 CVE-2023-49798 OpenZeppelin Contracts is a library for smart contract development. A merge issue when porting the 5.0.1 patch to the 4.9 branch caused a line duplic… Contracts Patch available Fix from $1,9502023-12-09 MEDIUM 5.3 CVE-2023-40014 OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 4.0.0 and prior to version 4.9.3, contracts using `ERC… Openzeppelin Contracts 4.9.3+ Fix from $1,6002023-08-10 MEDIUM 5.9 CVE-2023-34459 OpenZeppelin Contracts is a library for smart contract development. Starting in version 4.7.0 and prior to version 4.9.2, when the `verifyMultiProof`… Contracts 4.9.2+ Fix from $1,6002023-06-16 MEDIUM 5.3 CVE-2023-34234 OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer a… Contracts 4.9.1+ Fix from $1,6002023-06-07 MEDIUM 5.3 CVE-2023-30541 OpenZeppelin Contracts is a library for secure smart contract development. A function in the implementation contract may be inaccessible if its selec… Contracts 4.8.3+ Fix from $1,6002023-04-17 HIGH 8.8 CVE-2023-30542 OpenZeppelin Contracts is a library for secure smart contract development. The proposal creation entrypoint (`propose`) in `GovernorCompatibilityBrav… Contracts 4.8.3+ Fix from $1,9502023-04-16 MEDIUM 6.5 CVE-2023-26488 OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for minting NFTs in batches does n… Contracts 4.8.2+ Fix from $1,6002023-03-03 MEDIUM 5.3 CVE-2023-23940 OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_val… Contracts 0.6.1+ Fix from $1,6002023-02-03 MEDIUM 5.6 CVE-2022-39384 OpenZeppelin Contracts is a library for secure smart contract development. Before version 4.4.1 but after 3.2.0, initializer functions that are invok… Contracts 4.4.1+ Fix from $1,6002022-11-04 MEDIUM 6.5 CVE-2022-35961 OpenZeppelin Contracts is a library for secure smart contract development. The functions `ECDSA.recover` and `ECDSA.tryRecover` are vulnerable to a k… Contracts 4.7.3+ Fix from $1,6002022-08-15 HIGH 7.5 CVE-2022-31198 OpenZeppelin Contracts is a library for secure smart contract development. This issue concerns instances of Governor that use the module `GovernorVot… Contracts 4.7.2+ Fix from $1,9502022-08-01 MEDIUM 5.3 CVE-2022-35915 OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbo… Contracts 4.7.2+ Fix from $1,6002022-08-01 MEDIUM 5.3 CVE-2022-35916 OpenZeppelin Contracts is a library for secure smart contract development. Contracts using the cross chain utilities for Arbitrum L2, `CrossChainEnab… Contracts 4.7.2+ Fix from $1,6002022-08-01 HIGH 7.5 CVE-2022-31170 OpenZeppelin Contracts is a library for smart contract development. Versions 4.0.0 until 4.7.1 are vulnerable to ERC165Checker reverting instead of r… Contracts 4.7.1+ Fix from $1,9502022-07-22 HIGH 7.5 CVE-2022-31172 OpenZeppelin Contracts is a library for smart contract development. Versions 4.1.0 until 4.7.1 are vulnerable to the SignatureChecker reverting. `Sig… Contracts 4.7.1+ Fix from $1,9502022-07-22 MEDIUM 6.5 CVE-2022-31153 OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vul… Contracts Patch available Fix from $1,6002022-07-15 HIGH 7.5 CVE-2021-46320 In OpenZeppelin <=v4.4.0, initializer functions that are invoked separate from contract creation (the most prominent example being minimal proxies) m… Openzeppelin after 4.4.0 Fix from $1,9502022-02-04 CRITICAL 9.8 CVE-2021-41264 OpenZeppelin Contracts is a library for smart contract development. In affected versions upgradeable contracts using `UUPSUpgradeable` may be vulnera… Contracts 4.3.2+ Fix from $2,3002021-11-12 CRITICAL 9.8 CVE-2021-39168 OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executo… Contracts 3.4.2 / 4.3.1+ Fix from $2,3002021-08-27 CRITICAL 9.8 CVE-2021-39167 OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executo… Contracts 3.4.2 / 4.3.1+ Fix from $2,3002021-08-27