Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2024-47532
RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensibl…
Restrictedpython
7.3+
CRITICAL 9.8
CVE-2024-24811
SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbit…
Sqlalchemyda
2.2+
MEDIUM 5.4
CVE-2023-42458
Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scripting vulnerability for SVG image…
Zope
4.8.10 / 5.8.5+
HIGH 7.7
CVE-2023-41050
AccessControl provides a general security framework for use in Zope. Python's "format" functionality allows someone controlling the format string to …
Accesscontrol
4.4 / 4.8.9+
HIGH 7.7
CVE-2023-41039
RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality allows someone controlling t…
Restrictedpython
5.4 / 6.2+
CRITICAL 9.9
CVE-2023-37271
RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program input into a trusted environm…
Restrictedpython
5.3+
HIGH 7.5
CVE-2023-36814
Products.CMFCore are the key framework services for the Zope Content Management Framework (CMF). The use of Python's marshal module to handle uncheck…
Products.cmfcore
3.2+
HIGH 7.2
CVE-2021-32811
Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code execution security issue. In order to…
Accesscontrol
4.3 / 4.6.3+
HIGH 7.2
CVE-2021-32807
The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. Restricted code is any code th…
Accesscontrol
4.3 / 5.2+
HIGH 7.8
CVE-2021-36089
Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecompress::app…
Grok
after 9.2.0
HIGH 8.8
CVE-2021-32674
Zope is an open-source web application server. This advisory extends the previous advisory at https://github.com/zopefoundation/Zope/security/advisor…
Zope
4.6.1 / 5.2.1+
MEDIUM 5.3
CVE-2021-21360
Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem artifacts. In Products.GenericSet…
Products.genericsetup
2.1.1+
MEDIUM 6.5
CVE-2021-21336
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 t…
Products.pluggableauthservice
2.6.0+
MEDIUM 6.1
CVE-2021-21337EPSS 8%
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 t…
Products.pluggableauthservice
2.6.1+
MEDIUM 6.1
CVE-2011-4924
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x be…
Zope
2.8.12 / 2.9.12+
MEDIUM 6.1
CVE-2009-5145
Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2.10.7, 2.10.6, 2.10.5, 2.10.4…
Zope
Patch available
MEDIUM 6.0
CVE-2009-2701
Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x…
Zodb
Patch available
HIGH 7.5
CVE-2009-0669
Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to bypass a…
Zodb
after 3.8.1
MEDIUM 6.5
CVE-2009-0668
Unspecified vulnerability in Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows…
Zodb
after 3.8.1
MEDIUM 5.0
CVE-2006-4684
The docutils module in Zope (Zope2) 2.7.0 through 2.7.9 and 2.8.0 through 2.8.8 does not properly handle web pages with reStructuredText (reST) marku…
Zope
Patch available
HIGH 7.5
CVE-2002-0688
ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and ca…
Zope
Patch available
MEDIUM 5.0
CVE-2002-0687
The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.
Zope
after 2.5.1b1
HIGH 7.5
CVE-2002-0170
Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violat…
Zope
Patch available
HIGH 7.5
CVE-2001-1227
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute o…
Zope
Patch available
HIGH 7.5
CVE-2001-1278
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute o…
Zope
Patch available
MEDIUM 5.0
CVE-2000-1212
Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privile…
Zope
Patch available
HIGH 7.5
CVE-2000-1211
Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which c…
Zope
Patch available
HIGH 7.2
CVE-2000-0725
Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying …
Zope
Patch available
HIGH 10.0
CVE-2000-0062
The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.
Zope
No fix yet