Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Loytec LWEB802: Reflected Cross-Site Scripting in LWEB802
Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA server
remorses/genql code injection
Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
Twig: The `spaceless` filter implicitly marks its output as safe
Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116)
.NET Spoofing Vulnerability
HedgeDoc: Stored HTML injection via email local-part
luci-app-banip Log Monitor IP Extraction Bypass
Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()
Grist: XSS through unsafe value interpolation in server-rendered pages
SiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer gap in Lute (form action / SVG xlink:href)
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
Email-derived URL path injection in the Swoosh Microsoft Graph adapter
Improper Output Neutralization for Logs in Kibana Leading to Log Injection
Dragonfly: RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer
SiYuan: Stored XSS results to Electron RCE in SiYuan marketplace via unescaped `data-obj` attribute (Bypass for CVE-2026-45375's patch)
Warp: OS command injection when opening terminal links from WSL
Caddy: stripHTML template function bypass
Open WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUI
Showing 1 - 20 of 1,000+ results