Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL
Grav < 2.0.4 File Access Bypass via Case Variation
OpenFGA MySQL backend: case-insensitive collation on identifier columns causes incorrect authorization decisions
jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
Traefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
NousResearch hermes-agent Streaming Reasoning Tag Filter stream_consumer.py GatewayStreamConsumer._filter_and_accumulate case sensitivity
Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
Authelia has an Edge Case Access Control Rule Mismatch
Authelia Missing Username Canonicalization in Basic Auth (LDAP)
@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
TYPO3 CMS - Broken Access Control in Form Framework
HAX CMS PHP Has a Stored XSS via Case-Sensitivity Mismatch in HTML Upload Validation
Potential exposure of private data via case-sensitive Cache-Control directives in UpdateCacheMiddleware
Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects
Klaw: user lockout due to case sensitivity inconsistency
Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
Showing 1 - 20 of 1,000+ results