Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Rate-limit Bypass in zenml-io/zenml
Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension
Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension
Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager
DNS Cookie bypass when combined with proxy-protocol use
Multi Factor Auth Bypass
Kronosnet: kronosnet: access control list bypass via link id spoofing on unencrypted dynamic links
AstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing
OpenClaw MS Teams < 2026.5.12 Authorization Bypass
Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account takeover (incl. admin)
9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
Symfony: Identity Spoofing via Unanchored DN Regex in X509Authenticator
Symfony: Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via sessio...
Missing ID token claim validation in ueberauth_apple allows account takeover
HedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofing
PraisonAI AgentMail before 4.6.78 Message Injection via Webhook
9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs
Showing 1 - 20 of 1,000+ results