Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Rate-limit Bypass in zenml-io/zenml
Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension
Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension
Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager
DNS Cookie bypass when combined with proxy-protocol use
Multi Factor Auth Bypass
Kronosnet: kronosnet: access control list bypass via link id spoofing on unencrypted dynamic links
AstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing
OpenClaw MS Teams < 2026.5.12 Authorization Bypass
Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account takeover (incl. admin)
9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
Symfony: Identity Spoofing via Unanchored DN Regex in X509Authenticator
Symfony: Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay
In Roundcube Webmail before 1
Missing ID token claim validation in ueberauth_apple allows account takeover
HedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofing
PraisonAI AgentMail before 4.6.78 Message Injection via Webhook
9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs
Showing 1 - 20 of 1,000+ results