Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Multiple vulnerabilities in Ghost Robotics' Vision 60
lakeFS Unauthenticated Operator Metadata Overwrite via setup_comm_prefs
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known
Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation
APIFold Vulnerable to Unauthenticated Webhook Event Injection
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder
n8n before 2.28.0 Authentication Bypass via test-webhook
Feedbin Unauthenticated Entry Content Disclosure via GET /api/v2/entries/:id/text
Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secrets
PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection
AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)
xrdp: No authentication required with Xvnc backend on RHEL 9
WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration
HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form context
SurrealDB before 3.1.0 Session Hijacking via /rpc sessions
Showing 1 - 20 of 1,000+ results