Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
BigBlueButton: Insecure Randomness allows to guess user's conference session token and impersonate them
AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
zcaceres markdownify-mcp webpage-to-markdown Markdownify.ts saveToTempFile random values
Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery
Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG
Account Takeover via Predictable SSO Ticket Generation
Netty QUIC stateless reset token material exposed through header-visible connection IDs
Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
In Spring AMQP sequential correlation IDs enable reply poisoning on fixed reply queues
Spring Framework Predictable Session ID in WebSocket Module
netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures
Permissive TrustAllCerts TLS Verification
Predictable afpd session token
Magento LTS: Weak API Session ID — Predictable MD5 of Time-Derived Inputs
RELATE: Predictable Token Generation in auth.py and exam.py
chatchat-space Langchain-Chatchat Uploaded File openai_routes.py _get_file_id random values
Values produced by ${random.value} are not suitable for use as secrets
FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Brute Force
DNN has same HostGUID for all new installs
Chamilo LMS has Weak REST API Key Generation (Predictable)
Showing 1 - 20 of 1,000+ results