Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Brute Force
DNN has same HostGUID for all new installs
Chamilo LMS has Weak REST API Key Generation (Predictable)
OpenClaw < 2026.4.2 - PKCE Verifier Exposure via OAuth State Parameter
open-webui JWT Key start_windows.bat random values
XikeStor SKS8310-8X Predictable Session Identifiers
A vulnerability in the SAML 2
Gradio has Open Redirect in OAuth Flow
SODOLA SL902-SWTGW124AS <= 200.1.20 Predictable Session ID
Fleet: Device lock PIN can be predicted if lock time is known
FreeScout's Predictable Authentication Token Enables Account Takeover
Piwigo's secret key can be brute forced
Binardat 10G08-0800GSM Network Switch Predictable Session Identifiers
Cesanta Mongoose DNS Transaction ID dns.c mg_sendnsreq random values
Insecure Credential Generation for Solax Power Pocket WiFi models MQTT Cloud Connection
NervesHub has Insufficient Token Entropy that Allows Authentication Bypass via Brute Force
Jervis has a Weak Random for Timing Attack Mitigation
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.5 - Unauthenticated Sensitive Information Exposure
libtpms returns wrong initialization vector when certain symmetric ciphers are used
Login Lockdown & Protection <= 2.14 - IP Block Bypass
Showing 1 - 20 of 1,000+ results