Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Cosign verification accepts any valid Rekor entry under certain conditions
Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com
cpp-httplib Untrusted HTTP Header Handling: Internal Header Shadowing (REMOTE*/LOCAL*)
OrangeHRM is Vulnerable to Account Takeover Through Unvalidated Username in Password Reset Workflow
Unauthenticated Arbitrary File Upload (upgrade_contents.php)
CGGMP24 is missing a check in the ZK proof used in CGGMP21
Subscriptions & Memberships for PayPal <= 1.1.7 - Unauthenticated Fake Payment Creation
eGovFramework <= 4.3.1 Unauthenticated Encryption Oracle via Web Editor Image Upload Endpoints
D-Link DAP-2695 Firmware Update sub_40C6B8 signature verification
Intent Abuse in Google Messages for Wear OS for Silent Message Sending
chatwoot Widget IFrameHelper.js initPostMessageCommunication origin validation
Rancher CLI SAML authentication is vulnerable to phishing attacks
Rapid7 AppSpider Project Name Validation Bypass
Formbricks missing JWT signature verification
Authlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass)
matrix-js-sdk has insufficient validation when considering a room to be upgraded by another
Belkin AX1800 Firmware Update data authenticity
Tenda G1 Firmware Update check_upload_file data authenticity
Tenda AC15 Firmware Update check_fw data authenticity
D-Link DIR-619L boa FirmwareUpgrade data authenticity
Showing 1 - 20 of 1,000+ results