Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Odh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-token without origin validation
DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration
Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
Origin Validation Error in X-Rite MA-T6
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
Lightpanda:URL parser misidentifies page origin for URLs containing @ in the path - Same-Origin Policy bypass
Lightpanda: fetch() and XMLHttpRequest attach session cookies to cross-origin requests regardless of credentials mode
AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
Windows Network Address Translation (NAT) Spoofing Vulnerability
In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all reque...
In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not va...
ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
Showing 1 - 20 of 1,000+ results