Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
BIG-IP httpd access control vulnerability
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage
Beckhoff: Performing privileged operations and gaining administrator access
BullWall Ransomware Containment hard-coded folder exclusions
In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date
Unauthenticated log access in Twonky Server
The Dyson MQTT server (2022 and possibly later) allows publications and subscriptions by a client that has the correct values of AWS_ACCESS_KEY_ID,...
Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network
Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP...
An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a device o...
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv)
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote...
In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the s...
xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF
IBM Personal Communications command execution
Unprotected alternative channel of return branch target prediction in some Intel(R) Processors may allow an authorized user to potentially enable i...
Showing 1 - 20 of 1,000+ results