Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race Condition
Microsoft UFO shared WebSocket handler state causes cross-client response hijacking
Fleet Vulnerable to Windows MDM cross-device command disclosure
NATS is vulnerable to MQTT hijacking via Client ID
Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Server
Jail chroot escape via fd exchange with a different jail
Lettermint Node.js SDK leaks email properties to unintended recipients when client instance is reused
Whisper Money has IDOR Vulnerability on sync/balances endpoint
OpenProject users can delete other user's session, causing them to be logged out
SO_REUSEPORT_LB breaks connect(2) for UDP sockets
Spotipy repo vulnerable to secrets exfiltration via `pull_request_target`
cifs.upcall makes an upcall to the wrong namespace in containerized environments
Improper session handling in B&R APROL
Element Android PIN autologout bypass
Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared instance
Pgadmin: users authenticated simultaneously via ldap may be attached to the wrong session
404 Solution <= 2.35.17 - Missing Authentication to Sensitive Information Exposure
Exposure of Token in open-webui/open-webui
Gnome-remote-desktop: inadequate validation of session agents using d-bus methods may expose rdp tls certificate
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8
Showing 1 - 20 of 1,000+ results