Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the c...
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
@hapi/wreck : Sensitive `Proxy-Authorization` header leaked across cross-hostname redirects
OpenClaw < 2026.5.28 Bot Framework SSRF via serviceUrl Parameter Validation
OpenClaw < 2026.5.27 Token Leakage via MS Teams Outbound Requests
OpenClaw < 2026.6.5 Authorization Header Forwarding via SSE
Credential exposure in ICU Scandinavia Boomerang
CAI Content Credentials | Insufficiently Protected Credentials (CWE-522)
GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats
Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
Insufficiently Protected Credentials in GitLab
Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they...
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
uniFLOW Universal Login Manager (ULM) Standalone Improper Protection of Sensitive Information Leads to Information Disclosure
Parseable < 2.9.2 - Cleartext Credential Exposure in Notification Target API
Showing 1 - 20 of 1,000+ results