Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension
Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions
Directus: Authorization-dependent response served from unsegmented cache key
PAN-OS: Information Disclosure Vulnerability in Management Web Interface
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Potential exposure of private data via cached Set-Cookie response
API Platform Core: Cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure
Angular: Request Credential & Cache Policy Stripping in Angular Service Worker
Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities
Angular: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache
undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
Improper Search Cache Isolation for Scoped Search API Keys in Typesense
Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux
Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddleware
Discourse: Cached outdated summaries can leak removed content
Hono: Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage
Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware
Static resource cache poisoning in Spring MVC and WebFlux
Showing 1 - 20 of 1,000+ results