Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints
Keycloak: keycloak: uma policy bypass allows authenticated users to gain unauthorized access to victim-owned resources.
ZKTeco ZKBioSecurity 3.0 User Enumeration via authLoginAction
Keycloak: keycloak authorization header parsing leading to potential security control bypass
URI validation failure on SVG parsing in Dompdf
Junos OS: SRX Series: Under a specific device configuration an attacker can access the devices J-Web management services from any interface, regard...
Incorrectly handling of URI '#fragment' element as part of the path element
Incorrect concatenation of multiple value request headers in ext-authz extension
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of...
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to...
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS...