Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algorithms
Grav Flex-Objects < 1.4.3 Authorization Bypass via API
.NET Security Feature Bypass Vulnerability
Silent channel-binding authentication downgrade via unsupported certificate algorithms
Apache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default config...
Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing
OpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event Handlers
Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at boot
Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at boot
MCP Registry: OCI ownership validation fails open on upstream rate limits, allowing attacker-controlled package claims
net-imap vulnerable to STARTTLS stripping via invalid response timing
OpenClaw < 2026.4.8 - strictInlineEval Approval Boundary Bypass via Approval-Timeout Fallback
OpenClaw < 2026.3.31 - Fail-Open Security Scan Bypass in Plugin Installation
OpenClaw < 2026.3.31 - Decompression Bomb Denial of Service via Image Pixel-Limit Guard Bypass
OpenViking < 0.3.9 Authentication Bypass via VikingBot OpenAPI
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions
Showing 1 - 20 of 1,000+ results