Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Hulumi: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture
Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name
DOMPurify before 3.4.9 Trusted Types Policy State Contamination
Klever-Go KVM read-only execution can commit contract delete and upgrade side effects
PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)
HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing
CrowdSec AppSec silently drops request body for chunked / HTTP-2 requests
Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability
Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name
Twig: Sandbox property and method bypass via object-destructuring assignment
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
.NET Framework Remote Code Execution Vulnerability
Visual Studio Remote Code Execution Vulnerability
Showing 1 - 20 of 1,000+ results