Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Kavita: Pre-Auth Account Takeover
NousResearch hermes-agent CLI web-dashboard web_server.py _discover_dashboard_plugins comparison
Pingvin Share X: TOTP Authentication Bypass via Password-only Login
fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
Parse Server: Session field immutability bypass via falsy-value guard
mppx has Stripe charge credential replay via missing idempotency check
soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
httpsig-hyper has Improper Digest Verification that May Allow Message Integrity Bypass
iccDEV has Type Confusion in CIccTag:IsTypeCompressed()
Cisco Identity Services Engine Radius Suppression Denial of Service Vulnerability
The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure
ConsoleFindCommandMatchList
HuangDou UTCMS Login login.php comparison
NetAlertX has Password Bypass Vulnerability due to Loose Comparison in PHP
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
Issuer field partial matches allowed in pyjwt
Junos OS Evolved: Connections to the network and broadcast address accepted
Two-Factor Authentication (2FA) Bypass in mailcow: dockerized
Softaculous Webuzo Authentication Bypass
Authentication Bypass when using using older password hashes
Showing 1 - 20 of 1,000+ results