Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
nextlevelbuilder GoClaw exec_approval.go extractBin name resolution
File Browser: Colliding username normalization gives two users the same home directory
OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper
Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs
Use of Incorrectly-Resolved Name or Reference in GitLab
Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allo...
Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community catal...
pyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory
Use of Incorrectly-Resolved Name or Reference in GitLab
Traefik: StripPrefixRegex auth bypass via Path/RawPath desync
OpenClaw < 2026.3.31 - Webhook Replay Cache Cross-Target messageId Scope Bypass
Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that trigge...
OpenClaw < 2026.4.2 - Insufficient Scope in Zalo Webhook Replay Dedupe Keys
uutils coreutils cp Semantic Loss and Potential Denial of Service with -R via Device Node Stream Reading
OpenFGA has Improper Policy Enforcement
OpenClaw < 2026.3.22 - Allowlist Bypass via Unregistered Time Dispatch Wrapper
OpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology Chat
fast-jwt Affected by Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup)
Showing 1 - 20 of 1,000+ results