Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Penpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE
Vitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
ownCloud Core: Updater has an exposed dangerous method or function
Microsoft Edge (Chromium-based) Spoofing Vulnerability
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
Nx: `nx graph` dev server permissive CORS policy
Appsmith: Caddy admin API exposed without authentication
Postiz has an unauthenticated billing-enforcement bypass via /public/modify-subscription
@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incom...
Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)
Hepta Platforms|Heptabase - Exposed Dangerous
A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could allow a webs...
Arbitrary File Read, Write, Rename, and Delete in Logseq
Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection
Nautobot: GitRepository.current_head field should not be writable through REST API
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1
view_component: Preview Route Can Dispatch Inherited Helper Methods
IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Auth Remote Code Execution
Arqit SKA-Platform Enables Access to Debug Information
Arqit SKA-Platform Vulnerable to Key Exposure
Showing 1 - 20 of 1,000+ results