Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow
Sipeed PicoClaw context.go NewContextBuilder inclusion of functionality from untrusted control sphere
ForgeCode Arbitrary Code Execution via Unvetted .mcp.json in Untrusted Repository
OpenClaw < 2026.5.22 Untrusted Plugin Loading via Setup-mode
Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Cherry Studio RCE via SearchService nodeIntegration Misconfiguration
FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows
Showing 1 - 20 of 1,000+ results