Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
U.S. GAO EPDS and CBCA EDS network access control bypass
Traccar Client: silent configuration hijack via unverified deep link redirects all GPS telemetry
Netty's Default QUIC token handler accepts any client-supplied token
Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection
electerm: Local code through electerm's single-instance socket
Summarize < 0.15.1 Unauthorized Daemon Request via Untrusted Events
WWBN AVideo: Unauthenticated Arbitrary Email Sending via sendEmail.json.php Allows Phishing from Site's Legitimate From Address
Anviz CrossChex Standard Improper Verification of Source of a Communication Channel
OpenClaw < 2026.3.22 - Arbitrary Code Execution via Unvalidated WebView JavascriptInterface
Authenticator Vulnerable to Authentication Flow Hijack
Easy Chat Server 3.1 Denial of Service via message Parameter
Cesanta Mongoose TCP Sequence Number net_builtin.c getpeer verification of source
Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability i...
An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiO...
Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a sess...
Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowin...
SillyTavern Web Interface Vulnerable to DNS Rebinding
A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent att...
Showing 1 - 20 of 1,000+ results