Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
CVE-2026-73500
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
CVE-2026-73502
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
CVE-2026-73499
etcd: Watch API authorization bypass via open-ended range requests
CVE-2026-73505
Oh My Posh: Arbitrary command execution via template injection in the path segment
CVE-2026-73506
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
CVE-2026-69160
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
CVE-2026-73509
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
CVE-2026-73564
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
CVE-2026-62323
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored
CVE-2026-57497
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules
CVE-2026-55502
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials
CVE-2026-55499
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activi...
CVE-2026-55497
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
CVE-2026-55496
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails
CVE-2026-55495
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
Showing 1 - 20 of 1,000+ results