Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
CVE-2026-32145
wisp has Allocation of Resources Without Limits or Throttling
CVE-2026-34715
ewe Has Improper Neutralization of CRLF Sequences in HTTP Headers (HTTP Request/Response Splitting)
CVE-2026-34593
Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash
CVE-2026-33872
elixir-nodejs has Cross-User Data Leakage or Information Disclosure due to Worker Protocol Race Condition
CVE-2026-28809
esaml XXE vulnerability allows local file disclosure and SSRF via crafted SAML messages
CVE-2026-32873
Loop with Unreachable Exit Condition ('Infinite Loop') in ewe
CVE-2026-32881
Permissive List of Allowed Inputs in ewe
CVE-2026-28807
Wisp Vulnerable to Path Traversal
CVE-2026-21619
hex_core has Unsafe Deserialization of Erlang Terms
CVE-2025-68113
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
CVE-2025-48044
Ash has authorization bypass when bypass policy condition evaluates to true
CVE-2025-48043
Ash Framework: Filter authorization misapplies impossible bypass/runtime policies
CVE-2025-48042
Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden
CVE-2025-4754
ash_authentication_phoenix has Insufficient Session Expiration
CVE-2025-3864
Hackney fails to properly release HTTP connections to the pool
CVE-2025-32782
ash_authentication has email link auto-click account confirmation vulnerability
CVE-2025-25202
Ash Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install`
CVE-2025-1211
Server-side Request Forgery (SSRF) in hackney
CVE-2024-51988
RabbitMQ HTTP API's queue deletion endpoint does not verify that the user has a required permission
CVE-2024-49756
In AshPostgres, empty, atomic, non-bulk actions, policy bypass for side-effects vulnerability.
Showing 1 - 20 of 1,000+ results