Search across all tracked vulnerability databases
Browse and filter security vulnerabilities across ecosystems
CVE-2025-68113
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
CVE-2025-48044
Ash has authorization bypass when bypass policy condition evaluates to true
CVE-2025-48043
Ash Framework: Filter authorization misapplies impossible bypass/runtime policies
CVE-2025-48042
Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden
CVE-2025-4754
ash_authentication_phoenix has Insufficient Session Expiration
CVE-2025-3864
Hackney fails to properly release HTTP connections to the pool
CVE-2025-32782
ash_authentication has email link auto-click account confirmation vulnerability
CVE-2025-25202
Ash Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install`
CVE-2025-1211
Server-side Request Forgery (SSRF) in hackney
CVE-2024-51988
RabbitMQ HTTP API's queue deletion endpoint does not verify that the user has a required permission
CVE-2024-49756
In AshPostgres, empty, atomic, non-bulk actions, policy bypass for side-effects vulnerability.
CVE-2024-31209
OpenID Connect client Atom Exhaustion in provider configuration worker ets table location
CVE-2023-50966
erlang-jose vulnerable to denial of service via large p2c value
CVE-2024-25718
Samly access control vulnerability
CVE-2023-5588
Pleroma Path Traversal vulnerability
CVE-2023-45312
MTProto proxy remote code execution vulnerability
CVE-2023-42446
Pow Mnesia cache doesn't invalidate all expired keys on startup
CVE-2023-35174
Livebook Desktop's protocol handler can be exploited to execute arbitrary command on Windows
CVE-2017-20166
Ecto lacks a protection mechanism
CVE-2021-46871
phoenix_html allows Cross-site Scripting in HEEx class attributes
Showing 1 - 20 of 1,000+ results