Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
CVE-2026-59933
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
CVE-2026-59932
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
CVE-2026-59931
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
CVE-2026-59943
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
CVE-2026-59942
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
CVE-2026-59941
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
CVE-2026-56722
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
CVE-2026-55555
Dompdf: File existence oracle via font-face stylesheet declaration
CVE-2026-55554
Dompdf: Chroot Validation Bypass
CVE-2026-59882
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
Guzzle: URI fragments disclosed in redirect Referer headers
Guzzle: Host-only cookie scope is not preserved
Guzzle: Unbounded response cookies risk denial of service
CVE-2026-59883
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
CVE-2026-59946
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
Showing 1 - 20 of 1,000+ results