Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
yard: Possible arbitrary path traversal and file access via yard server
CVE-2026-27820
Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption
Malicious code in monolith-twirp-pullsd-authorization (RubyGems)
Malicious code in monolith-twirp-pullsd-users (RubyGems)
Malicious code in gitlab-orchestrator (RubyGems)
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
CVE-2026-40869
Decidim amendments can be accepted or rejected by anyone
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
CVE-2026-23891
Decidim has a cross-site scripting (XSS) in user name
CVE-2026-40069
bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts
CVE-2026-40070
bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and issuance paths)
CVE-2026-39324
Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization
CVE-2026-35611
Addressable has a Regular Expression Denial of Service in Addressable templates
CVE-2026-35201
rdiscount has an Out-of-bounds Read
CVE-2026-34835
Rack::Request accepts invalid Host characters, enabling host allowlist bypass
CVE-2026-34831
Rack has Content-Length mismatch in Rack::Files error responses
CVE-2026-34830
Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect
Showing 1 - 20 of 1,000+ results