Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
git2 has potential undefined behavior when dereferencing Buf struct
openmls has improper tag validation
CVE-2026-25541
bytes has integer overflow in BytesMut::reserve
CVE-2026-25537
jsonwebtoken has Type Confusion that leads to potential authorization bypass
CVE-2026-24762
RustFS Logs Sensitive Credentials in Plaintext
CVE-2026-21862
RustFS has SourceIp bypass via spoofed X-Forwarded-For/Real-IP headers
ml-dsa's UseHint function has off by two error when r0 equals zero
CVE-2026-24889
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
CVE-2026-24850
ML-DSA Signature Verification Accepts Signatures with Repeated Hint Indices
CVE-2026-24785
Clatter has a PSK Validity Rule Violation issue
CVE-2026-24783
soroban-fixed-point-math has Incorrect Rounding and Overflow Handling in Signed Fixed-Point Math with Negatives
Cap'n Proto has Undefined Behavior in constant::Reader and StructSchema
oneshot has potential Use After Free when used asynchronously
CVE-2026-24116
Wasmtime segfault or unused out-of-sandbox load with f64.copysign operator on x86-64
CVE-2026-22696
dcap-qvl has Missing Verification for QE Identity
CVE-2025-67124
miniserve affected by a TOCTOU and symlink race vulnerability
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
Triton VM has a Soundness Vulnerability due to Improper Sampling of Randomness
CVE-2026-22864
Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
CVE-2026-22863
Deno node:crypto doesn't finalize cipher
Showing 1 - 20 of 1,000+ results