Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Wavlink WL-WN579A3 POST Request wireless.cgi GuestWifi command injection
Malicious code in test_pkg_forppe (npm)
OpenClaw: WebSocket shared-auth connections could self-declare elevated scopes
CVE-2026-32621
Apollo Federation vulnerable to prototype pollution via incomplete key sanitization
claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability
Malicious code in devlino (npm)
Apollo Federation has prototype pollution via incomplete key sanitization
Malicious code in fastapi-middleware-cors (PyPI)
AnythingLLM has a Streaming Phase XSS to RCE via LLM Response Injection
CVE-2026-32301
Centrifugo: SSRF via unverified JWT claims interpolated into dynamic JWKS endpoint URL
CVE-2026-32306
OneUptime ClickHouse SQL Injection via Aggregate Query Parameters
Dagu has a Path Traversal via `dagRunId` in Inline DAG Execution
FreeRDP has a Heap Buffer Overflow in nsc_process_message() via Unchecked SURFACE_BITS_COMMAND Bitmap Dimensions
telnetd in GNU inetutils through 2
CVE-2026-32304
Locutus vulnerable to RCE via unsanitized input in create_function()
CVE-2026-32614
SM9 Infinity-Point Ciphertext Forgery Vulnerability
SandboxJS has a Sandbox Escape
OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE
OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes
CVE-2026-31886
Dagu: Path Traversal via `dagRunId` in Inline DAG Execution
Showing 1 - 20 of 1,000+ results