Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker
Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass
Traefik before v2.11.55 Authentication Bypass via digestAuth
Malicious code in qoeoe (PyPI)
Malicious code in astlsi (PyPI)
AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes
@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target
Malicious code in tailwind-contact-forms (npm)
ACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' Parameter
Malicious code in box-sign-client-poc (npm)
Malicious code in box-sign-client (npm)
Malicious code in claude-channel-discord (npm)
Malicious code in real-router-telemetry (npm)
Malicious code in line-through (npm)
XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259)
XING CPTrans-ME-X contains a Use of Default Password (CWE-1393)
XING CPTrans-ME-X contains an OS Command Injection (CWE-78)
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView
Malicious code in taskforge-9xv (npm)
Malicious code in taskforge-8xv (npm)
Showing 1 - 20 of 1,000+ results