Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)
Ella Core: Unauthenticated AMF DoS via malformed InitialUEMessage with undersized integrity-protected NAS payload
Inappropriate implementation in V8 in Google Chrome prior to 146
Out of bounds write in Skia in Google Chrome prior to 146
OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")
OpenClaw: Untrusted web origins can obtain authenticated operator.admin access in trusted-proxy mode
Stable Channel Update for Desktop
Anchore Enterprise GraphQL Reports API SQL injection
undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid server_max_window_bits Validation
undici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and crashes the client
undici is vulnerable to Unbounded Memory Consumption in undici WebSocket permessage-deflate Decompression
Black: Arbitrary file writes from unsanitized user input in cache file name
Command Injection via incomplete shell metacharacter blocklist in node:child_process (bypass of CVE-2026-27190 fix)
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint
NEXULEAN API Key Leak
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
flatted: Unbounded recursion DoS in parse() revive phase
Poseidon V1 variable-length input collision via implicit zero-padding
Showing 1 - 20 of 1,000+ results