VulnScope — package-centric CVE lookup- HIGH8.5CVE-2026-49444n8n: Python sandbox escape
- CRITICAL9.1vLLM: OpenAI auth bypass
- MEDIUM6.1Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
- CRITICAL9.6Langflow: Unauthenticated RCE in Shareable Playgrounds
- MEDIUM6.5Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
- HIGH7.5vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
- HIGH8.8Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
- MEDIUM4.2Astro: XSS via Unescaped Attribute Names in Spread Props
- HIGH7.5Astro: Host header SSRF in prerendered error page fetch
- MEDIUM5.3@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config
- HIGH7.5Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read
- MEDIUM6.5hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
- MEDIUM4.8hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
- HIGH7.1hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
- MEDIUM5.9hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
- MEDIUM5.3hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
- —pypdf: Possible infinite loop when processing outlines/bookmarks in writer
- —pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction
- HIGH7.1Astro: Reflected XSS via unescaped slot name
- —Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
- —Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
- —pypdf: Possible large memory usage for form XObjects during text extraction
- —pypdf: Inefficient decoding of FlateDecode PNG predictor streams
- HIGH7.3aws-cdk-lib: OS Command Injection in NodejsFunction Bundling
- MEDIUM5.3markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
← PrevPage 2 of 829Next →