VulnScope — package-centric CVE lookup- MEDIUM6.5CVE-2025-58175GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
- MEDIUM5.3netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
- MEDIUM6.5In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
- MEDIUM5.3Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
- MEDIUM6.8Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
- MEDIUM4.0Netty: Unix-socket fd receive leaks descriptors when peer sends two at once
- MEDIUM6.5epa4all-client: Unauthenticated REST API for Patient Record Writes
- CRITICAL9.1Yamcs Vulnerable to Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
- CRITICAL9.8Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm override
- CRITICAL9.1Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
- MEDIUM6.5Yamcs has No Rate Limiting on Authentication Endpoint
- MEDIUM4.3Yamcs vulnerable to unauthorized user enumeration via IAM API endpoints
- MEDIUM4.3Yamcs Vulnerable to LDAP Injection in LdapAuthModule
- MEDIUM6.4Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromise
- MEDIUM5.5fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode
- CRITICAL9.6GlassFish's gadget handler is vulnerable to RCE
- CRITICAL9.1GlassFish's Administration Console is Vulnerable to RCE
- CRITICAL9.8Camel-CXF and Camel-Knative Message Header are Vulnerable to Injection via Missing Inbound Filtering
- MEDIUM6.8Keycloak: Unauthorized account takeover via WebAuthn token replay
- MEDIUM6.5Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass
- MEDIUM4.9Keycloak: Information Disclosure via evaluate-scopes Admin API
- MEDIUM5.4Keycloak: Revoked Tokens Can Remain Active When Both Realm-Level and Client-Level `notBefore` Revocation Policies are Configured
- MEDIUM4.3Keycloak: Policy bypass during WebAuthn credential registration via client-side JavaScript manipulation
- MEDIUM5.3EPSS 0.06%OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation
- MEDIUM5.3EPSS 0.13%Apache Commons Configuration: StackOverflowError for YAML input with cycles