VulnScope — package-centric CVE lookup- MEDIUM5.3CVE-2026-49342YARD is a documentation generation tool for the Ruby programming language.
- HIGH7.1libde265 is an open source implementation of the h.265 video codec.
- MEDIUM4.3libde265 is an open source implementation of the h.265 video codec.
- HIGH7.1libde265 is an open source implementation of the h.265 video codec.
- MEDIUM6.5A use-after-free vulnerability was found in FFmpeg's RASC video decoder.
- CRITICAL9.6Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
- HIGH7.5Langflow: Unauthenticated DoS through multipart form boundary file upload
- MEDIUM6.1Langflow: Logout button does not clear session
- CRITICAL9.9Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
- MEDIUM6.8dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens
- HIGH7.1A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation.
- HIGH7.6A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation.
- HIGH7.1An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation.
- HIGH7.1A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation.
- MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder.
- MEDIUM6.5UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
- HIGH7.1jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
- HIGH7.5Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
- HIGH7.6Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
- HIGH8.0py7zr: Arbitrary File Write Vulnerability
- HIGH7.3Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
- MEDIUM5.8guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
- MEDIUM5.9guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
- HIGH8.3libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sf…
- MEDIUM6.5A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.1…