VulnScope — package-centric CVE lookup- LOW2.2CVE-2026-12567BBOT: Symlink-Following Arbitrary Write via github_workflows Module
- LOW3.1BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
- LOW3.7undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
- LOW3.7undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
- LOW2.2Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
- LOW2.5Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
- LOW3.7Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
- LOW3.7python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
- LOW3.7python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
- LOW3.7python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
- LOW3.1React Router: Potential CSRF via PUT/PATCH/DELETE document requests
- LOW3.2@babel/core: Arbitrary File Read via sourceMappingURL Comment
- LOW3.7Tornado has out-of-bounds memory access via C extension
- LOW3.5Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
- LOW3.7Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provid…
- LOW3.7Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup…
- LOW3.1Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known
- LOW3.1Bugsink: Issue event views can show an event from another project if its UUID is known
- LOW2.5A security flaw has been discovered in gradio-app gradio 6.14.0.
- LOW3.7daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processi…
- LOW3.1EPSS 0.04%Apache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log access
- LOW3.7Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
- LOW3.17-Zip is a file archiver with a high compression ratio.
- LOW3.3Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`
- LOW3.7EPSS 0.06%PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)