VulnScope — package-centric CVE lookup
LOW2.2 CVE-2026-12567 BBOT: Symlink-Following Arbitrary Write via github_workflows Module 6/18/2026 LOW3.1 BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing 6/18/2026 CRITICAL9.8 python-statemachine SCXML <data expr> Eval Injection 6/18/2026 CRITICAL9.3 Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak 6/17/2026 CRITICAL9.1 Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory 6/17/2026 CRITICAL9.1 Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks 6/17/2026 CRITICAL9.8 Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure 6/17/2026 CRITICAL9.8 Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API 6/16/2026 CRITICAL9.1 vLLM: OpenAI auth bypass 6/16/2026 CRITICAL9.6 Langflow: Unauthenticated RCE in Shareable Playgrounds 6/16/2026 LOW3.7 Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname 6/15/2026 LOW3.7 python-multipart: Negative Content-Length in parse_form buffers the entire body in memory 6/15/2026 LOW3.7 python-multipart: Semicolon treated as querystring field separator enables parameter smuggling 6/15/2026 LOW3.7 python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters 6/15/2026 LOW3.7 Tornado has out-of-bounds memory access via C extension 6/12/2026 CRITICAL9.1 Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token 6/11/2026 CRITICAL9.8 MariaDB: mysql_real_escape_string() incorrectly handled big5 6/7/2026 LOW3.1 Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known 6/5/2026 LOW3.1 Bugsink: Issue event views can show an event from another project if its UUID is known 6/5/2026 CRITICAL9.1 NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker) 6/5/2026 CRITICAL9.1 Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user pattern 6/5/2026 LOW2.5 A security flaw has been discovered in gradio-app gradio 6.14.0. 6/4/2026 CRITICAL9.8 Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids Bypass 6/3/2026 LOW3.7 daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processi… 6/3/2026 CRITICAL9.6 praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members 6/1/2026