VulnScope — package-centric CVE lookup- HIGH8.2CVE-2026-54271protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names
- HIGH7.5protobufjs: Denial of service through unbounded Any expansion during JSON conversion
- HIGH8.2tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template
- HIGH7.5ws: Memory exhaustion DoS from tiny fragments and data chunks
- HIGH7.5form-data: CRLF injection in form-data via unescaped multipart field names and filenames
- HIGH8.1Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
- HIGH7.5Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
- HIGH7.7Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection
- HIGH7.3Vim is an open source, command line text editor.
- HIGH7.5Vim is an open source, command line text editor.
- HIGH7.1WsgiDAV encoded dot segments can escape filesystem share roots
- HIGH7.5@grpc/grpc-js: A malformed request can cause a server crash
- HIGH7.5@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
- HIGH8.8OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts.uri
- HIGH8.1Litestar has HTML Injection Through its CSRF Token
- HIGH7.5Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied i…
- HIGH7.5Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause…
- HIGH7.5Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen str…
- HIGH7.5Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with…
- HIGH7.4Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentic…
- HIGH7.5Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frame…
- HIGH8.1Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap…
- HIGH8.2FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response reading
- HIGH8.0MariaDB server is a community developed fork of MySQL server.
- HIGH8.0MariaDB server is a community developed fork of MySQL server.
← PrevPage 2 of 213Next →