VulnScope — package-centric CVE lookup- LOW2.5CVE-2026-32970EPSS 0.02%OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode
- LOW3.1EPSS 0.01%Keycloak vulnerable to authorization bypass via the Admin API
- LOW2.7EPSS 0.01%Keycloak: Information disclosure of disabled user attributes via administrative endpoint
- LOW3.7EPSS 0.14%org.eclipse.jetty:jetty-http has different parsing of invalid URIs
- LOW2.0EPSS 0.01%@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass
- LOW2.7EPSS 0.01%Backstage vulnerable to potential reading of SCM URLs using built in token
- LOW3.7EPSS 0.04%OpenClaw has cross-account DM pairing authorization bypass via unscoped pairing store access
- LOW3.4EPSS 0.02%Dark Reader gives users the ability to request style sheets from local web servers
- LOW3.7EPSS 0.04%OpenClaw: Discord DM reaction ingress missed dmPolicy/allowFrom checks in restricted setups
- LOW3.3EPSS 0.02%@tootallnate/once vulnerable to Incorrect Control Flow Scoping
- LOW2.6EPSS 0.04%OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows
- LOW3.3EPSS 0.02%OpenClaw's Control UI Static File Handler Follows Symlinks and Allows Out-of-Root File Read
- LOW3.7EPSS 0.04%OpenClaw has Signal group allowlist authorization bypass via DM pairing-store leakage
- LOW2.2EPSS 0.01%Vim is an open source, command line text editor.
- LOW3.1EPSS 0.01%Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
- LOW3.3EPSS 0.01%Snowflake JDBC Driver is Vulnerable to Uncontrolled Resource Consumption through SdkProxyRoutePlanner
- LOW3.6EPSS 0.02%OpenClaw safeBins stdin-only bypass via sort output and recursive grep flags
- LOW3.8EPSS 0.03%Keycloak: Missing Check on Disabled Client for Docker Registry Protocol
- LOW3.7EPSS 0.16%Apache Tomcat: Security constraint bypass with HTTP/0.9
- LOW3.7EPSS 0.04%OpenClaw Affected by Remote Code Execution via System Prompt Injection in Slack Channel Descriptions
- LOW3.7EPSS 0.05%qs's arrayLimit bypass in comma parsing allows denial of service
- LOW2.9EPSS 0.01%ajv has ReDoS when using `$data` option
- LOW2.5EPSS 0.01%Apache Shiro Affected by an Observable Timing Discrepancy Vulnerability
- LOW3.7EPSS 0.01%webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior
- LOW3.7EPSS 0.01%webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence