VulnScope — package-centric CVE lookup- HIGH7.5CVE-2026-55091flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key
- —@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument
- MEDIUM6.5UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
- —Python Liquid: Infinite loop when parsing malformed `{% case %}` tags
- —parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
- HIGH7.1jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
- —jupyterlab-git extension: Stored XSS leading to RCE
- HIGH7.5Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
- HIGH7.6Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
- —containerd CRI checkpoint restore CDI annotation smuggling
- —Arbitrary host CRI log file read via symlink following in CRI checkpoint restore
- —containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
- —containerd: CRI checkpoint import allows local image tag poisoning
- —containerd image-triggered runtime DoS via unbounded group parsing
- HIGH8.0py7zr: Arbitrary File Write Vulnerability
- —In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period.
- —In the Linux kernel, the following vulnerability has been resolved: ip6_vti: set netns_immutable on the fallback device.
- —In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible If IB_MR_R…
- HIGH7.3Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
- HIGH8.8CedarJava has policy injection vulnerability
- HIGH8.8CedarJava has type confusion vulnerability
- MEDIUM5.8guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
- MEDIUM5.9guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
- MEDIUM5.3NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)
- HIGH8.3libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sf…
← PrevPage 2 of 2504Next →