VulnScope — package-centric CVE lookup- MEDIUM6.5CVE-2026-48022@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
- —CVE-2026-48007Element Call reports full URLs of visited pages to analytics server
- —Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
- —PDM: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing
- —PDM wheel installation leads to Path Traversal via overridden write_to_fs
- —PDM: Project-Local State and Config Writes Follow Symlinks
- —Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload
- MEDIUM5.9Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
- HIGH8.1Litestar has HTML Injection Through its CSRF Token
- MEDIUM6.5vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
- HIGH7.5Acknowledgement extension out of memory
- HIGH8.0Jenkins: Stored XSS vulnerability in node offline cause description
- LOW3.5Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
- —@hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture
- —@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts
- —@hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened
- —@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
- —@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name
- —@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers
- HIGH8.1In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
- MEDIUM6.5In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
- MEDIUM6.3FUXA's scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions
- MEDIUM5.3FUXA has SQL Injection in its TDengine DAQ connector via backslash bypass of escapeTdString
- HIGH8.2FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response reading
- HIGH8.7Netty has Insufficient Bailiwick Validation for NS Records
← PrevPage 2 of 660Next →