VulnScope — package-centric CVE lookup- MEDIUM5.4CVE-2026-6269Incorrect Authorization in GitLab
- LOW3.1CVE-2026-3553Incorrect Authorization in GitLab
- MEDIUM6.5Allocation of Resources Without Limits or Throttling in GitLab
- MEDIUM4.3Improper Restriction of Rendered UI Layers or Frames in GitLab
- MEDIUM6.8File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
- MEDIUM6.5File Browser has a DoS Vulnerability via Public Login API
- MEDIUM6.9Netty is a network application framework for development of protocol servers and clients.
- MEDIUM4.8Netty is a network application framework for development of protocol servers and clients.
- MEDIUM5.3Netty is a network application framework for development of protocol servers and clients.
- MEDIUM6.7A flaw was found in QEMU's virtio-blk device.
- MEDIUM5.3OpenTelemetry-cpp is the C++ implementation of OpenTelemetry.
- MEDIUM6.5Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint
- MEDIUM6.5Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint
- MEDIUM5.4Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
- MEDIUM5.3Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations.
- MEDIUM5.9Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks.
- LOW3.7Tornado has out-of-bounds memory access via C extension
- MEDIUM5.9gorest InMemorySecret2FA race condition allows process crash via concurrent map access (CWE-362)
- CRITICAL9.0Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
- MEDIUM6.5Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
- MEDIUM6.5GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
- MEDIUM6.7LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access
- MEDIUM4.3Improper Neutralization of Substitution Characters in GitLab
- MEDIUM6.5Server-Side Request Forgery (SSRF) in GitLab
- LOW3.7Authorization Bypass Through User-Controlled Key in GitLab