VulnScope — 以套件為主體的 CVE 查詢工具
CRITICAL9.0 CVE-2026-55203 HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allo… 2026/6/18 LOW1.8 A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. 2026/6/18 HIGH8.8 An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in… 2026/6/18 HIGH7.5 Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID 2026/6/18 LOW2.2 BBOT: Symlink-Following Arbitrary Write via github_workflows Module 2026/6/18 LOW3.1 BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing 2026/6/18 HIGH8.0 Strimzi: Cross-namespace privilege escalation via `Kafka.spec.entityOperator` 2026/6/18 HIGH7.5 Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a l… 2026/6/17 HIGH7.4 undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent 2026/6/17 LOW3.7 Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. 2026/6/17 LOW3.7 Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring,… 2026/6/17 HIGH7.5 Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's orig… 2026/6/17 HIGH8.2 Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthent… 2026/6/17 HIGH7.5 HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS 2026/6/17 HIGH7.5 handlebars.java FileTemplateLoader Path Traversal 2026/6/17 HIGH7.6 LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector 2026/6/17 HIGH8.4 pdfkit: Path traversal in from_string 2026/6/17 HIGH7.7 Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects 2026/6/17 HIGH7.7 Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal 2026/6/17 HIGH7.6 Open WebUI: Stored XSS to Account Takeover via Model Profile Images 2026/6/17 HIGH7.1 Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion 2026/6/17 HIGH8.7 Open WebUI: Stored XSS in Mermaid Markdown Preview 2026/6/17 HIGH8.3 Open WebUI: Forged chat-file link allows cross-user file read and deletion 2026/6/17 HIGH8.5 Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401) 2026/6/17 LOW3.1 Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage… 2026/6/17