VulnScope — 以套件為主體的 CVE 查詢工具- LOW3.7CVE-2026-43514EPSS 0.10%Apache Tomcat: AJP secret compared in non-constant time
- LOW3.7EPSS 0.05%Micronaut has Unbounded `bundleCache` in `ResourceBundleMessageSource` that Allows Memory Exhaustion via `Accept-Language` Header
- LOW2.4EPSS 0.03%Geyser Vulnerable to Server-Side Request Forgery (SSRF) via Player Head Texture URL in Geyser
- LOW3.7EPSS 0.07%xxl-job has a Resource Injection issue
- LOW3.7EPSS 0.06%Spring gRPC AuthenticationException messages are reflected to remote client
- LOW3.7EPSS 0.07%Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
- LOW3.7EPSS 0.01%Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claim
- LOW3.1EPSS 0.01%Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
- LOW3.7EPSS 0.02%Keycloak's identity-first login flow exposes user information
- LOW2.6EPSS 0.09%Spring MVC and WebFlux has Server Sent Event stream corruption
- LOW3.1EPSS 0.01%Keycloak vulnerable to authorization bypass via the Admin API
- LOW2.7EPSS 0.01%Keycloak: Information disclosure of disabled user attributes via administrative endpoint
- LOW3.7EPSS 0.14%org.eclipse.jetty:jetty-http has different parsing of invalid URIs
- LOW3.1EPSS 0.01%Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
- LOW3.3EPSS 0.01%Snowflake JDBC Driver is Vulnerable to Uncontrolled Resource Consumption through SdkProxyRoutePlanner
- LOW3.8EPSS 0.03%Keycloak: Missing Check on Disabled Client for Docker Registry Protocol
- LOW3.7EPSS 0.16%Apache Tomcat: Security constraint bypass with HTTP/0.9
- LOW2.5EPSS 0.01%Apache Shiro Affected by an Observable Timing Discrepancy Vulnerability
- LOW2.7EPSS 0.01%Keycloak Server-Side Request Forgery (SSRF) vulnerability
- LOW2.7EPSS 0.01%Keycloak Admin API allows an administrator with limited privileges to retrieve sensitive custom attributes
- LOW3.1EPSS 0.02%Keycloak's missing timestamp validation allows attackers to extend SAML response validity periods
- LOW3.7EPSS 0.04%Apache Karaf Decanter has Deserialization of Untrusted Data in its Log Socket Collector
- LOW2.7EPSS 0.01%Keycloak Admin REST API exposes backend schema and rules
- LOW3.1EPSS 0.01%Keycloak does not validate and update refresh token usage atomically
- LOW3.7EPSS 0.01%Keycloak has an improper input validation vulnerability