VulnScope — 以套件為主體的 CVE 查詢工具- HIGH7.3CVE-2026-8771EPSS 0.04%org.linlinjava:litemall-wx-api has an Injection issue
- HIGH7.3EPSS 0.03%Beetl's SpELFunction extension function has an expression injection risk
- HIGH7.4EPSS 0.01%Improper Verification of Cryptographic Signature in com.oviva.telematik:epa4all-client
- HIGH8.1EPSS 0.07%Apache Flink: Remote code execution via SQL injection in code generation
- HIGH8.1EPSS 0.01%epa4all-client: TLS Certificate Validation Disabled in Production
- HIGH8.1EPSS 0.03%Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading
- HIGH7.5EPSS 0.08%Apache Tomcat: LockOutRealm treats user names as case-sensitive
- HIGH7.3EPSS 0.05%Apache Tomcat: WebSocket authentication header exposure
- HIGH7.5EPSS 0.05%Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
- HIGH8.2EPSS 0.04%Spring AI: Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisor
- HIGH7.5EPSS 0.04%Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage
- HIGH7.6EPSS 0.04%Valtimo has sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer
- HIGH8.6EPSS 0.03%Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs
- HIGH8.1EPSS 0.01%epa4all-client has a VAU Signature bypass
- HIGH7.5EPSS 0.01%bitcoinj has a ScriptExecution P2PKH/P2WPKH Verification Bypass
- HIGH8.8EPSS 0.02%Apache NiFi: Missing Execute Code Required Permission on TinkerpopClientService
- HIGH7.5EPSS 0.08%Alkacon OpenCms is vulnerable to XXE when the <!DOCTYPE> refers to an external host
- HIGH7.3EPSS 13.7%Alkacon OpenCms allows remote unauthenticated attackers to obtain sensitive information
- HIGH7.2EPSS 0.01%Spring Cloud Config Server Susceptible To TOCTOU Attack
- HIGH7.5EPSS 0.02%Spring Cloud Config has an Authorization Bypass Through User-Controlled Key
- HIGH7.5EPSS 0.02%Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS
- HIGH7.3EPSS 0.02%Netty has HttpClientCodec response desynchronization
- HIGH7.5EPSS 0.02%Netty Lz4FrameDecoder is vulnerable to resource exhaustion
- HIGH7.5EPSS 0.02%Netty HTTP/3 QPACK literal unbounded allocation
- HIGH7.5EPSS 0.03%Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder)