LOW3.7EPSS 0.07%Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
LOW2.9EPSS 0.02%Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Securi…
LOW3.7EPSS 0.07%Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Librar…
LOW3.7EPSS 0.04%Vulnerability in Oracle Java SE (component: Libraries).
LOW2.9EPSS 0.02%Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Securi…
LOW2.7EPSS 0.01%Langflow has an Information Leak through Incomplete API Key Redaction
LOW3.5EPSS 0.01%libgphoto2 is a camera access and control library.
LOW2.4EPSS 0.01%libgphoto2 is a camera access and control library.
LOW3.5EPSS 0.01%libgphoto2 is a camera access and control library.
LOW3.1EPSS 0.03%langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding
LOW3.7EPSS 0.03%ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
LOW3.1EPSS 0.01%Weblate: Improper access control for pending tasks in API
LOW2.9EPSS 0.01%libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
LOW3.1EPSS 0.01%Insufficient policy enforcement in CORS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer…
LOW3.1EPSS 0.01%Insufficient policy enforcement in Passwords in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the ren…
LOW3.5EPSS 0.04%DbGate has cross site scripting via the SVG Icon String Handler component
LOW3.7EPSS 0.01%phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals()
LOW3.3EPSS 0.01%In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is exe…
LOW3.5EPSS 0.03%OpenStack Keystone: Restricted application credentials can create EC2 credentials