VulnScope — 以套件為主體的 CVE 查詢工具- LOW3.7CVE-2026-49854Tornado has out-of-bounds memory access via C extension
- MEDIUM6.5CVE-2025-58175GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
- HIGH7.2GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
- HIGH7.3Vim is an open source, command line text editor.
- HIGH7.5Vim is an open source, command line text editor.
- MEDIUM6.9Vim is an open source, command line text editor.
- HIGH7.2GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
- HIGH7.1WsgiDAV encoded dot segments can escape filesystem share roots
- —Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
- MEDIUM5.8Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset
- MEDIUM6.5python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood
- MEDIUM5.3netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
- —netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access
- CRITICAL9.1Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
- —Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
- —PDM: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing
- —PDM wheel installation leads to Path Traversal via overridden write_to_fs
- —PDM: Project-Local State and Config Writes Follow Symlinks
- MEDIUM5.9Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
- HIGH8.1Litestar has HTML Injection Through its CSRF Token
- MEDIUM6.5vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
- HIGH7.5Acknowledgement extension out of memory
- HIGH8.0Jenkins: Stored XSS vulnerability in node offline cause description
- HIGH8.1In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
- MEDIUM6.5In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header