VulnScope — 以套件為主體的 CVE 查詢工具- LOW3.7CVE-2026-40969EPSS 0.06%Spring gRPC AuthenticationException messages are reflected to remote client
- LOW3.7EPSS 0.07%Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
- LOW2.7EPSS 0.01%Langflow has an Information Leak through Incomplete API Key Redaction
- LOW3.7EPSS 0.11%Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1
- LOW3.1EPSS 0.03%langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding
- LOW3.1EPSS 0.01%Weblate: Improper access control for pending tasks in API
- LOW3.5EPSS 0.03%OpenStack Keystone: Restricted application credentials can create EC2 credentials
- LOW2.7EPSS 0.01%Privilege abuse in ModelAdmin.list_editable
- LOW3.7EPSS 0.01%Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claim
- LOW2.7EPSS 0.01%Nautobot: Management of users via REST API does not apply configured password validators
- LOW3.1EPSS 0.01%Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories
- LOW3.1EPSS 0.01%Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
- LOW3.7EPSS 0.02%Keycloak's identity-first login flow exposes user information
- LOW3.3EPSS 0.01%Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
- LOW2.6EPSS 0.09%Spring MVC and WebFlux has Server Sent Event stream corruption
- LOW3.6EPSS 0.02%Stored XSS in Memray-generated HTML reports via unescaped command-line metadata
- LOW3.7EPSS 0.01%Copyparty has unexpected JavaScript execution via crafted URL to folder with `.prologue.html`
- LOW3.1EPSS 0.01%Keycloak vulnerable to authorization bypass via the Admin API
- LOW2.7EPSS 0.01%Keycloak: Information disclosure of disabled user attributes via administrative endpoint
- LOW3.7EPSS 0.14%org.eclipse.jetty:jetty-http has different parsing of invalid URIs
- LOW3.7EPSS 0.01%Potential incorrect permissions on newly created file system objects
- LOW3.1EPSS 0.01%Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
- LOW3.3EPSS 0.01%Snowflake JDBC Driver is Vulnerable to Uncontrolled Resource Consumption through SdkProxyRoutePlanner
- LOW3.1EPSS 0.04%wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data
- LOW3.8EPSS 0.03%Keycloak: Missing Check on Disabled Client for Docker Registry Protocol