VulnScope — 以套件為主體的 CVE 查詢工具- LOW3.7CVE-2025-11143EPSS 0.14%org.eclipse.jetty:jetty-http has different parsing of invalid URIs
- LOW3.7EPSS 0.01%Django has a Race Condition vulnerability
- LOW3.1EPSS 0.01%Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
- LOW3.3EPSS 0.01%Snowflake JDBC Driver is Vulnerable to Uncontrolled Resource Consumption through SdkProxyRoutePlanner
- LOW3.1EPSS 0.04%wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data
- LOW3.8EPSS 0.03%Keycloak: Missing Check on Disabled Client for Docker Registry Protocol
- LOW3.7EPSS 0.16%Apache Tomcat - Security constraint bypass with HTTP/0.9
- LOW3.7EPSS 0.02%LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
- LOW2.5EPSS 0.01%Apache Shiro Affected by an Observable Timing Discrepancy Vulnerability
- LOW2.7EPSS 0.01%Keycloak Server-Side Request Forgery (SSRF) vulnerability
- LOW2.7EPSS 0.01%Keycloak Admin API allows an administrator with limited privileges to retrieve sensitive custom attributes
- LOW3.2EPSS 0.01%Llama Stack exposes secret in initialization log
- LOW3.1EPSS 0.02%Keycloak's missing timestamp validation allows attackers to extend SAML response validity periods
- LOW3.7EPSS 0.04%Apache Karaf Decanter has Deserialization of Untrusted Data in its Log Socket Collector
- LOW3.7EPSS 0.07%FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detection
- LOW2.7EPSS 0.01%Keycloak Admin REST API exposes backend schema and rules
- LOW3.1EPSS 0.01%Keycloak does not validate and update refresh token usage atomically
- LOW3.7EPSS 0.01%Keycloak has an improper input validation vulnerability
- LOW2.5EPSS 0.01%Weblate command-line client susceptible to SSL verification skip
- LOW3.3EPSS 0.01%AcademySoftwareFoundation OpenColorIO has an out-of-bounds vulnerability
- LOW3.3EPSS 0.01%LIEF is vulnerable to segmentation fault
- LOW3.5EPSS 0.04%Jenkins has a CSRF vulnerability on the login form
- LOW2.7EPSS 0.01%Keycloak Admin REST (Representational State Transfer) API does not properly enforce permissions
- LOW3.7EPSS 0.01%Keycloak unable to restrict access to the admin console
- LOW3.6EPSS 0.02%Spotipy has a XSS vulnerability in its OAuth callback server