VulnScope — 以套件為主體的 CVE 查詢工具
LOW2.2 CVE-2026-12567 BBOT: Symlink-Following Arbitrary Write via github_workflows Module 2026/6/18 LOW3.1 BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing 2026/6/18 LOW2.2 Pi Agent: Race condition in Pi auth.json writes could expose stored credentials 2026/6/17 LOW2.5 Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass 2026/6/16 LOW3.7 Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname 2026/6/15 LOW3.7 python-multipart: Negative Content-Length in parse_form buffers the entire body in memory 2026/6/15 LOW3.7 python-multipart: Semicolon treated as querystring field separator enables parameter smuggling 2026/6/15 LOW3.7 python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters 2026/6/15 LOW3.1 React Router: Potential CSRF via PUT/PATCH/DELETE document requests 2026/6/15 LOW3.2 @babel/core: Arbitrary File Read via sourceMappingURL Comment 2026/6/15 LOW3.7 Tornado has out-of-bounds memory access via C extension 2026/6/12 LOW3.5 Papra HTTP redirect bypass can lead to SSRF via webhook delivery system 2026/6/10 LOW3.7 Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provid… 2026/6/9 LOW3.7 Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup… 2026/6/9 LOW3.1 Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known 2026/6/5 LOW3.1 Bugsink: Issue event views can show an event from another project if its UUID is known 2026/6/5 LOW2.5 A security flaw has been discovered in gradio-app gradio 6.14.0. 2026/6/4 LOW3.7 daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processi… 2026/6/3 LOW3.1 EPSS 0.04% Apache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log access 2026/6/1 LOW3.7 Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix 2026/5/29 LOW3.1 7-Zip is a file archiver with a high compression ratio. 2026/5/29 LOW3.3 Dulwich doesn't sanitize commit subjects in `porcelain.format_patch` 2026/5/29 LOW3.7 EPSS 0.06% PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) 2026/5/28 LOW3.3 EPSS 0.01% pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams 2026/5/28 LOW2.0 NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation 2026/5/21