VulnScope — 以套件為主體的 CVE 查詢工具
LOW2.5 CVE-2026-44969 dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled 2026/5/14 LOW2.7 EPSS 0.09% Synapse pagination Denial of Service 2026/5/14 LOW3.7 EPSS 0.01% Next.js's Middleware / Proxy redirects can be cache-poisoned 2026/5/11 LOW3.7 EPSS 0.01% Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting 2026/5/11 LOW3.8 EPSS 0.02% Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify() 2026/5/9 LOW3.3 EPSS 0.01% OSGeo GDAL vulnerable to out-of-bounds read 2026/5/7 LOW3.7 EPSS 0.04% nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect) 2026/5/7 LOW3.5 EPSS 0.04% Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed 2026/5/6 LOW3.7 EPSS 0.02% Flowise: Bcrypt Password Hash Exposure 2026/5/6 LOW3.4 EPSS 0.00% Paramiko rsakey.py allows the SHA-1 algorithm 2026/5/6 LOW3.0 EPSS 0.01% ciguard: Container image runs as root (no USER directive) 2026/5/5 LOW3.7 EPSS 0.02% ciguard: SCA HTTP client reads response body without size cap 2026/5/5 LOW3.7 EPSS 0.05% Microdot has HTTP response splitting in Response.set_cookie() 2026/5/5 LOW2.6 EPSS 0.04% Langchain-Chatchat Uses Insufficiently Random Values 2026/5/5 LOW2.6 EPSS 0.03% Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API 2026/5/5 LOW2.6 EPSS 0.01% Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm 2026/5/5 LOW3.7 EPSS 0.06% Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams 2026/5/5 LOW3.7 EPSS 0.02% A flaw was found in gnutls. 2026/4/30 LOW3.7 EPSS 0.04% A flaw was found in gnutls. 2026/4/30 LOW2.2 EPSS 0.05% Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4) 2026/4/23 LOW2.7 EPSS 0.01% Langflow has an Information Leak through Incomplete API Key Redaction 2026/4/20 LOW3.7 EPSS 0.11% Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries 2026/4/18 LOW3.1 EPSS 0.03% langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding 2026/4/16 LOW3.7 EPSS 0.03% ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint 2026/4/16 LOW3.1 EPSS 0.01% Weblate: Improper access control for pending tasks in API 2026/4/16