VulnScope — 以套件為主體的 CVE 查詢工具
MEDIUM5.3 CVE-2026-42769 Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CM… 2026/6/9 HIGH7.5 Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frame… 2026/6/9 HIGH8.1 Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap… 2026/6/9 CRITICAL9.1 Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex… 2026/6/9 MEDIUM6.3 FUXA's scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions 2026/6/8 MEDIUM5.3 FUXA has SQL Injection in its TDengine DAQ connector via backslash bypass of escapeTdString 2026/6/8 HIGH8.2 FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response reading 2026/6/8 — actual Allows Electron to Run As Node 2026/6/8 MEDIUM5.4 Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type 2026/6/8 — Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews. 2026/6/8 MEDIUM4.3 MariaDB server is a community developed fork of MySQL server. 2026/6/7 MEDIUM6.3 MariaDB server is a community developed fork of MySQL server. 2026/6/7 HIGH8.0 MariaDB server is a community developed fork of MySQL server. 2026/6/7 — MariaDB server is a community developed fork of MySQL server. 2026/6/7 — MariaDB server is a community developed fork of MySQL server. 2026/6/7 HIGH8.0 MariaDB server is a community developed fork of MySQL server. 2026/6/7 HIGH8.0 MariaDB server is a community developed fork of MySQL server. 2026/6/7 MEDIUM5.0 MariaDB server is a community developed fork of MySQL server. 2026/6/7 MEDIUM4.3 Bugsink: DOS using large numbers of event tags 2026/6/5 MEDIUM4.3 Bugsink: Project scoping missing in sourcemap and debug-file lookup 2026/6/5 LOW3.1 Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known 2026/6/5 LOW3.1 Bugsink: Issue event views can show an event from another project if its UUID is known 2026/6/5 HIGH8.7 TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection 2026/6/5 HIGH8.7 TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments 2026/6/5 HIGH8.7 TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes 2026/6/5