搜尋
3,429 筆結果- MEDIUM5.3CVE-2026-47676Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
- MEDIUM5.3CVE-2026-47674Hono: IP Restriction bypasses static deny rules for non-canonical IPv6
- MEDIUM4.3CVE-2026-47675Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
- MEDIUM4.8CVE-2026-47673Hono: JWT middleware accepts any Authorization scheme, not only Bearer
- MEDIUM6.5CVE-2026-49144EPSS 0.02%browserstack-runner has an unauthenticated arbitrary file read via path traversal in HTTP server
- MEDIUM5.5CVE-2026-44022Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands
- MEDIUM5.4CVE-2026-33244EPSS 0.03%React Router has stored XSS via unescaped Location header in prerendered redirect HTML
- MEDIUM6.5CVE-2026-47411praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}
- MEDIUM6.5CVE-2026-42360EPSS 0.05%Apache Airflow: Rendered template truncation bypasses nested sensitive-key masking
- MEDIUM5.9CVE-2026-41017EPSS 0.02%Apache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-terminating proxy
- MEDIUM6.5CVE-2026-45192EPSS 0.04%Apache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra API Response
- MEDIUM6.5CVE-2026-47408praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership
- MEDIUM5.5CVE-2026-47395PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
- MEDIUM5.5CVE-2026-47390PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
- MEDIUM6.5CVE-2026-47213BoxLite has a Timeout Bypass Vulnerability
- MEDIUM6.5CVE-2026-47184zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood
- MEDIUM6.5CVE-2026-47183zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion
- MEDIUM6.5CVE-2026-47180zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service
- MEDIUM5.3CVE-2026-8814EPSS 0.06%ExifReader is vulnerable to denial of service via unbounded decompression of image metadata
- MEDIUM4.8CVE-2026-44490axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
- MEDIUM5.5CVE-2026-47144Shamefile has an arbitrary file read via shamefile.yaml in shame next
- MEDIUM5.0CVE-2026-46526EPSS 0.03%local-deep-research has an SSRF bypass in `safe_get`
- MEDIUM6.7CVE-2026-46380compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem
- MEDIUM5.3CVE-2026-48525EPSS 0.05%PyJWT is a JSON Web Token implementation in Python.
- MEDIUM5.4CVE-2026-48523EPSS 0.01%PyJWT is a JSON Web Token implementation in Python.
第 1 / 138 頁下一頁 →