VulnScope — 以套件為主體的 CVE 查詢工具- HIGH8.2CVE-2026-54271protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names
- HIGH7.5CVE-2026-48712protobufjs: Denial of service through unbounded Any expansion during JSON conversion
- HIGH8.2tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template
- HIGH7.5ws: Memory exhaustion DoS from tiny fragments and data chunks
- HIGH7.5form-data: CRLF injection in form-data via unescaped multipart field names and filenames
- HIGH8.1Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
- HIGH7.5Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
- HIGH7.7Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection
- HIGH7.1WsgiDAV encoded dot segments can escape filesystem share roots
- HIGH7.5@grpc/grpc-js: A malformed request can cause a server crash
- HIGH7.5@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
- HIGH8.8OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts.uri
- HIGH8.1Litestar has HTML Injection Through its CSRF Token
- HIGH8.2FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response reading
- HIGH8.7TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection
- HIGH8.7TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments
- HIGH8.7TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes
- HIGH8.7TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs
- HIGH8.8DbGate: Remote Code Execution via functionName injection in loadReader endpoint
- HIGH7.7Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP
- HIGH8.3praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
- HIGH7.3Apache Airflow: Arbitrary import in custom deadline-reference deserialization
- HIGH8.8Apache Airflow: Authenticated RCE via XCom PATCH endpoint — XComUpdateBody missing FORBIDDEN_XCOM_KEYS validator
- HIGH7.5Apache Airflow: API authorization bypass: bulk TaskInstances allows cross-DAG mutation
- HIGH7.5React Router vulnerable to Denial of Service via reflected user input in single-fetch