VulnScope — 以套件為主體的 CVE 查詢工具- LOW3.5CVE-2026-42448EPSS 0.04%Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
- CRITICAL9.9EPSS 0.01%wger: cross-tenant password reset and plaintext disclosure via gym=None bypass
- CRITICAL9.9EPSS 0.05%Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
- CRITICAL9.9EPSS 0.05%Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
- LOW3.4EPSS 0.00%Paramiko rsakey.py allows the SHA-1 algorithm
- LOW3.0EPSS 0.01%ciguard: Container image runs as root (no USER directive)
- LOW3.7EPSS 0.02%ciguard: SCA HTTP client reads response body without size cap
- CRITICAL9.8EPSS 0.08%OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables.
- LOW3.7EPSS 0.05%Microdot has HTTP response splitting in Response.set_cookie()
- LOW2.6EPSS 0.04%Langchain-Chatchat Uses Insufficiently Random Values
- LOW2.6EPSS 0.03%Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API
- LOW2.6EPSS 0.01%Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm
- CRITICAL9.6EPSS 0.01%Langflow Knowledge Bases API is Vulnerable to Path Traversal
- CRITICAL9.9EPSS 0.06%FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
- CRITICAL9.8EPSS 0.06%ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView
- CRITICAL9.1EPSS 0.01%Sentry's improper authentication on SAML SSO process allows user identity linking
- CRITICAL9.8EPSS 0.25%NVIDIA NVFlare Dashboard: Authorization bypass through user-controlled key via user management and authentication system
- CRITICAL9.8⚠ KEVEPSS 56.9%LiteLLM has SQL Injection in Proxy API key verification
- CRITICAL9.8EPSS 0.88%Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer
- LOW2.7EPSS 0.01%Langflow has an Information Leak through Incomplete API Key Redaction
- LOW3.7EPSS 0.11%Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1
- CRITICAL9.8EPSS 0.10%PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection
- CRITICAL9.1EPSS 0.20%OpenViking: Unauthenticated remote bot control via OpenAPI HTTP routes
- CRITICAL9.1EPSS 0.06%Sentry: Improper authentication on SAML SSO process allows user identity linking
- LOW3.1EPSS 0.03%langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding