VulnScope — 以套件為主體的 CVE 查詢工具- HIGH7.3CVE-2026-11417aws-cdk-lib: OS Command Injection in NodejsFunction Bundling
- HIGH7.5Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
- HIGH7.5python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
- HIGH7.7Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
- HIGH7.5tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
- HIGH7.5Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
- HIGH8.2protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names
- CRITICAL9.8Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
- HIGH7.5protobufjs: Denial of service through unbounded Any expansion during JSON conversion
- HIGH8.2tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template
- HIGH7.5ws: Memory exhaustion DoS from tiny fragments and data chunks
- HIGH7.5form-data: CRLF injection in form-data via unescaped multipart field names and filenames
- HIGH8.1Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
- HIGH7.5Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
- CRITICAL9.0Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
- HIGH7.7Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection
- HIGH7.3Vim is an open source, command line text editor.
- HIGH7.5Vim is an open source, command line text editor.
- HIGH7.1WsgiDAV encoded dot segments can escape filesystem share roots
- CRITICAL9.1Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
- HIGH7.5@grpc/grpc-js: A malformed request can cause a server crash
- HIGH7.5@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
- HIGH8.8OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts.uri
- HIGH8.1Litestar has HTML Injection Through its CSRF Token
- CRITICAL9.8Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification.