VulnScope — 以套件為主體的 CVE 查詢工具- MEDIUM6.7CVE-2026-48121LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access
- MEDIUM5.3CVE-2026-48049@hapi/inert has a static-file confinement bypass via sibling-prefix path
- HIGH7.5@grpc/grpc-js: A malformed request can cause a server crash
- HIGH7.5@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
- MEDIUM5.3joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas
- HIGH8.8OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts.uri
- MEDIUM6.5@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
- —Element Call reports full URLs of visited pages to analytics server
- —Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload
- LOW3.5Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
- —@hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture
- —@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts
- —@hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened
- —@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
- —@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name
- —@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers
- MEDIUM6.3FUXA's scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions
- MEDIUM5.3FUXA has SQL Injection in its TDengine DAQ connector via backslash bypass of escapeTdString
- HIGH8.2FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response reading
- —actual Allows Electron to Run As Node
- —Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.
- HIGH8.7TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection
- HIGH8.7TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments
- HIGH8.7TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes
- HIGH8.7TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs