VulnScope — package-centric CVE lookup- LOW3.3CVE-2026-8088EPSS 0.01%OSGeo gdal GDapi.c GDfieldinfo out-of-bounds
- LOW3.5EPSS 0.04%Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
- LOW3.7EPSS 0.05%Micronaut has Unbounded `bundleCache` in `ResourceBundleMessageSource` that Allows Memory Exhaustion via `Accept-Language` Header
- LOW3.4EPSS 0.00%Paramiko rsakey.py allows the SHA-1 algorithm
- LOW3.0EPSS 0.01%ciguard: Container image runs as root (no USER directive)
- LOW3.7EPSS 0.02%ciguard: SCA HTTP client reads response body without size cap
- LOW2.4EPSS 0.03%Geyser Vulnerable to Server-Side Request Forgery (SSRF) via Player Head Texture URL in Geyser
- LOW3.7EPSS 0.05%Microdot has HTTP response splitting in Response.set_cookie()
- LOW2.6EPSS 0.04%Langchain-Chatchat Uses Insufficiently Random Values
- LOW2.6EPSS 0.03%Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API
- LOW2.6EPSS 0.01%Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm
- LOW3.7EPSS 0.02%A flaw was found in gnutls.
- LOW3.7EPSS 0.04%A flaw was found in gnutls.
- LOW3.7EPSS 0.07%xxl-job has a Resource Injection issue
- LOW3.7EPSS 0.06%Spring gRPC AuthenticationException messages are reflected to remote client
- LOW3.7EPSS 0.07%Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
- LOW2.7EPSS 0.01%Langflow has an Information Leak through Incomplete API Key Redaction
- LOW3.7EPSS 0.11%Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1
- LOW3.1EPSS 0.03%langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding
- LOW3.1EPSS 0.01%Weblate: Improper access control for pending tasks in API
- LOW2.9EPSS 0.01%libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
- LOW3.5EPSS 0.03%OpenStack Keystone: Restricted application credentials can create EC2 credentials
- LOW2.7EPSS 0.01%Privilege abuse in ModelAdmin.list_editable
- LOW3.7EPSS 0.01%Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claim
- LOW2.7EPSS 0.01%Nautobot: Management of users via REST API does not apply configured password validators