VulnScope — package-centric CVE lookup
LOW3.3 CVE-2026-21716 EPSS 0.01% An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permissi… 3/30/2026 LOW3.3 EPSS 0.01% A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, wh… 3/30/2026 LOW3.1 EPSS 0.01% Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories 3/27/2026 LOW3.1 EPSS 0.01% Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation 3/26/2026 LOW3.7 EPSS 0.03% NGINX ngx_mail_proxy_module vulnerability 3/24/2026 LOW3.7 EPSS 0.02% Keycloak's identity-first login flow exposes user information 3/23/2026 LOW3.3 EPSS 0.01% Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching 3/22/2026 LOW2.6 EPSS 0.09% Spring MVC and WebFlux has Server Sent Event stream corruption 3/20/2026 LOW3.6 EPSS 0.02% Stored XSS in Memray-generated HTML reports via unescaped command-line metadata 3/16/2026 LOW3.7 EPSS 0.01% Copyparty has unexpected JavaScript execution via crafted URL to folder with `.prologue.html` 3/12/2026 LOW3.1 EPSS 0.01% Keycloak vulnerable to authorization bypass via the Admin API 3/12/2026 LOW2.7 EPSS 0.01% Keycloak: Information disclosure of disabled user attributes via administrative endpoint 3/11/2026 LOW3.7 EPSS 0.14% org.eclipse.jetty:jetty-http has different parsing of invalid URIs 3/5/2026 LOW3.7 EPSS 0.01% Potential incorrect permissions on newly created file system objects 3/3/2026 LOW2.2 EPSS 0.01% Vim is an open source, command line text editor. 2/27/2026 LOW3.1 EPSS 0.01% Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass 2/27/2026 LOW3.3 EPSS 0.01% Snowflake JDBC Driver is Vulnerable to Uncontrolled Resource Consumption through SdkProxyRoutePlanner 2/27/2026 LOW3.1 EPSS 0.04% wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data 2/26/2026 LOW3.8 EPSS 0.03% Keycloak: Missing Check on Disabled Client for Docker Registry Protocol 2/19/2026 LOW3.7 EPSS 0.16% Apache Tomcat: Security constraint bypass with HTTP/0.9 2/17/2026 LOW3.7 EPSS 0.02% LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages 2/11/2026 LOW2.5 EPSS 0.01% Apache Shiro Affected by an Observable Timing Discrepancy Vulnerability 2/10/2026 LOW2.7 EPSS 0.01% Keycloak Server-Side Request Forgery (SSRF) vulnerability 2/2/2026 LOW2.7 EPSS 0.01% Keycloak Admin API allows an administrator with limited privileges to retrieve sensitive custom attributes 2/2/2026 LOW3.2 EPSS 0.01% Llama Stack exposes secret in initialization log 1/30/2026