VulnScope — package-centric CVE lookup- LOW3.0CVE-2026-44218EPSS 0.01%ciguard: Container image runs as root (no USER directive)
- LOW3.7EPSS 0.02%ciguard: SCA HTTP client reads response body without size cap
- LOW2.4EPSS 0.03%Geyser Vulnerable to Server-Side Request Forgery (SSRF) via Player Head Texture URL in Geyser
- LOW3.7EPSS 0.05%Microdot has HTTP response splitting in Response.set_cookie()
- LOW2.6EPSS 0.04%Langchain-Chatchat Uses Insufficiently Random Values
- LOW2.6EPSS 0.03%Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API
- LOW2.6EPSS 0.01%Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm
- LOW3.7EPSS 0.06%Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
- LOW3.7EPSS 0.07%xxl-job has a Resource Injection issue
- LOW3.7EPSS 0.06%Spring gRPC AuthenticationException messages are reflected to remote client
- LOW2.2EPSS 0.05%Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4)
- LOW3.7EPSS 0.07%Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
- LOW2.7EPSS 0.01%Langflow has an Information Leak through Incomplete API Key Redaction
- LOW3.7EPSS 0.11%Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
- LOW3.1EPSS 0.03%langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding
- LOW3.7EPSS 0.03%ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
- LOW3.1EPSS 0.01%Weblate: Improper access control for pending tasks in API
- LOW3.5EPSS 0.04%DbGate has cross site scripting via the SVG Icon String Handler component
- LOW3.5EPSS 0.03%OpenStack Keystone: Restricted application credentials can create EC2 credentials
- LOW3.7EPSS 0.08%OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths
- LOW3.7EPSS 0.02%LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter
- LOW3.7EPSS 0.03%Parse Server has a login timing side-channel reveals user existence
- LOW3.7EPSS 0.04%OpenClaw: Shared-secret comparison call sites leaked length information through timing
- LOW2.8EPSS 0.01%Electron: Crash in clipboard.readImage() on malformed clipboard image data
- LOW2.7EPSS 0.01%Django vulnerable to privilege abuse in ModelAdmin.list_editable