VulnScope — package-centric CVE lookup- HIGH7.2CVE-2025-52465GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
- HIGH7.2GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
- HIGH7.5Acknowledgement extension out of memory
- HIGH8.0Jenkins: Stored XSS vulnerability in node offline cause description
- HIGH8.1In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
- HIGH8.7Netty has Insufficient Bailiwick Validation for NS Records
- HIGH7.5Netty: SCTP reassembly nests buffers without bound
- HIGH8.7Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
- HIGH7.5Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
- HIGH7.5Netty's Default QUIC token handler accepts any client-supplied token
- HIGH7.5Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length
- HIGH7.5Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
- HIGH7.5Netty has Unbounded Direct Memory Consumption in its RedisDecoder
- HIGH7.5Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
- HIGH8.1Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
- CRITICAL9.1Yamcs Vulnerable to Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
- CRITICAL9.8Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm override
- CRITICAL9.1Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
- HIGH7.5XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests
- HIGH8.3OpenMetadata: TEST_CONNECTION workflow leaks ingestion-bot JWT and database password to regular users
- HIGH7.5Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
- CRITICAL9.6GlassFish's gadget handler is vulnerable to RCE
- CRITICAL9.1GlassFish's Administration Console is Vulnerable to RCE
- CRITICAL9.8Camel-CXF and Camel-Knative Message Header are Vulnerable to Injection via Missing Inbound Filtering
- HIGH7.1Keycloak: Access token disclosure and implicit flow bypass via forged client data