VulnScope — package-centric CVE lookup
LOW2.2 CVE-2026-12567 BBOT: Symlink-Following Arbitrary Write via github_workflows Module 6/18/2026 LOW3.1 BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing 6/18/2026 LOW2.2 Pi Agent: Race condition in Pi auth.json writes could expose stored credentials 6/17/2026 LOW2.5 Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass 6/16/2026 LOW3.7 Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname 6/15/2026 LOW3.7 python-multipart: Negative Content-Length in parse_form buffers the entire body in memory 6/15/2026 LOW3.7 python-multipart: Semicolon treated as querystring field separator enables parameter smuggling 6/15/2026 LOW3.7 python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters 6/15/2026 LOW3.1 React Router: Potential CSRF via PUT/PATCH/DELETE document requests 6/15/2026 LOW3.2 @babel/core: Arbitrary File Read via sourceMappingURL Comment 6/15/2026 LOW3.7 Tornado has out-of-bounds memory access via C extension 6/12/2026 LOW3.5 Papra HTTP redirect bypass can lead to SSRF via webhook delivery system 6/10/2026 LOW3.7 Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provid… 6/9/2026 LOW3.7 Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup… 6/9/2026 LOW3.1 Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known 6/5/2026 LOW3.1 Bugsink: Issue event views can show an event from another project if its UUID is known 6/5/2026 LOW2.5 A security flaw has been discovered in gradio-app gradio 6.14.0. 6/4/2026 LOW3.7 daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processi… 6/3/2026 LOW3.1 EPSS 0.04% Apache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log access 6/1/2026 LOW3.7 Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix 5/29/2026 LOW3.1 7-Zip is a file archiver with a high compression ratio. 5/29/2026 LOW3.3 Dulwich doesn't sanitize commit subjects in `porcelain.format_patch` 5/29/2026 LOW3.7 EPSS 0.06% PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) 5/28/2026 LOW3.3 EPSS 0.01% pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams 5/28/2026 LOW2.0 NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation 5/21/2026