VulnScope — package-centric CVE lookup
LOW3.3 CVE-2026-21716 EPSS 0.01% An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permissi… 3/30/2026 LOW3.3 EPSS 0.01% A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, wh… 3/30/2026 LOW3.1 EPSS 0.01% Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories 3/27/2026 LOW3.7 EPSS 0.03% OpenClaw may have stale policy enforcement for queued node actions 3/26/2026 LOW3.1 EPSS 0.01% Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation 3/26/2026 LOW3.7 EPSS 0.03% NGINX ngx_mail_proxy_module vulnerability 3/24/2026 LOW3.7 EPSS 0.02% Keycloak's identity-first login flow exposes user information 3/23/2026 LOW3.3 EPSS 0.01% Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching 3/22/2026 LOW3.7 EPSS 0.02% h3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes 3/20/2026 LOW2.6 EPSS 0.09% Spring MVC and WebFlux has Server Sent Event stream corruption 3/20/2026 LOW3.6 EPSS 0.02% Stored XSS in Memray-generated HTML reports via unescaped command-line metadata 3/16/2026 LOW2.7 EPSS 0.03% StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens 3/16/2026 LOW2.5 EPSS 0.02% OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode 3/13/2026 LOW3.7 EPSS 0.01% Copyparty has unexpected JavaScript execution via crafted URL to folder with `.prologue.html` 3/12/2026 LOW3.1 EPSS 0.01% Keycloak vulnerable to authorization bypass via the Admin API 3/12/2026 LOW2.7 EPSS 0.01% Keycloak: Information disclosure of disabled user attributes via administrative endpoint 3/11/2026 LOW3.7 EPSS 0.14% org.eclipse.jetty:jetty-http has different parsing of invalid URIs 3/5/2026 LOW2.0 EPSS 0.01% @backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass 3/5/2026 LOW2.7 EPSS 0.01% Backstage vulnerable to potential reading of SCM URLs using built in token 3/5/2026 LOW3.7 EPSS 0.04% OpenClaw has cross-account DM pairing authorization bypass via unscoped pairing store access 3/4/2026 LOW3.4 EPSS 0.02% Dark Reader gives users the ability to request style sheets from local web servers 3/4/2026 LOW3.7 EPSS 0.04% OpenClaw: Discord DM reaction ingress missed dmPolicy/allowFrom checks in restricted setups 3/3/2026 LOW3.7 EPSS 0.01% Potential incorrect permissions on newly created file system objects 3/3/2026 LOW3.3 EPSS 0.02% @tootallnate/once vulnerable to Incorrect Control Flow Scoping 3/3/2026 LOW2.6 EPSS 0.04% OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows 3/2/2026