MEDIUM5.3joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas
MEDIUM6.5@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
MEDIUM5.9Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
MEDIUM6.5vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
LOW3.5Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
MEDIUM6.3FUXA's scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions
MEDIUM5.3FUXA has SQL Injection in its TDengine DAQ connector via backslash bypass of escapeTdString
MEDIUM5.4Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type
MEDIUM4.3Bugsink: DOS using large numbers of event tags
MEDIUM4.3Bugsink: Project scoping missing in sourcemap and debug-file lookup
LOW3.1Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known
LOW3.1Bugsink: Issue event views can show an event from another project if its UUID is known
CRITICAL9.1NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)
CRITICAL10.0DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
MEDIUM6.0NocoDB: Postgres SQL Injection in Formula `ARRAYSORT`
MEDIUM6.1MCP Server Kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltration