Search
121 results- LOW3.7CVE-2026-44489Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
- LOW2.0CVE-2026-46549NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
- LOW3.7CVE-2026-44572EPSS 0.01%Next.js's Middleware / Proxy redirects can be cache-poisoned
- LOW3.7CVE-2026-44582EPSS 0.01%Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
- LOW3.8CVE-2026-44459EPSS 0.02%Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
- LOW3.7CVE-2026-44589EPSS 0.04%nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)
- LOW3.7CVE-2026-8026EPSS 0.01%Flowise: Bcrypt Password Hash Exposure
- LOW3.7CVE-2026-42040EPSS 0.06%Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
- LOW2.2CVE-2026-41321EPSS 0.05%Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4)
- LOW3.7CVE-2026-33877EPSS 0.03%ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
- LOW3.5CVE-2026-6216EPSS 0.04%DbGate has cross site scripting via the SVG Icon String Handler component
- LOW3.7CVE-2026-41913EPSS 0.08%OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths
- LOW3.7CVE-2026-34166EPSS 0.02%LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter
- LOW3.7CVE-2026-39321EPSS 0.03%Parse Server has a login timing side-channel reveals user existence
- LOW3.7CVE-2026-41407EPSS 0.04%OpenClaw: Shared-secret comparison call sites leaked length information through timing
- LOW2.8CVE-2026-34781EPSS 0.01%Electron: Crash in clipboard.readImage() on malformed clipboard image data
- LOW2.3CVE-2026-34764EPSS 0.02%Electron: Use-after-free in offscreen shared texture release() callback
- LOW3.7CVE-2026-41333EPSS 0.08%OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting
- LOW3.9CVE-2026-34768EPSS 0.01%Electron: Unquoted executable path in app.setLoginItemSettings on Windows
- LOW3.3CVE-2026-34766EPSS 0.01%Electron: USB device selection not validated against filtered device list
- LOW3.7CVE-2026-35648EPSS 0.03%OpenClaw may have stale policy enforcement for queued node actions
- LOW3.7CVE-2026-33490EPSS 0.02%h3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes
- LOW2.7CVE-2026-32638EPSS 0.03%StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens
- LOW2.5CVE-2026-32970EPSS 0.02%OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode
- LOW3.1CVE-2026-2366EPSS 0.01%Keycloak vulnerable to authorization bypass via the Admin API
Page 1 of 5Next →