CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect
Integer Overflow or Wraparound and Out-of-bounds Write in compress
Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri
obot before v0.21.1 Authorization Bypass via /mcp-connect
Obot before v0.23.0 Server-Side Request Forgery via MCP
Obot before v0.23.0 Authentication Bypass via Registry API
Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration
Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint
Cloudreve before 4.16.1 Path Traversal via Remote Download
Cloudreve before 4.17.0 SSRF via Admin.Read OAuth scope
Fleet before 4.87.0 Unauthenticated iOS App Download via Predictable URLs
Fleet before 4.89.0 SQL Injection via ORDER BY Activity Endpoints
Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching
Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer
Contrast before 1.18.0 AML Injection Remote Code Execution
Contrast before 1.19.1 CopyFile Policy Symlink Subversion
Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery
Contrast before 1.8.1 Information Disclosure via Logging
Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount
Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure
Contrast before 1.12.1 Insecure LUKS2 Persistent Storage
Containerd has image-pull DoS via crafted OCI index graph amplification
Dozzle label filters do not restrict container event and statistics streams
ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass
ZITADEL: MFA bypass via session reuse in Login V2
Showing 1 to 25 CVEs · page 1 (more available)