CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit
Shamefile has an arbitrary file read via shamefile.yaml in shame next
Prompty: Arbitrary File Read via ${file:path} Reference Expansion
JupyterLab Git: Stored XSS leading to RCE
Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
BoxLite: Permission Bypass in boxlite Allows Modification of Read-Only Files
BoxLite: Path Traversal Vulnerability in boxlite Leads to Arbitrary File Write on the Host
LangSmith Client SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
Open WebUI: Stored XSS via Model Description
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page.
Jupyter Notebook and JupyterLab token theft via stored XSS in help command linker
LangSmith SDK: Streaming token events bypass output redaction
Azure MCP Server Tools Elevation of Privilege Vulnerability
LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
dcap-qvl has Missing Verification for QE Identity
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth b…
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
OpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`)
OpenC3 COSMOS vulnerable to cross-site scripting in Login functionality (`GHSL-2024-128`)
Showing 1 to 25 CVEs · page 1 (more available)