CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-55663 MEDIUM

mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)

CVSS 5.6 EPSS 0.19% Aug 25, 2026
crates.ionpm
CVE-2026-75915 HIGH

CodeWhale before 0.8.64 Environment Variable Leak via js_execution

CVSS 8.7 EPSS 0.68% Aug 18, 2026
crates.ionpm
CVE-2026-75914 HIGH

CodeWhale before 0.8.64 Path Traversal via image_analyze symlink

CVSS 8.7 EPSS 0.53% Aug 18, 2026
crates.ionpm
CVE-2026-75913 HIGH

CodeWhale before 0.8.64 Argument Injection via git_show

CVSS 8.5 EPSS 0.48% Aug 18, 2026
crates.ionpm
CVE-2026-75912 HIGH

CodeWhale before 0.8.64 Argument Injection via git_blame

CVSS 8.3 EPSS 0.45% Aug 18, 2026
crates.ionpm
CVE-2026-75911 HIGH

CodeWhale before 0.8.64 Remote Code Execution via allow_shell

CVSS 8.5 EPSS 0.25% Aug 18, 2026
crates.ionpm
CVE-2026-75859 HIGH

CodeWhale before 0.8.64 Arbitrary File Read via instructions

CVSS 8.7 EPSS 0.53% Aug 18, 2026
crates.ionpm
CVE-2026-75858 HIGH

CodeWhale rlm_eval before 0.8.64 Remote Code Execution

CVSS 8.5 EPSS 0.36% Aug 18, 2026
crates.ionpm
CVE-2026-75857 HIGH

CodeWhale before 0.8.64 Privilege Escalation via exec_shell_interact

CVSS 7.3 EPSS 0.15% Aug 18, 2026
crates.ionpm
CVE-2026-75856 CRITICAL

CodeWhale before 0.8.64 SSRF Bypass via DNS Pinning TOCTOU

CVSS 9.2 EPSS 0.50% Aug 18, 2026
crates.ionpm
CVE-2026-72925 MEDIUM

SWC HTML minifier may allow script element breakout when minifying embedded JSON

CVSS 6.1 EPSS 0.34% Aug 11, 2026
crates.ionpm
CVE-2026-47144 MEDIUM

Shamefile has an arbitrary file read via shamefile.yaml in shame next

CVSS 5.5 EPSS 0.18% Jul 20, 2026
PyPIcrates.ionpm
CVE-2026-53598 HIGH

Prompty: Arbitrary File Read via ${file:path} Reference Expansion

CVSS 7.5 EPSS 1.29% Jul 16, 2026
NuGetPyPIcrates.ionpm
CVE-2026-46695 CRITICAL

BoxLite: Permission Bypass in boxlite Allows Modification of Read-Only Files

CVSS 10.0 EPSS 0.48% Jun 10, 2026
GoPyPIcrates.ionpm
CVE-2026-46703 CRITICAL

BoxLite: Path Traversal Vulnerability in boxlite Leads to Arbitrary File Write on the Host

CVSS 9.6 EPSS 0.78% Jun 10, 2026
GoPyPIcrates.ionpm
CVE-2026-45311 CRITICAL

CodeWhale: run_tests Tool Enables RCE via Malicious Repository Without Approval

CVSS 9.6 EPSS 0.69% May 28, 2026
crates.ionpm
CVE-2026-45310 HIGH

CodeWhale: SSRF via HTTP Redirect Bypass in fetch_url Tool

CVSS 7.4 EPSS 0.37% May 28, 2026
crates.ionpm
CVE-2026-42559 HIGH

RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transport

CVSS 8.8 EPSS 0.24% May 14, 2026
crates.ionpm
CVE-2026-22696 CRITICAL

dcap-qvl has Missing Verification for QE Identity

CVSS 9.3 EPSS 0.21% Jan 26, 2026
PyPIcrates.ionpm
CVE-2025-31477 CRITICAL

Improper Scope Validation in the open Endpoint of tauri-plugin-shell

CVSS 9.3 EPSS 1.02% Apr 2, 2025
crates.ionpm
CVE-2024-46488 HIGH

sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Se…

CVSS 8.8 EPSS 0.44% Sep 25, 2024
PyPIRubyGemscrates.ionpm
CVE-2024-45389 MEDIUM

Pagefind DOM clobbering could escalate to Cross-site Scripting (XSS)

CVSS 6.1 EPSS 0.42% Sep 3, 2024
crates.ionpm
CVE-2024-43414 HIGH

Apollo Query Planner and Apollo Gateway may infinitely loop on sufficiently complex queries

CVSS 8.7 EPSS 0.99% Aug 27, 2024
crates.ionpm
CVE-2023-48795 MEDIUM

ssh: Prefix truncation attack on Binary Packet Protocol (BPP)

CVSS 5.9 EPSS 93.55% Dec 18, 2023
GoPyPIcrates.io
CVE-2023-26154 MEDIUM

Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the p…

CVSS 5.9 EPSS 0.96% Dec 6, 2023
GoMavenNuGetPackagistPubPyPIRubyGemsSwiftURLcrates.ionpm

Showing 1 to 25 CVEs · page 1 (more available)