CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env
basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)
CloudTAK: Authenticated full-read SSRF in /api/esri* routes — user-controlled URL fetched with no IP-classification guard
Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters
Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges
Astro: Malformed port in the Host header can crash the Node adapter
Astro: Netlify Image CDN allowlist bypass enables SSRF
Socket.IO: Engine.IO Protocol Revision Mismatch DoS
adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
Electron: Sandboxed preload code cache can be poisoned by a compromised renderer
Electron: Local race condition in Squirrel.Mac update installation on macOS
Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions
Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled
Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions
Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in serialized function bodies
Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
Nest: Remote process termination via a deeply nested microservice message pattern
brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized
@grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages
@grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches
Axios: Prototype pollution gadget in fetch adapter can alter outbound requests
Showing 1 to 25 CVEs · page 1 (more available)