VulnScope — package-centric CVE lookup- LOW3.7CVE-2025-10939EPSS 0.01%Keycloak unable to restrict access to the admin console
- LOW3.6EPSS 0.02%Spotipy has a XSS vulnerability in its OAuth callback server
- LOW3.7EPSS 0.05%NutzBoot vulnerable to deserialization
- LOW2.8EPSS 0.01%Mustangproject allows exfiltrating files via XXE attacks
- LOW3.3EPSS 0.01%Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
- LOW3.5EPSS 0.08%changedetection.io: Stored XSS in Watch update via API
- LOW3.3EPSS 0.03%An issue was discovered in PyTorch v2.5 and v2.7.1.
- LOW2.6EPSS 0.03%Weblate leaks the IP of project member inviting user to be reviewer in Audit log
- LOW3.1EPSS 0.06%reflex-dev/reflex has an Open Redirect vulnerability
- LOW2.5EPSS 0.12%DataChain Vulnerable to Deserialization of Untrusted Data from Environment Variables
- LOW3.1EPSS 0.02%Django vulnerable to partial directory traversal via archives
- LOW3.7EPSS 0.03%WSO2's Input Validation Management Service contains Observable Discrepancy when Multi-Attribute Login is enabled
- LOW3.7EPSS 0.13%xxl-job has Inadequate Encryption Strength
- LOW3.3EPSS 0.14%Jenkins User1st uTester Plugin vulnerability exposes unencrypted token to authenticated users
- LOW3.1EPSS 0.12%Jenkins Testsigma Test Plan vulnerability exposes API keys via job configuration form
- LOW3.5EPSS 0.06%Transformers's Improper Input Validation vulnerability can be exploited through username injection
- LOW3.5EPSS 0.15%XXL SSO is vulnerable to an Open Redirect through malicious manipulation of the redirect_url argument
- LOW3.3EPSS 0.15%pywasm3 has Improper Restriction of Operations within the Bounds of a Memory Buffer
- LOW3.7EPSS 0.11%Gradio CORS Origin Validation Bypass Vulnerability
- LOW2.6EPSS 0.18%Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
- LOW3.1EPSS 0.08%Spring Framework DataBinder Case Sensitive Match Exception
- LOW2.8EPSS 0.06%OpenStack Ironic fails to restrict paths used for file:// image URLs
- LOW2.7EPSS 0.12%The lesscss script service allows cache clearing without programming right
- LOW3.8EPSS 0.09%Solr script service doesn't take dropped programming right into account
- LOW2.7EPSS 0.50%Apereo CAS has inefficient regular expression complexity