VulnScope — package-centric CVE lookup- LOW3.7CVE-2026-5419EPSS 0.04%A flaw was found in gnutls.
- LOW3.7EPSS 0.07%xxl-job has a Resource Injection issue
- LOW3.7EPSS 0.06%Spring gRPC AuthenticationException messages are reflected to remote client
- LOW2.2EPSS 0.05%Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4)
- LOW3.7EPSS 0.07%Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
- LOW2.7EPSS 0.01%Langflow has an Information Leak through Incomplete API Key Redaction
- LOW3.7EPSS 0.11%Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1
- LOW3.1EPSS 0.03%langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding
- LOW3.7EPSS 0.03%ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
- LOW3.1EPSS 0.01%Weblate: Improper access control for pending tasks in API
- LOW2.9EPSS 0.01%libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
- LOW3.5EPSS 0.04%DbGate has cross site scripting via the SVG Icon String Handler component
- LOW3.5EPSS 0.03%OpenStack Keystone: Restricted application credentials can create EC2 credentials
- LOW3.7EPSS 0.08%OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths
- LOW3.7EPSS 0.02%LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter
- LOW3.7EPSS 0.03%Parse Server has a login timing side-channel reveals user existence
- LOW3.7EPSS 0.04%OpenClaw: Shared-secret comparison call sites leaked length information through timing
- LOW2.8EPSS 0.01%Electron: Crash in clipboard.readImage() on malformed clipboard image data
- LOW2.7EPSS 0.01%Privilege abuse in ModelAdmin.list_editable
- LOW3.7EPSS 0.01%Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claim
- LOW2.3EPSS 0.02%Electron: Use-after-free in offscreen shared texture release() callback
- LOW3.7EPSS 0.08%OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting
- LOW3.9EPSS 0.01%Electron: Unquoted executable path in app.setLoginItemSettings on Windows
- LOW3.3EPSS 0.01%Electron: USB device selection not validated against filtered device list
- LOW2.7EPSS 0.01%Nautobot: Management of users via REST API does not apply configured password validators