VulnScope — package-centric CVE lookup
LOW2.5 CVE-2026-44969 dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled 5/14/2026 LOW2.7 EPSS 0.09% Synapse pagination Denial of Service 5/14/2026 LOW3.7 EPSS 0.10% Apache Tomcat: AJP secret compared in non-constant time 5/12/2026 LOW3.7 EPSS 0.01% Next.js's Middleware / Proxy redirects can be cache-poisoned 5/11/2026 LOW3.7 EPSS 0.01% Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting 5/11/2026 LOW3.8 EPSS 0.02% Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify() 5/9/2026 LOW3.3 EPSS 0.01% OSGeo gdal GDapi.c GDfieldinfo out-of-bounds 5/7/2026 LOW3.7 EPSS 0.04% nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect) 5/7/2026 LOW3.5 EPSS 0.04% Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed 5/6/2026 LOW3.7 EPSS 0.05% Micronaut has Unbounded `bundleCache` in `ResourceBundleMessageSource` that Allows Memory Exhaustion via `Accept-Language` Header 5/6/2026 LOW3.7 EPSS 0.02% Flowise: Bcrypt Password Hash Exposure 5/6/2026 LOW3.4 EPSS 0.00% Paramiko rsakey.py allows the SHA-1 algorithm 5/6/2026 LOW3.0 EPSS 0.01% ciguard: Container image runs as root (no USER directive) 5/5/2026 LOW3.7 EPSS 0.02% ciguard: SCA HTTP client reads response body without size cap 5/5/2026 LOW2.4 EPSS 0.03% Geyser Vulnerable to Server-Side Request Forgery (SSRF) via Player Head Texture URL in Geyser 5/5/2026 LOW3.7 EPSS 0.05% Microdot has HTTP response splitting in Response.set_cookie() 5/5/2026 LOW2.6 EPSS 0.04% Langchain-Chatchat Uses Insufficiently Random Values 5/5/2026 LOW2.6 EPSS 0.03% Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API 5/5/2026 LOW2.6 EPSS 0.01% Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm 5/5/2026 LOW3.7 EPSS 0.06% Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams 5/5/2026 LOW3.7 EPSS 0.07% xxl-job has a Resource Injection issue 4/29/2026 LOW3.7 EPSS 0.06% Spring gRPC AuthenticationException messages are reflected to remote client 4/28/2026 LOW2.2 EPSS 0.05% Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4) 4/23/2026 LOW3.7 EPSS 0.07% Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider 4/22/2026 LOW2.7 EPSS 0.01% Langflow has an Information Leak through Incomplete API Key Redaction 4/20/2026