VulnScope — package-centric CVE lookup- LOW2.2CVE-2026-54327Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
- LOW2.5CVE-2026-54326Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
- LOW3.1React Router: Potential CSRF via PUT/PATCH/DELETE document requests
- LOW3.2@babel/core: Arbitrary File Read via sourceMappingURL Comment
- LOW3.5Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
- LOW3.7Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
- LOW2.0NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
- LOW3.7EPSS 0.01%Next.js's Middleware / Proxy redirects can be cache-poisoned
- LOW3.7EPSS 0.01%Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
- LOW3.8EPSS 0.02%Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
- LOW3.7EPSS 0.04%nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)
- LOW3.7EPSS 0.02%Flowise: Bcrypt Password Hash Exposure
- LOW3.7EPSS 0.06%Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
- LOW2.2EPSS 0.05%Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4)
- LOW3.7EPSS 0.03%ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
- LOW3.5EPSS 0.04%DbGate has cross site scripting via the SVG Icon String Handler component
- LOW3.7EPSS 0.08%OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths
- LOW3.7EPSS 0.02%LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter
- LOW3.7EPSS 0.03%Parse Server has a login timing side-channel reveals user existence
- LOW3.7EPSS 0.04%OpenClaw: Shared-secret comparison call sites leaked length information through timing
- LOW2.8EPSS 0.01%Electron: Crash in clipboard.readImage() on malformed clipboard image data
- LOW2.3EPSS 0.02%Electron: Use-after-free in offscreen shared texture release() callback
- LOW3.7EPSS 0.08%OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting
- LOW3.9EPSS 0.01%Electron: Unquoted executable path in app.setLoginItemSettings on Windows
- LOW3.3EPSS 0.01%Electron: USB device selection not validated against filtered device list