VulnScope — package-centric CVE lookup- LOW3.7CVE-2025-15284EPSS 0.04%qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion
- LOW3.3EPSS 0.02%Mattermost Desktop App exposes sensitive information in its application logs
- LOW3.7EPSS 0.04%Improper Validation of Query Parameters in Auth0 Next.js SDK
- LOW3.5EPSS 0.02%Astro Development Server has Arbitrary Local File Read
- LOW2.7EPSS 0.03%Astro development server error page is vulnerable to reflected Cross-site Scripting
- LOW3.7EPSS 0.05%EverShop is vulnerable to Unauthorized Order Information Access (IDOR)
- LOW3.7EPSS 0.08%Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
- LOW3.0EPSS 0.03%Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch module
- LOW3.1EPSS 0.02%Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival
- LOW3.5EPSS 0.02%ExpressGateway Cross-Site Scripting Vulnerability in lib/rest/routes/apps.js
- LOW3.5EPSS 0.06%ExpressGateway Cross-Site Scripting Vulnerability in lib/rest/routes/users.js
- LOW2.6EPSS 0.05%Template Secret leakage in logs in Scaffolder when using `fetch:template`
- LOW2.5EPSS 0.47%node-tmp - security update
- LOW3.5EPSS 0.26%Koa Open Redirect via Referrer Header (User-Controlled)
- LOW3.4EPSS 0.04%on-headers is vulnerable to http response header manipulation
- LOW3.7EPSS 0.43%Next.js has a Cache poisoning vulnerability due to omission of the Vary header
- LOW3.7EPSS 0.33%string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS)
- LOW3.1EPSS 0.09%brace-expansion Regular Expression Denial of Service vulnerability
- LOW3.7EPSS 0.73%Meteor Affected By Inefficient Regular Expression Complexity
- LOW3.1EPSS 0.05%undici Denial of Service attack via bad certificate data
- LOW3.7EPSS 0.75%Next.js Race Condition to Cache Poisoning
- LOW3.1EPSS 0.06%Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields
- LOW3.3EPSS 0.01%NodeJS Driver for Snowflake has race condition when checking access to Easy Logging configuration file
- LOW3.1EPSS 0.06%Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content
- LOW3.5EPSS 0.40%Suspended Directus user can continue to use session token to access API