VulnScope — package-centric CVE lookup- LOW3.5CVE-2025-2699EPSS 0.10%GetmeUK ContentTools Cross-Site Scripting (XSS)
- LOW3.3EPSS 0.01%Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection
- LOW3.9EPSS 0.11%MongoDB Shell may be susceptible to control character Injection via shell output
- LOW2.7EPSS 0.75%Matrix IRC Bridge allows IRC command injection to own puppeted user
- LOW3.5EPSS 0.21%Regular Expression Denial of Service (ReDoS) in @eslint/plugin-kit
- LOW3.7EPSS 0.03%ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function
- LOW3.3EPSS 0.05%ReLaXed Cross-site Scripting vulnerability
- LOW2.5EPSS 0.36%Mattermost Desktop App fails to sufficiently configure Electron Fuses
- LOW3.7EPSS 0.36%Mattermost Desktop App fails to safeguard screen capture functionality
- LOW3.1EPSS 0.08%CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover
- LOW3.1EPSS 0.16%The fuels-ts typescript SDK has no awareness of to-be-spent transactions
- LOW3.7EPSS 0.07%@jmondi/url-to-png enables capture screenshot of localhost web services (unauthenticated pages)
- LOW2.0EPSS 0.36%Undici vulnerable to data leak when using response.arrayBuffer()
- LOW3.8EPSS 0.03%Mattermost Desktop App allows for bypassing TCC restrictions on macOS
- LOW2.3EPSS 0.43%@strapi/plugin-content-manager leaks data via relations via the Admin Panel
- LOW3.5EPSS 0.14%vxe-table Cross-site Scripting vulnerability
- LOW2.6EPSS 0.07%CSRF in firebase-tools emulator suite in github.com/firebase/firebase-tools
- LOW2.6EPSS 0.07%Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect
- LOW3.9EPSS 0.20%Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
- LOW2.3EPSS 0.09%Session Token in URL in directus
- LOW3.9EPSS 0.28%Undici proxy-authorization header not cleared on cross-origin redirect in fetch
- LOW3.5EPSS 0.03%lambda-middleware Inefficient Regular Expression Complexity vulnerability
- LOW3.7EPSS 0.06%google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability
- LOW3.9EPSS 0.12%Undici's cookie header not cleared on cross-origin redirect in fetch
- LOW3.5EPSS 0.36%matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms