Supported Tests by SmartScanner

365 tests found

Get Started

Download SmartScanner Free →

Test all vulnerabilities with our free version

Learn More

Read Security Guides →

In-depth articles on vulnerability remediation

Vulnerability NameSeverity

Cross-Site Scripting in dojo - dojo

Medium

Read the Docs vulnerable to Cross-Site Scripting (XSS)

Medium

Incorrect default cookie name and recommendation

Low

Cross-Site Scripting in simditor

Medium

Cross-Site Scripting in bootbox

Medium

Reflected Cross-Site Scripting in jquery.terminal

Medium

Cross-Site Scripting in react-svg

High

Memory Exposure in tunnel-agent

Medium

Cross-Site Scripting in shave

Medium

Cross-Site Scripting in bracket-template

High

Prototype Pollution in deap

High

Denial of Service in canvas

Medium

Regular Expression Denial of Service

Medium

Path Traversal in localhost-now - localhost-now

High

Regular Expression Denial of Service - nwmatcher

Medium

Cross-Site Scripting in ids-enterprise - ids-enterprise

High

Cross-Site Scripting in ids-enterprise

High

Remote code execution in Handlebars.js

Medium

Sandbox Bypass Leading to Arbitrary Code Execution in constantinople

High

HTML tag injection

Medium

Insecure Default Configuration in tesseract.js

Medium

Prototype Pollution in lutils-merge

Medium

Prototype Pollution in upmerge

Medium

Failure to sanitize quotes which can lead to sql injection in squel

High

Regular Expression Denial of Service in underscore.string

Medium

Cross-Site Scripting in marked

Medium

Cross-Site Scripting (XSS) in cloudcmd

High

Denial of Service in url-relative

Medium

Content injection in marked

Medium

Command Injection in dot

Medium

Reverse Tabnapping in swagger-ui

Medium

Cross-Site Scripting in ids-enterprise - ids-enterprise - GHSA-crfx-5phg-hmw9

High

Cross-Site Scripting in @nuxt/devalue

Medium

Cross-Site Scripting via JSONP

Medium

Denial of Service in mem

Medium

Cross-Site Scripting in cyberchef

Medium

Cross-Site Scripting in dojo - dojo - GHSA-536q-8gxx-m782

Medium

Message Signature Bypass in openpgp

High

Prototype Pollution in deeply

High

Cross-Site Scripting in iobroker.web

Medium

Remote Code Execution in Angular Expressions

High

Validation bypass is possible in Json Pattern Validator

Medium

Cross-Site Scripting in selectize-plugin-a11y

Medium

Denial of Service in rgb2hex

Medium

Improper Key Verification in openpgp

High

Cross-Site Scripting in vant

High

Incorrect Account Used for Signing - eth-ledger-bridge-keyring

High

Incorrect Account Used for Signing

High

OS Command Injection in devcert-sanscache

High

Regular Expression Denial of Service in Acorn

High

Sandbox bypass in constantinople

Medium

Command Injection in hot-formula-parser

High

False-negative validation results in MINT transactions with invalid baton - slpjs

High

False-negative validation results in MINT transactions with invalid baton

High

discord-html not escaping HTML code blocks when lacking a language identifier

High

Downloads Resources over HTTP in rs-brightcove

High

Prototype Pollution in Dojox

Low

XSS in dojox due to insufficient escape in dojox.xmpp.util.xmlEncode

Medium

Cross-Site Scripting in seeftl

High

XSS in TinyMCE

Medium

Holder can generate proof of ownership for credentials it does not control in vp-toolkit

High

Holder can (re)create authentic credentials after receiving a credential in vp-toolkit

High

Cross-Site Scripting in fileview

High

Cross-Site Scripting in sanitize-html - sanitize-html - GHSA-3j7m-hmh3-9jmp

Medium

Information disclosure through error object in auth0.js

High

Introspection in schema validation in Apollo Server

Medium

Validation Bypass in slp-validate

High

Resources Downloaded over Insecure Protocol in igniteui

Low

Sandbox Breakout in realms-shim

High

Cross-Site Scripting in editor.md

Medium

Cross Site Scripting (XSS) in plotly.js

Medium

Missing Origin Validation in parcel-bundler - parcel-bundler

High

Denial of Service in nes

High

Critical severity vulnerability that affects slpjs

High

Downloads Resources over HTTP in jser-stat

Medium

Moderate severity vulnerability that affects validator - validator - GHSA-552w-rqg8-gxxm

Medium

Regular Expression Denial of Service in ssri

Medium

Sandbox Breakout in realms-shim - realms-shim

High

Default Express middleware security check is ignored in production

High

XSS Filter Bypass via Encoded URL in validator

Medium

Cross-Site Scripting in nunjucks

Medium

Cross-Site Scripting in handlebars

Medium

Arbitrary Code Injection in pouchdb

High

High severity vulnerability that affects gun

High

VBScript Content Injection in marked

Medium

Moderate severity vulnerability that affects marked

Medium

Prototype Pollution in async merge-object

High

Cross-Site Scripting in serialize-javascript

Medium

Low severity vulnerability that affects eye.js

Low

Downloads Resources over HTTP in strider-sauce

High

Prototype Pollution in merge-options

High

Downloads Resources over HTTP in openframe-glslviewer

High

Downloads Resources over HTTP in product-monitor

High

Multiple XSS Filter Bypasses in validator

Medium

ReDoS via long UserAgent header in ua-parser

High

Cross-Site Scripting in mustache

High

Regular Expression Denial of Service in parsejson

High

Path Traversal in socket.io-file

High

Regular expression denial of service in url-regex

High

ECDSA signature vulnerability of Minerva timing attack in jsrsasign

Medium

Stored XSS in TimelineJS3

High

Storing Password in Local Storage

Medium

Unrestricted Upload of File with Dangerous Type in blueimp-file-upload

High

Cross-Site Scripting in @progress/kendo-angular-editor

High

False-positive validity for NFT1 genesis transactions in SLPJS

High

Cross-Site Scripting in bootstrap-tagsinput

High

Cross-Site Scripting in jqtree

High

Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-p239-93f7-h6xf

High

Cross-Site Scripting (XSS) in pivottable

High

DOM-based XSS in auth0-lock

Low

Multiple Content Injection Vulnerabilities in marked

Medium

Authentication Bypass in console-io

High

Insecure randomness in socket.io

High

Moderate severity vulnerability that affects validator

Medium

Sensitive Data Exposure in msrcrypto

High

Downloads Resources over HTTP in js-given

High

Moderate severity vulnerability that affects validator - validator

Medium

Command Injection in wxchangba

Medium

Cross-Site Scripting in @berslucas/liljs

Medium

Malicious Package in rpc-websocket

High

Arbitrary Code Execution in mathjs - mathjs

High

Auth0-js bypasses CSRF checks

High

False-positive validity for NFT1 genesis transactions

High

XSS via JQLite DOM manipulation functions in AngularJS

Medium

Command Injection in ungit - ungit

High

Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-7f59-x49p-v8mq

High

Cross-Site Scripting in mrk.js

High

Cross-Site Scripting in react-marked-markdown

High

Denial of Service in ethereumjs-vm

High

Malicious Package in angular-material-sidenav-rnd

High

Malicious Package in cordova-plugin-china-picker

High

Arbitrary JavaScript Execution in typed-function

High

Cross-Site Scripting in semantic-ui-search

High

HTML Injection in preact

Medium

Cross-Site Scripting in cmmn-js-properties-panel

High

Prototype Pollution in lodash.defaultsdeep - lodash.defaultsdeep

High

Command Injection in marsdb

High

Cross-Site Scripting in fomantic-ui

High

Cross-Site Scripting in google-closure-library

Medium

Cross-Site Scripting in hexo-admin

High

Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-388g-jwpg-x6j4

Medium

Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-vp93-gcx5-4w52

Medium

Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-w992-2gmj-9xxj

Medium

DOM-based XSS in gmail-js

High

Incorrect Calculation in bigint-money

Low

Malicious Package in bmap

High

Regular Expression Denial of Service in ansi2html

High

Regular Expression Denial of Service in validator

High

Reverse Tabnabbing in quill

Medium

User Impersonation in converse.js

Medium

XSS in client rendered block templates in rendr

High

Denial of Service in handlebars

Medium

Prototype Pollution in sahmat

High

Cross-Site Scripting in atlasboard-atlassian-package

High

Cross-Site Scripting in bootstrap-select - bootstrap-select

High

HTML Injection in marky-markdown - marky-markdown

High

Improper Authorization in react-oauth-flow

High

Improper Authorization in @sap-cloud-sdk/core

High

Cross-Site Scripting in mermaid - mermaid

High

Denial of Service in serialize-to-js

High

Missing Origin Validation in browserify-hmr

High

Prototype Pollution in smart-extend

Medium

Command Injection in soletta-dev-app

High

Malicious Package in react-datepicker-plus

High

Malicious Package in vue-backbone

High

Cross-Site Scripting in diagram-js-direct-editing

Medium

Cross-Site Scripting in graylog-web-interface

High

Cross-Site Scripting in @ionic/core

High

Cross-Site Scripting in jquery.json-viewer - jquery.json-viewer

High

Path Traversal in zero

High

Cross-Site Scripting in dmn-js-properties-panel

High

Cross-Site Scripting in Prism - prismjs

High

Prototype Pollution in lodash.merge

High

Cross-Site Scripting in snekserve

High

CSRF Vulnerability in jquery-ujs

Medium

Cross-Site Scripting in yui

Medium

Arbitrary File Write in iobroker.admin

High

Prototype Pollution in get-setter

High

Prototype Pollution in getsetdeep

High

Prototype Pollution in handlebars - handlebars - GHSA-g9r4-xpmj-mj65

High

Malicious Package in awesome_react_utility

High

Malicious Package in codify

High

Malicious Package in json-serializer - json-serializer

High

Command Injection in ascii-art

Low

Cross-Site Scripting in buefy

High

Cross-Site Scripting in markdown-it-katex

High

Cross-Site Scripting in md-data-table

High

HTML Injection in marky-markdown

Medium

Insecure Cryptography Algorithm in parsel

High

Insufficient Entropy in parsel

High

Cross-Site Scripting in htmr

High

Cross-Site Scripting in wangeditor

High

Cross-Site Request Forgery (CSRF) in Auth0

High

Malicious Package in motiv.scss

High

Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-22q9-hqm5-mhmc

Medium

Malicious Package in zemen

High

Path Traversal in ponse

High

Prototype Pollution in lodash.defaultsdeep

High

Prototype Pollution in mergify

Medium

Prototype Pollution in mithril

High

Unauthorized File Access in atompm

High

Configuration Override in helmet-csp

Medium

Cross-Site Scripting in eco

High

ReDOS vulnerabities: multiple grammars - highlight.js

Medium

ReDOS vulnerabities: multiple grammars

Medium

Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-876r-hj45-fw7g

High

Cross-Site Scripting in react

High

Prototype Pollution in flat-wrap

High

Prototype Pollution in safe-object2 - safe-object2

High

Prototype Pollution in unflatten

High

Client TLS credentials sent raw to server in npm package nats

High

Cross-Site Scripting in ngx-md

High

Path Traversal in sapper

High

Potential XSS in jQuery dependency in Mirador

Medium

Prototype Pollution in json-logic-js

High

Unrestricted Upload of File with Dangerous Type in jquery-file-upload

High

Authentication Bypass in otpauth

High

Cross-Site Scripting in console-feed

High

Malicious Package in rate-map

High

Prototype Pollution in lodash.merge - lodash.merge

High

Prototype Pollution in lodash.mergewith - lodash.mergewith

High

Prototype Pollution in lodash.mergewith

High

Cross-Site Scripting in mavon-editor

Medium

Malicious Package in json-serializer

High

Cross-Site Scripting in markdown-to-jsx - markdown-to-jsx

High

Machine-In-The-Middle in airtable

High

Arbitrary Code Execution in handlebars - handlebars - GHSA-q2c6-c6pm-g3gh

High

Regular Expression Denial of Service in markdown

Low

Cross-Site Scripting in nextcloud-vue-collections

High

Outdated Static Dependency in vue-moment

Medium

Regex denial of service vulnerability in codesample plugin

Low

Signatures are mistakenly recognized to be valid in jsrsasign

Medium

Hardcoded Initialization Vector in parsel

High

Server-Side Request Forgery in @uppy/companion - @uppy/companion

High

Verification flaw in Solid identity-token-verifier

Medium

Improperly Controlled Modification of Object Prototype Attributes

High

Cross-site scripting vulnerability in TinyMCE - tinymce - GHSA-5vm8-hhgr-jcjp

Medium

Improper Verification of Cryptographic Signature in aws-encryption-sdk-javascript

Medium

Regular Expression Denial of Service in millisecond

Medium

Execution with Unnecessary Privileges in arc-electron

High

Removal of functional code in faker.js

High

Inefficient Regular Expression Complexity in Validator.js - validator

Medium

Marked ReDoS due to email addresses being evaluated in quadratic time

Medium

fuelux vulnerable to Cross-Site Scripting in Pillbox feature

High

Pannellum Cross-Site Scripting due to data not being sanitized for URIs or vbscript

Medium

cookie-signature Timing Attack

Medium

Path traversal for local publishers in TechDocs backend

Medium

Arbitrary Code Execution in require-node

High

Regular Expression Denial of Service in slug

Medium

Cleartext Transmission of Sensitive Information in moment-timezone

Medium

Command Injection in moment-timezone

Low

gatsby-transformer-remark has possible unsanitized JavaScript code injection

High

Cross-site Scripting in bootstrap-table - bootstrap-table

Low

RSSHub SSRF vulnerability

High

Prototype Pollution in chartkick

High

Improper Input Validation in url-js

Medium

Spoofing attack in swagger-ui-dist

Medium

Sudden swap of user auth tokens in Volto

Medium

Cross-site Scripting in sanitize-url

Medium

Server-Side Request Forgery in FUXA

High

Command injection in launchpad

High

yargs-parser Vulnerable to Prototype Pollution

Medium

Prototype Pollution in algoliasearch-helper

High

Cross-site Scripting in CKEditor4

Medium

Prototype Pollution in mathjs

High

Prototype Pollution in mout - mout

High

Prototype Pollution in set-in

High

Prototype pollution vulnerability in js-extend

High

Failure to validate signature during handshake

High

Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML

High

modern-async's `forEachSeries` and `forEachLimit` functions do not limit the number of requests

High

Prototype Pollution in ts-nodash

High

Utils.readChallengeTx does not verify the server account signature

Medium

Prototype Pollution in libnested

High

Command Injection in ungit

High

Prototype pollution in supermixer

High

Cross-site Scripting in @rocket.chat/livechat

Medium

URL Confusion When Scheme Not Supplied in medialize/uri.js

Medium

Cross site scripting in valine

Medium

Cross-site Scripting in tableexport.jquery.plugin

Medium

Prototype Pollution in fullpage.js

High

Cross-site Scripting in fullpage.js

Medium

Prototype Pollution in madlib-object-utils

High

Unrestricted Upload of File with Dangerous Type in ButterCMS

High

Unrestricted Upload of File with Dangerous Type in Payload

High

Improper handling of multiline messages in node-irc affects matrix-appservice-irc

High

Cross-site Scripting in Auth0 Lock

Medium

Prototype Pollution in json-pointer

Medium

x-data-spreadsheet through 1.1.9 vulnerable to Cross-site Scripting

Medium

Prototype pollution in dojo - dojo

High

Improper Neutralization of Input During Web Page Generation in CKEditor4

Medium

Improper Neutralization of Input During Web Page Generation in swagger-ui

Medium

Improper Control of Generation of Code in doT

High

Improper Neutralization of Input During Web Page Generation in Select2

Medium

Improper Removal of Sensitive Information Before Storage or Transfer in Strapi - @strapi/strapi

High

Improper Removal of Sensitive Information Before Storage or Transfer in Strapi

High

Improper Input Validation in Deap

High

AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes

Medium

cruddl vulnerable to ArangoDB Query Language (AQL) injection through flexSearch

High

OpenPGP 1.2.0 and earlier decrypts arbitrary messages

High

Unsanitized JavaScript code injection possible in gatsby-plugin-mdx

High

Potential Sensitive Cookie Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxy

Medium

Improper handling of CSS at-rules in lettersanitizer

High

Hostname confusion in parse-url

High

Server-Side Request Forgery in parse-url

High

Potential Authorization Header Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxy

Medium

jquery-validation Regular Expression Denial of Service due to arbitrary input to url2 method

High

Cross site scripting in parse-url

Medium

Prototype Pollution in deep-get-set

High

JWS and JWT signature validation vulnerability with special characters

High

Regular expression denial of service in react-native

High

Server-Side Request Forgery in link-preview-js

Medium

Cross site scripting in parse-url - parse-url

Medium

Authorization Bypass in parse-path

High

set-deep-prop Prototype Pollution

High

ion-parser Prototype Pollution when malicious INI file submitted to application that parses with `parse`

High

node-import `params` argument can be controlled by users without any sanitization

High

ts-deepmerge before 2.0.2 vulnerable to Prototype Pollution

High

markdown-it-toc Cross-site Scripting due to title of generated toc and contents of header not being escaped

Medium

grapesjs before 0.19.5 vulnerable to Cross-site Scripting

Medium

Improperly Controlled Modification of Dynamically-Determined Object Attributes in utilitify

High

Improperly Controlled Modification of Dynamically-Determined Object Attributes in vega-util

Medium

Prototype Pollution in cookiex/deep

High

Uncontrolled Resource Consumption in fun-map

High

Prototype Pollution in arr-flatten-unflatten

High

Prototype pollution in class-transformer

Medium

Prototype Pollution in madlib-object-utils - madlib-object-utils

High

Prototype Pollution in x-assign

High

Solana Pay Vulnerable to Weakness in Transfer Validation Logic

Medium

Cross-Site Scripting in min-http-server

Medium

Prototype pollution in chart.js

High

Prototype Pollution in property-expr

High

RSA-PSS signature validation vulnerability by prepending zeros in jsrsasign

High

Cross site scripting in mobiledoc-kit

Medium

Uncontrolled Resource Consumption in node-opcua

High

parse-url parses http URLs incorrectly, making it vulnerable to host name spoofing

Medium

Matrix-appservice-irc vulnerable to sql injection via roomIds argument

Medium

deep-object-diff vulnerable to Prototype Pollution

Medium

Cross-site scripting vulnerability in TinyMCE alerts

Medium

@cubejs-backend/api-gateway row level security bypass

High

dustjs-linkedin vulnerable to Prototype Pollution

High

Jodit Editor vulnerable to Cross-site Scripting - jodit

Medium

secp256k1-js implements ECDSA without required r and s validation, leading to signature forgery

High

matrix-appservice-irc vulnerable to IRC mode parameter confusion

Medium

Parsing issue in matrix-org/node-irc leading to room takeovers

High

@mattkrick/sanitize-svg vulnerable to Cross-Site Scripting (XSS)

High

Cross-site Scripting in Joplin

Medium

inflect vulnerable to Inefficient Regular Expression Complexity

High

merge vulnerable to Prototype Pollution

High

cumulative-distribution-function Infinite Loop vulnerability

High

prismjs Regular Expression Denial of Service vulnerability

Medium

Improper Input Validation in Google Closure Library

Medium

deep-parse-json vulnerable to Prototype Pollution

Medium

Improper Control of Generation of Code ('Code Injection') in mdx-mermaid

Low

DOM-based cross-site scripting in Froala Editor

Medium

Options structure open to Cross-site Scripting if passed unfiltered

High

Prototype poisoning

Medium

Remote code execution in Eclipse Theia

High

Joplin is vulnerable to arbitrary code execution

High

Smoothie vulnerable to Cross-site Scripting when tooltipLabel or strokeStyle are controlled by users

Medium

node-opcua DoS vulnerability via message with memory allocation that exceeds v8's memory limit

High

node-opcua DoS when bypassing limitations for excessive memory consumption

High

matrix-js-sdk subject to user impersonation due to key/device identifier confusion in SAS verification

High

steal vulnerable to Prototype Pollution via optionName variable

High

Inefficient Regular Expression Complexity in vuelidate

High

TypeORM vulnerable to MAID and Prototype Pollution

High

Improper beacon events in matrix-js-sdk can result in availability issues

Medium

steal vulnerable to Prototype Pollution via key variable in babel.js

High

steal vulnerable to Prototype Pollution via requestedVersion variable

High

matrix-js-sdk subject to impersonated messages due to permissive key forwarding

High

CKEditor 5 Markdown plugin Regular expression Denial of Service

Medium

matrix-js-sdk subject to user spoofing via Olm/Megolm protocol confusion

High

ejs template injection vulnerability

High

@dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability Details

Medium

jsx-slack insufficient patch for CVE-2021-43838 ReDoS

Medium

jquery.terminal self XSS on user input

Low

Vuetify Cross-site Scripting vulnerability

Medium

Prototype Pollution in mout

High

Fastly Compute@Edge JS Runtime has fixed random number seed during compilation

High

React Editable Json Tree vulnerable to arbitrary code execution via function parsing

High

Cross-site Scripting (XSS) in serve-lite

Medium

Directory Traversal vulnerability in serve-lite

High

TaffyDB can allow access to any data items in the DB - taffy

High

TaffyDB can allow access to any data items in the DB

High

RSA PKCS#1 decryption vulnerability with prepending zeros in jsrsasign

High

ECDSA signature validation vulnerability by accepting wrong ASN.1 encoding in jsrsasign

High

Prototype Pollution in dojo

High

Path Traversal in mcstatic

High

metascraper before v5.2.0 vulnerable to stored cross-site scripting

Medium

CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - @ckeditor/ckeditor5-html-support

Medium

CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - @ckeditor/ckeditor5-markdown-gfm

Medium

CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process

Medium

@ianwalter/merge Prototype Pollution via `merge` function

Medium

Nadesiko3 OS Command Injection vulnerability

High

nadesiko3 allows remote attacker to inject invalid value to decodeURIComponent of nako3edit

Medium

nadesiko3 vulnerable to OS Command Injection

High

steal vulnerable to Prototype Pollution

High

Valine code injection vulnerability

High

Toast UI Grid vulnerable to Cross-site Scripting

Medium

steal vulnerable to Prototype Pollution via alias variable

High

Regular Expression Denial of Service in ua-parser-js

High

Prototype Pollution in dset

Medium

materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input

Medium

Privilege Issues in jailed

High

Prototype Pollution in Dexie

High

Insecure password handling vulnerability in Strapi

High

Cross-site Scripting in video.js

Medium

Cross-site Scripting in jquery.json-viewer

Medium

Cross-site Scripting in pandao editor.md

Medium

Invalid Curve Attack in openpgp

Medium

Cross-site Scripting in node-red-dashboard

Medium

Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-hgch-jjmr-gp7w

High

Cross-site Scripting in pandao

Medium

Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-r3x4-wr4h-pw33

High

XSS in knockout

Medium

Uncaught exception in engine.io

Medium

Denial of Service and Content Injection in i18n-node-angular

High

Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval

High

node-red-dashboard vulnerable to Cross-site Scripting

Medium

Cross-Site Scripting in @novnc/novnc

Medium

Cross-site Scripting in Joplin - joplin - GHSA-6r7x-hc8m-985r

Medium

Unprotected dynamically loaded chunks

Low

Prototype Pollution in highlight.js

Medium

Axios vulnerable to Server-Side Request Forgery

Medium

regular expression denial of service (ReDoS) - date-and-time

High

Regular Expression Denial of Service (REDoS) in Marked

Medium

SSRF in Rendertron

Medium

Prototype pollution in JointJS - jointjs

High

Angular Expressions - Remote Code Execution

High

Prototype pollution in set-in - set-in

High

Cross-site Scripting in vis-timeline

Medium

Regular expression Denial of Service in @progfay/scrapbox-parser

Medium

Cross-site Scripting (XSS) in Eclipse Theia

High

[thi.ng/egf] Potential arbitrary code execution of `#gpg`-tagged property values

Medium

Prototype Pollution Vulnerability in object-collider

High

Denial of Service (DoS) via the unsetByPath function in jsjoints

High

Hostname spoofing via backslashes in URL

Medium

Improper Neutralization of Input in Theia console

Medium

XSS in Vega

Low

Cross-site scripting in SocksJS-node

Medium

Path traversal in Node-RED-Dashboard

High

Prototype Pollution in dot-object

Medium

Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-engine

Medium

Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-font

Medium

Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-image

Medium

Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-list

Medium

Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-media-embed

Medium

Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-paste-from-office

Medium

Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-widget

Medium

Regular expression Denial of Service in multiple packages

Medium

Server-Side Request Forgery in private-ip

High

Prototype Pollution in decal - decal

High

Regular Expression Denial of Service (ReDoS) in ua-parser-js

High

Arbitrary code execution in djv

High

Prototype pollution in set-object-value

High

Prototype Pollution in copy-props

High

Regular Expression Denial of Service in hosted-git-info

Medium

Improper Input Validation in klona

High

Improper Input Validation in sanitize-html - sanitize-html

Medium

Insufficient Verification of Data Authenticity in Eclipse Theia

High

Improper Input Validation in SocksJS-Node

Medium

Prototype Pollution in undefsafe

Medium

Resource exhaustion in socket.io-parser

High

Padding Oracle Attack due to Observable Timing Discrepancy in jose

Medium

Prototype pollution in json8-merge-patch

High

Cross-site Scripting in reveal.js - reveal.js

Medium

Improper Authentication in react-adal

High

Prototype pollution in pathval

High

Prototype Pollution in set-or-get

High

Regular expression denial of service in codemirror

Medium

Regular Expression Denial of Service in dat.gui

High

Regular Expression Denial of Service in trim

High

Cross-site scripting in @atlaskit/editor-core

Medium

Buffer overflow in canvas

High

Prototype pollution in json8

High

Prototype Pollution in node-oojs

High

Prototype Pollution in phpjs

High

Prototype Pollution in promisehelpers

High

Regular expression denial of service in @absolunet/kafe

Medium

Path traversal in rollup-plugin-serve

High

Prototype Pollution in tiny-conf

High

Improper Input Validation in access-policy

High

Improper parsing of octal bytes in netmask

High

Prototype Pollution in gedi

High

Insecure template handling in haml-coffee

High

Regular Expression Denial of Service in postcss - postcss

Medium

Cross-site scripting in Joplin - joplin

Medium

Cross-site Scripting in aurelia-framework

Medium

Validation bypass in jpv

High

Command Injection in @theia/messages

Medium

Exposure of Resource to Wrong Sphere in valib

Medium

Prototype Pollution in swiper

High

ua-parser-js Regular Expression Denial of Service vulnerability

High

Injection and Command Injection in devcert

High

Uncontrolled Resource Consumption in firebase

Medium

Code Injection in cd-messenger

High

Prototype pollution in controlled-merge

High

Prototype Pollution in deep-get-set - deep-get-set

High

Prototype Pollution in safe-object2

High

Cross-site Scripting in docsify

Medium

Code Injection in mosc

High

Prototype Pollution in deep-override

High

Cross-site scripting in react-bootstrap-table

Medium

Regular Expression Denial of Service (ReDoS) in Prism

High

Widget feature vulnerability allowing to execute JavaScript code using undo functionality

High

Prototype pollution in safe-obj

High

Clipboard feature vulnerability allowing to inject arbitrary HTML into the editor using paste functionality

Medium

Denial of service in Valine

Medium

Reflected XSS when using flashMessages or languageDictionary

High

Passing in a non-string 'html' argument can lead to unsanitized output

Medium

ReDOS in IS-SVG

High

Regular Expression Denial of Service (ReDOS) - color-string

Medium

Cross-site Scripting in curly-bracket-parser

Medium

Fake objects feature vulnerability allowing to execute JavaScript code using malformed HTML.

High

Prototype Pollution in deepmergefn

Medium

Clipboard-based DOM-XSS

Medium

Prototype Pollution in mootools

Medium

Incorrect Calculation in the MSR JavaScript Cryptography Library

High

Cross-site Scripting in file-upload-with-preview

Medium

Prototype Pollution in jointjs

Medium

Uncontrolled Resource Consumption in transpile

Medium

Path traversal

Medium

Prototype pollution vulnerability in 'patchmerge

High

Script injection - @backstage/plugin-techdocs

Medium

Script injection

Medium

Cross-site Scripting in jsoneditor

Medium

Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4

Medium

Basic-auth app bundle credential exposure in gatsby-source-wordpress

High

Cross-site Scripting in Mermaid

Medium

Cross-site Scripting in tempura

Medium

Improper Input Validation in is-email

High

Prototype pollution in aurelia-path

High

XSS vulnerability allowing arbitrary JavaScript execution

Medium

Cross-site scripting in anchorme

Medium

Cross-site Scripting in Froala Editor - froala-editor

Medium

Cross Site Request Forgery in kindeditor

High

GraphiQL introspection schema template injection attack

High

Unauthorized access to data in @sap-cloud-sdk/core

Medium

Uncontrolled Resource Consumption in trim-off-newlines

Medium

Prototype Pollution in merge-change

High

Unsafe defaults in `remark-html`

High

Prototype pollution vulnerability in 'deepref

High

Cross-site Request Forgery (CSRF) in joplin

Medium

Cross site scripting in kindeditor

Medium

Prototype Pollution in Proto

High

Clipboard-based XSS

High

Improper Verification of Communication Channel in @theia/plugin-ext

Medium

Code injection in plupload

Medium

Prototype pollution vulnerability in 'libnested

High

Risk of code injection

High

Insecure random number generation in keypair

High

Cross-Site Scripting Vulnerability in @joeattardi/emoji-button

High

Prototype Pollution in dotty - dotty

Medium

Cross-site Scripting in pekeupload

Medium

Prototype Pollution in @fabiocaccamo/utils.js

High

Strapi mishandles hidden attributes within admin API responses

High

Twitter-Post-Fetcher vulnerable to Use of Web Link to Untrusted Target with window.opener Access

Medium

Misinterpretation of malicious XML input - xmldom - GHSA-h6q6-9hqw-rwfv

Medium

liquidjs may leak properties of a prototype

Medium

Expo on iOS is insecure due incorrect security attribute application

Medium

Markdown-Nice v1.8.22 vulnerable to Cross-site Scripting

Medium

Cross-site Scripting in Bootstrap-3-Typeahead

Medium

Cross-site Scripting in bootstrap-table

Medium

markdown-it vulnerable to Inefficient Regular Expression Complexity

High

string-kit Inefficient Regular Expression Complexity vulnerability

High

Json2html vulnerable to cross-site scripting

Medium

Cross site scripting in Metro UI

Medium

Regular Expression Denial of Service in moment - moment

Medium

Prototype Pollution in js-data - js-data

High

uppy's companion module is vulnerable to Server-Side Request Forgery (SSRF) - uppy

High

Reflected cross-site scripting (XSS) vulnerability

High

Incorrect sanitisation function leads to `XSS` in mermaid

High

Prototype Pollution in realms-shim - realms-shim

High

Prototype Pollution in realms-shim

High

Cross site scripting in three.js

High

Exposure of Sensitive Information in simple-get

High

Prototype Pollution in keyget

Medium

Cross-site Scripting in karma

Medium

Server-Side Request Forgery in @peertube/embed-api

Medium

Cross site scripting in @awsui/components-react

High

Open redirect in karma

Medium

Authorization Bypass Through User-Controlled Key in urijs

Medium

Prototype Pollution in litespeed.js and appwrite/server-ce

High

Leading white space bypasses protocol validation

Medium

Prototype Pollution in object-extend

High

Cross-site Scripting in Prism

High

Cross site scripting in reveal.js

Medium

Open Redirect in urijs

Medium

Eta vulnerable to Code Injection via templates rendered with user-defined data

High

Joplin Desktop App vulnerable to Cross-site Scripting

Medium

XSS Attack with Express API

High

Cross site scripting in froala-editor

Medium

Cross site scripting Vulnerability in backstage Software Catalog - @backstage/core-components

Medium

Cross site scripting Vulnerability in backstage Software Catalog

Medium

jSuites subect to Cross-site Scripting

Medium

Improper calculations in ECC implementation can trigger a Denial-of-Service (DoS)

High

iziModal Cross-site Scripting vulnerability

Medium

Baremetrics date range picker vulnerable to Cross-site Scripting

Medium

textAngular Cross-site Scripting vulnerability

Medium

Mind-elixir Cross-site Scripting vulnerability

Medium

Cross-Site-Scripting attack on `<RichTextField>` - react-admin

Medium

Cross-Site-Scripting attack on `<RichTextField>`

Medium

Cross-site scripting in CKEditor5

Medium

Cross-site Scripting in dijit editor's LinkDialog plugin

Low

Path Traversal in localhost-now - localhost-now - GHSA-2gjg-5x33-mmp2

High

Cross-site Scripting in jspreadsheet

Medium

Vega vulnerable to arbitrary code execution when clicking href links

Medium

@braintree/sanitize-url Cross-site Scripting vulnerability

Medium

rangy vulnerable to Prototype Pollution

High

xterm vulnerable to remote code execution

High

mde utilities contains Prototype Pollution

High

Vega Expression Language `scale` expression function Cross Site Scripting - vega

Medium

Vega Expression Language `scale` expression function Cross Site Scripting

Medium

dot-lens vulnerable to Prototype Pollution

High

Vega has Cross-site Scripting vulnerability in `lassoAppend` function - vega

Medium

Vega has Cross-site Scripting vulnerability in `lassoAppend` function

Medium

rsshub vulnerable to Cross-site Scripting via unvalidated URL parameters

Medium

Padding Oracle Attack due to Observable Timing Discrepancy in jose-node-esm-runtime

Medium

Padding Oracle Attack due to Observable Timing Discrepancy in jose-node-cjs-runtime

Medium

Arbitrary local file read vulnerability during template rendering - swig-templates

High

Arbitrary local file read vulnerability during template rendering

High

angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend

High

Padding Oracle Attack due to Observable Timing Discrepancy in jose-browser-runtime

Medium

Content Injection via TileJSON Name in mapbox.js

Medium

Content Injection via TileJSON attribute in mapbox.js

Medium

matrix-js-sdk Prototype Pollution vulnerability

High

fastify/websocket vulnerable to uncaught exception via crash on malformed packet

High

xmldom allows multiple root nodes in a DOM - xmldom

High

xmldom allows multiple root nodes in a DOM

High

CKEditor 4.0 vulnerability in the HTML Data Processor

Medium

Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-g336-c7wv-8hp3

High

Cross-Site Scripting in @toast-ui/editor

High

Cross-Site Scripting in bootstrap-vue

High

Content Injection in remarkable

High

Cross-Site Scripting in webtorrent

Medium

Cross-Site Scripting in c3

Medium

Reverse Tabnabbing in showdown

Low

SvelteKit vulnerable to Cross-Site Request Forgery

High

phoenix_html allows Cross-site Scripting in HEEx class attributes

Medium

Pandao Editor.md vulnerable to cross-site scripting (XSS) in editor parameter

Medium

Pandao Editor.md vulnerable to cross-site scripting (XSS) in iframe src parameter

Medium

Regular Expression Denial of Service in hawk

High

Regular Expression Denial of Service in highcharts - highcharts

High

Denial of Service in protobufjs - protobufjs

Medium

Regular Expression Denial of Service in clean-css

Low

Regular Expression Denial of Service in marked - marked - GHSA-ch52-vgq2-943f

Low

Regular Expression Denial of Service in moment

High

Denial of Service in axios

High

SvelteKit framework has Insufficient CSRF protection for CORS requests

High

Insecure Cryptography Algorithm in simple-crypto-js

Medium

Authentication Bypass in @strapi/plugin-users-permissions

High

Improper Input Validation in sanitize-html

Medium

Out-of-bounds Read in base64url

Medium

Switcher Client contains Regular Expression Denial of Service (ReDoS)

High

matrix-js-sdk vulnerable to invisible eavesdropping in group calls

Medium

Cross-Site Scripting in @ckeditor/ckeditor5-link

Medium

Cross-site scripting vulnerability in TinyMCE - tinymce - GHSA-vrv8-v4w8-f95h

Medium

Cross-Site Scripting in react - react

Medium

Prototype pollution in matrix-js-sdk (part 2)

High

Server side request forgery in SwaggerUI - swagger-ui-dist

Medium

Server side request forgery in SwaggerUI - swagger-ui-react

Medium

Server side request forgery in SwaggerUI

Medium

@claviska/jquery-minicolors vulnerable to Cross-site Scripting

Medium

Deserialization of Untrusted Data in bson - bson

Medium

Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url

High

Out-of-bounds Read in atob

High

Incorrect Authorization in @uppy/companion

High

Uncaught Exception in engine.io - engine.io

High

Cross-site scripting vulnerability in TinyMCE - tinymce - GHSA-27gm-ghr9-4v95

High

Leaking of user information on Cross-Domain communication in sysend

Medium

@vendure/admin-ui-plugin authenticated Cross-site Scripting vulnerability

Medium

is_js vulnerable to Regular Expression Denial of Service

High

Cross-Site Scripting in jquery - jquery

Medium

RCE in SiteServer CMS

High

semver-regex Regular Expression Denial of Service (ReDOS)

High

jquery-plugin-query-object contains prototype pollution vulnerability

High

Kibana Sensitive Data Disclosure

Medium

eivindfjeldstad-dot contains prototype pollution vulnerability

Medium

Validation bypass in frourio

High

Validation bypass in frourio-express

High

Malicious Package in radicjs

High

Malicious Package in pm-controls

High

xdlocalstorage does not verify request origin

High

Regular expression denial of service in semver-regex

Low

Regular Expression Denial of Service (ReDoS) in jsx-slack

Low

Possible inject arbitrary `CSS` into the generated graph affecting the container HTML

Medium

JOSE vulnerable to resource exhaustion via specifically crafted JWE - jose-browser-runtime

Medium

JOSE vulnerable to resource exhaustion via specifically crafted JWE - jose-node-cjs-runtime

Medium

JOSE vulnerable to resource exhaustion via specifically crafted JWE - jose-node-esm-runtime

Medium

JOSE vulnerable to resource exhaustion via specifically crafted JWE

Medium

Potential exposure of tokens to an Unauthorized Actor

Medium

Uncontrolled Resource Consumption in markdown-it

Medium

Denial of Service (DoS) vulnerability in RSSHub

Medium

Malicious Package in leaflet-gpx

High

Malicious Package in coffee-project

High

Malicious Package in ember-power-timepicker

High

Malicious Package in geoheat

High

Malicious Package in angular-location-update

High

Malicious Package in libubx

High

Malicious Package in jasmin

High

Malicious Package in oauth-validator

High

Malicious Package in react-dates-sc

High

Malicious Package in ngx-pica

High

Malicious Package in github-jquery-widgets

High

Malicious Package in scroool

High

Malicious Package in precode.js

High

Malicious Package in react-server-native

High

Malicious Package in mx-nested-menu

High

Malicious Package in device-mqtt

High

v8n vulnerable to Inefficient Regular Expression Complexity

High

Malicious Package in radic-util

High

Prototype Pollution in backbone-query-parameters

High

matrix-js-sdk can be tricked into disclosing E2EE room keys to a participating homeserver

Medium

@excalidraw/excalidraw Cross-site Scripting vulnerability

Medium

Prototype pollution in dotty

High

Prototype Pollution in lutils

Medium

Prototype pollution in nestie

High

Regular Expression Denial of Service in browserslist

Medium

steal vulnerable to Regular Expression Denial of Service via source and sourceWithComments

High

steal Inefficient Regular Expression Complexity vulnerability via string variable

High

Angular critical CSS inlining Cross-site Scripting Vulnerability Advisory

High

Materialize-css vulnerable to Improper Neutralization of Input During Web Page Generation - materialize-css

Medium

Materialize-css vulnerable to Improper Neutralization of Input During Web Page Generation

Medium

Materialize-css vulnerable to Cross-site Scripting in tooltip component - materialize-css

Medium

Materialize-css vulnerable to Cross-site Scripting in tooltip component

Medium

Materialize-css vulnerable to Cross-site Scripting in autocomplete component - materialize-css

Medium

Materialize-css vulnerable to Cross-site Scripting in autocomplete component

Medium

dijit editor cross-site scripting vulnerability

Medium

Regular Expression Denial of Service in jquery-validation

High

Prototype Pollution in js-data

High

Prototype pollution in @tsed/core

Medium

Cross-site Scripting in markdown-it-highlightjs

Medium

Prototype Pollution in decal

High

Denial of service in prismjs

High

js-bson vulnerable to REDoS

High

Inefficient Regular Expression Complexity in handsontable

High

rendertron can remotely shut down Chrome instance

High

dalek-browser-chrome Downloads Resources over HTTP

High

rendertron LFI vulnerability

High

rendertron XSS vulnerability

Medium

ReDoS via long UserAgent header in useragent

High

Invalid Curve Attack in node-jose

Medium

Elliptic Uses a Broken or Risky Cryptographic Algorithm

Medium

Rendertron discloses absolute paths of files

High

SimpleMDE XSS Vulnerability

Medium

Svelte vulnerable to XSS when using objects during server-side rendering

Medium

Valine HTML Injection

Medium

Directory Traversal in commentapp.stetsonwood

High

opencv.js is malware

High

Command injection in github-todos

High

steal vulnerable to Regular Expression Denial of Service via input variable

High

dalek-browser-ie downloads Resources over HTTP

High

URIjs Vulnerable to Hostname spoofing via backslashes in URL

Medium

Template Injection in jsrender

Medium

Regular Expression Denial of Service in marked - marked

High

Sanitization bypass using HTML Entities in marked

Medium

Prototype Pollution in deephas

High

openssl.js is malware

High

Insecure Defaults Allow MITM Over TLS in engine.io-client

Medium

Marked vulnerable to XSS from data URIs

Medium

Cross-site scripting in jspdf - jspdf

Medium

Cross-site scripting in jspdf

Medium

Regular Expression Denial of Service in content

High

Cross-site Scripting in remarkable

Medium

Code injection in mock2easy

High

Regular Expression Denial of Service in postcss

Medium

Pandao editor.md vulnerable to DOM XSS

Medium

XSS in Data URI in remarkable

High

Regular Expression Denial of Service in decamelize

High

Pandao editor.md vulnerable to XSS in IMG attributes

Medium

jspdf vulnerable to Regular Expression Denial of Service (ReDoS)

High

netmask npm package mishandles octal input data

Medium

ejs is vulnerable to remote code execution due to weak input validation

High

Cryptographically Weak PRNG in randomatic

Medium

ejs vulnerable to DoS due to weak input validation

High

Prototype Pollution in sey

Medium

node-browser downloads Resources over HTTP

High

mde ejs vulnerable to XSS

Medium

Prototype Pollution in field

High

Cross-Site Scripting in sanitize-html - sanitize-html

Medium

Cross-Site Scripting in sanitize-html

Medium

superagent vulnerable to zip bomb attacks

Medium

Cross-Site Scripting in i18next - i18next

Medium

Cross-Site Scripting in i18next

Medium

Macro in MathJax running untrusted Javascript within a web browser

Medium

Insecure template handling in Squirrelly

High

Denial of service in three

High

selenium-chromedriver Downloads Resources over HTTP

High

auth0-lock vulnerable to XSS via unsanitized placeholder property

Medium

pym.js CSRF Vulnerability

High

d3.js is malware

High

dalek-browser-ie-canary downloads Resources over HTTP

High

Path Traversal in localhost-now

High

Prototype Pollution in record-like-deep-assign

High

RSA signature validation vulnerability on maleable encoded message in jsrsasign

High

Sensitive data exposure in NATS - nats

High

Sensitive data exposure in NATS

High

Regular Expression Denial of Service in no-case

High

bracket-template vulnerable to reflected XSS

Medium

Regular Expression Denial of Service in jadedown

Low

Cross-site Scripting in React Draft Wysiwyg

Medium

cloudpub-redis downloads Resources over HTTP

High

CORS misconfiguration in socket.io

Medium

Code Injection in jsen

High

Regular Expression Denial of Service in djvalidator

High

Directory Traversal in rtcmulticonnection-client

High

Directory Traversal in cyber-js

High

Directory Traversal in xtalk

High

XSS in hello.js

High

Credential leak in react-native-fast-image

Medium

Remote Code Execution in scratch-vm

High

mime Regular Expression Denial of Service when MIME lookup performed on untrusted user input

High

selenium-wrapper downloads Resources over HTTP

High

Code Injection in cryo

High

Arbitrary Code Execution in mathjs

High

Regular Expression Denial of Service in riot-compiler

High

mcstatic directory traversal vulnerability

High

Bypassing Sanitization using DOM clobbering in html-janitor

Medium

html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS) - html-parse-stringify

Medium

html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS)

Medium

XSS in apexcharts

Medium

Prototype pollution in gsap

High

Cross-Site Scripting in html-janitor

Medium

Directory Traversal in fbr-client

High

Server-Side Request Forgery in @uppy/companion

High

Regular Expression Denial of Service in timespan

High

Electron vulnerable to URL spoofing via PDFium

Medium

Docsify XSS Vulnerability

Medium

auth0-js Privilege Escalation Vulnerability

High

tiny-json-http missing SSL certificate validation

High

DataTable Vulnerable to Cross-Site Scripting

High

Directory Traversal in datachannel-client

High

Prototype Pollution in asciitable.js

High

Cross-site Scripting in epubjs

Medium

jszip Vulnerable to Prototype Pollution

Medium

Regular Expression Denial of Service (ReDoS) - ssri

High

Regular Expression Denial of Service (ReDoS)

High

Inefficient Regular Expression Complexity in chalk/ansi-regex

High

decode-uri-component vulnerable to Denial of Service (DoS)

High

Cross-Site Scripting (XSS) in jquery

Medium

hexo-admin plugin for Node.js XSS Vulnerability

Medium

Cezerin Unauthorized Acces

High

jQuery-UI vulnerable to Cross-site Scripting in dialog closeText

Medium

XSS in `*Text` options of the Datepicker widget in jquery-ui

Medium

bson-objectid contains Improper input validation

High

XSS in the `altField` option of the Datepicker widget in jquery-ui

Medium

dojox vulnerable to unescaped string injection

High

Cross-Site Scripting in dojo

Medium

Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-4f9m-pxwh-68hg

Medium

Cross-Site Scripting in diagram-js

Medium

Etherpad Lite Access Restriction Bypass

High

Angular Redactor XSS Vulnerability

Medium

Converse.js Exposure of Sensitive Information

Medium

Simditor XSS Vulnerability

Medium

Cross-Site Scripting in swagger-ui - swagger-ui

High

Cisco node-jose improper validation of JWT signature

High

Auth0 angular-jwt misinterprets allowlist as regex

Medium

keyget vulnerable to prototype pollution

High

Grunt-karma vulnerable to prototype pollution

High

Xen Orchestra Mishandles Authorization

Medium

Docsify vulnerable to cross-site scripting due to mishandled encoding

Medium

mxGraph vulnerable to cross-site scripting in color field

Medium

MJML vulnerable to path traversal

High

mxGraph vulnerable to cross-site scripting in setTooltips function

Medium

mxGraph vulnerable to XXE attacks

High

rgb2hex vulnerable to inefficient regular expression complexity

High

skeemas Inefficient Regular Expression Complexity vulnerability

High

is-url Inefficient Regular Expression Complexity vulnerability

High

debug Inefficient Regular Expression Complexity vulnerability

High

Cross-realm object access in Webpack 5

High

EpicEditor XSS Vulnerability

Medium

Prototype Pollution leading to Remote Code Execution in superjson

High

Improper Input Validation in vriteio/vrite

Medium

Server-Side Request Forgery (SSRF) in vriteio/vrite

High

webmention.js Cross-site Scripting vulnerability

High

Leaking sensitive user information still possible by filtering on private with prefix fields

High

progressbar.js vulnerable to Prototype Pollution

High

Jodit Editor vulnerable to cross-site scripting

Medium

Path traversal vulnerability in gatsby-plugin-sharp

Medium

Making all attributes on a content-type public without noticing it - @strapi/utils

Medium

Making all attributes on a content-type public without noticing it

Medium

layui vulnerable to cross-site scripting

Medium

Improper Neutralization of Script in Attributes in @dcl/single-sign-on-client

High

@builder.io/qwik-city Cross-Site Request Forgery vulnerability

Medium

Cleartext Signed Message Signature Spoofing in openpgp

Medium

Chaijs/get-func-name vulnerable to ReDoS

High

tarteaucitron.js vulnerable to Cross-site Scripting

Medium

Cross-Site Scripting in serialize-to-js

Low

Unauthorized Access to Private Fields in User Registration API - @strapi/plugin-users-permissions

High

Unauthorized Access to Private Fields in User Registration API

High

TinyMCE XSS vulnerability in notificationManager.open API

Medium

antfu/utils vulnerable to prototype pollution

Medium

Feathers socket handler allows abusing implicit toString - @feathersjs/socketio

High

Feathers socket handler allows abusing implicit toString

High

editor.md vulnerable to Cross-site Scripting

Medium

Strapi leaking sensitive user information by filtering on private fields

High

Strapi plugins vulnerable to Server-Side Template Injection and Remote Code Execution in the Users-Permissions Plugin

High

Cloudera HUE Account Enumeration

Medium

external-svg-loader Cross-site Scripting vulnerability

High

Allocation of Resources Without Limits or Throttling in vriteio/vrite

Medium

html inputs of type password recorded in plaintext when converted to text inputs

Medium

Svelecte item names vulnerable to execution of arbitrary JavaScript

Medium

Strapi does not verify the access or ID tokens issued during the OAuth flow

Medium

ckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of Editor

Medium

When setting EntityOptions.apiPrefilter to a function, the filter is not applied to API requests for a resource by Id

Medium

jquery-ui Tooltip widget vulnerable to XSS

Medium

MrSwitch hello.js vulnerable to prototype pollution

High

Uncaught Exception in yaml

High

Joplin Cross-site Scripting vulnerability - joplin

Medium

Joplin Cross-site Scripting vulnerability

Medium

@udecode/plate-link does not sanitize URLs to prevent use of the `javascript:` scheme

High

Cross-Site Scripting in highcharts

High

A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA

High

Strapi Improper Rate Limiting vulnerability - @strapi/plugin-users-permissions

High

Strapi Improper Rate Limiting vulnerability

High

Strapi may leak sensitive user information, user reset password, tokens via content-manager views - @strapi/utils

Medium

Strapi may leak sensitive user information, user reset password, tokens via content-manager views

Medium

`chainId` may be outdated if user changes chains as part of connection in @web3-react - @web3-react/coinbase-wallet

Medium

`chainId` may be outdated if user changes chains as part of connection in @web3-react - @web3-react/eip1193

Medium

`chainId` may be outdated if user changes chains as part of connection in @web3-react - @web3-react/metamask

Medium

`chainId` may be outdated if user changes chains as part of connection in @web3-react

Medium

angular-ui-notification Cross-site Scripting vulnerability

Medium

Hidden fields can be leaked on readable collections in Payload

High

Use-After-Free in puppeteer

Medium

Prototype Pollution in NASA Open MCT

High

Gatsby develop server has Local File Inclusion vulnerability

Medium

Margox Braft-Editor Cross-site Scripting Vulnerability

Medium

Potential for cross-site scripting in PostHog-js

Medium

matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms

Low

graphql Uncontrolled Resource Consumption vulnerability

Medium

@nuxtlabs/github-module made Use of Hard-coded Credentials

High

Bootbox.js Cross Site Scripting vulnerability

Medium

TinyMCE mXSS vulnerability in undo/redo, getContent API, resetContent API, and Autosave plugin

Medium

TinyMCE vulnerable to mutation Cross-site Scripting via special characters in unescaped text nodes

Medium

Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpoint

Medium

chromedriver Command Injection vulnerability

Medium

NASA Open MCT Cross Site Scripting vulnerability

Medium

NASA Open MCT Cross Site Request Forgery (CSRF) vulnerability

Medium

Uncontrolled Resource Consumption in strapi

Medium

google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability

Low

Exposure of Sensitive Information in eventsource

High

uri-template-lite Regular Expression Denial of Service

Medium

Collection.js vulnerable to Prototype Pollution

High

Regular expression denial of service in devcert

High

dottie vulnerable to Prototype Pollution

High

fast-xml-parser regex vulnerability patch could be improved from a safety perspective

Low

Regular Expression Denial of Service in Handlebars

High

Prototype Pollution in handlebars - handlebars - GHSA-q42p-pg8m-cqh6

High

Arbitrary Code Execution in Handlebars - handlebars

High

Remote code execution in handlebars when compiling templates

High

Uncontrolled Resource Consumption in Hawk

High

Validation Bypass in kind-of

High

Inefficient Regular Expression Complexity in marked - marked

High

Inefficient Regular Expression Complexity in marked

High

ReDoS in normalize-url

High

Inefficient Regular Expression Complexity in nth-check

High

Prototype pollution in Plist before 3.0.5 can cause denial of service

High

Prototype Pollution in protobufjs

High

Prototype Pollution in querystringify

High

Code Execution Through IIFE in serialize-to-js

High

Insecure serialization leading to RCE in serialize-javascript

High

Uncontrolled Resource Consumption in trim-newlines

High

underscore-keypath vulnerable to Prototype Pollution

High

Incorrect protocol extraction via \r, \n and \t characters

High

Authorization Bypass Through User-Controlled Key in url-parse

High

Prototype Pollution in vConsole

High

Inefficient Regular Expression Complexity in validator.js

Medium

Improper Certificate Validation in xmlhttprequest-ssl

High

xmlhttprequest and xmlhttprequest-ssl vulnerable to Arbitrary Code Injection - xmlhttprequest

High

xmlhttprequest and xmlhttprequest-ssl vulnerable to Arbitrary Code Injection

High

Malicious Package in another-date-picker

High

Denial of Service in markdown-it-toc-and-anchor

High

Improper Key Verification in ipns

High

Malicious Package in another-date-range-picker

High

Denial of Service in ipfs-bitswap

Medium

URIjs Hostname spoofing via backslashes in URL

High

SSRF & Credentials Leak

High

Directory Traversal in evershop - @evershop/evershop - GHSA-4wrm-qmq2-5fjx

Medium

Cross-site Scripting in evershop - @evershop/evershop - GHSA-2xcj-557c-hf8r

Medium

Cross Site Scripting in evershop - @evershop/evershop

Medium

Directory Traversal in evershop - @evershop/evershop

High

Directory Traversal in evershop

Medium

Cross-site Scripting in evershop

Medium

Code execution in evershop

High

DOS by abusing `fetchOptions.retry`.

High

Buttercup allows attackers to obtain the hash of the master password

Medium

fast-xml-parser vulnerable to Prototype Pollution through tag or attribute name

Medium

Cross-site Scripting in @spscommerce/ds-react

High

mockjs vulnerable to Prototype Pollution via the Util.extend function

High

Cube API denial of service attack

Medium

Cross-site Scripting in cesium

Medium

HTML comments vulnerability allowing to execute JavaScript code

High

Sentry's Astro SDK vulnerable to ReDoS

High

bsock uses weak hashing algorithms

High

Cross-site scripting vulnerability in TinyMCE - tinymce

Medium

Cross-site scripting vulnerability in TinyMCE plugins

Medium

Cross-site scripting vulnerability in TinyMCE

Medium

Layui cross-site scripting (XSS) vulnerability

Medium

msgpackr's conversion of property names to strings can trigger infinite recursion

High

botframework-connector vulnerable to Improper Authentication

Medium

@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)

High

react-native-mmkv Insertion of Sensitive Information into Log File vulnerability

Medium

QooxDoo XSS in Callback Parameter

Medium

Incorrect Default Permissions in log4js

Medium

Sending a GET or HEAD request with a body crashes SvelteKit

High

npm package rfc6902 vulnerable to Prototype Pollution

High

@urql/next Cross-site Scripting vulnerability

High

@apollo/experimental-nextjs-app-support Cross-site Scripting vulnerability

High

react-query-streamed-hydration Cross-site Scripting vulnerability

High

MathJax Regular expression Denial of Service (ReDoS)

High

@lobehub/chat vulnerable to unauthorized access to plugins

Medium

crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard

High

shvl vulnerable to prototype pollution

High

dset vulnerable to prototype pollution

High

Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS)

Medium

Ckeditor XSS Vulnerability

Medium

Arbitrary Code Execution in handlebars

High

CKEditor cross-site scripting vulnerability in AJAX sample

Medium

ckeditor4 vulnerable to cross-site scripting

Medium

Regular Expression Denial of Service in marked

High

Luxon Inefficient Regular Expression Complexity vulnerability

High

Stimulsoft Dashboard.JS directory traversal vulnerability

High

Stimulsoft Dashboard.JS Cross Site Scripting vulnerability

Medium

Default swagger-ui configuration exposes all files in the module

Medium

GitHub Security Lab (GHSL) Vulnerability Report, scrypted: `GHSL-2023-218`, `GHSL-2023-219`

High

Prototype Pollution in JSON5 via Parse Method

High

Misinterpretation of malicious XML input - xmldom

Medium

Misinterpretation of malicious XML input

Medium

Marvin Attack of RSA and RSAOAEP decryption in jsrsasign

High

Starcounter-Jack JSON-Patch Prototype Pollution vulnerability

High

CKEditor4 Cross-site Scripting vulnerability in samples with enabled the preview feature

Medium

Stimulsoft Dashboard.JS Cross Site Scripting vulnerability - stimulsoft-dashboards-js

Medium

CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection

Medium

JSONata expression can pollute the "Object" prototype

High

TurboBoost Commands vulnerable to arbitrary method invocation

High

Strapi 4.1.12 Cross-site Scripting via crafted file

Medium

RSSHub Cross-site Scripting vulnerability caused by internal media proxy

Medium

RSSHub vulnerable to Server-Side Request Forgery

Medium

SQL injection in typeORM

High

Path traversal in webpack-dev-middleware

High

Cache Poisoning Vulnerability

Medium

Regular Expression Denial of Service in debug

Low

KaTeX's maxExpand bypassed by Unicode sub/superscripts

Medium

KaTeX's `\includegraphics` does not escape filename

Medium

KaTeX missing normalization of the protocol in URLs allows bypassing forbidden protocols

Medium

OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation

High

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements

Medium

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes

Medium

@workos-inc/authkit-nextjs session replay vulnerability

Medium

jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext - jose-node-cjs-runtime

Medium

jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext - jose-node-esm-runtime

Medium

jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext

Medium

Formstone Vulnerable to Reflected XSS

Medium

MooTools Regular Expression Denial of Service

High

jplayer Cross Site Scripting vulnerability

Medium

jQuery-Upload-File XSS in fileNameStr

Medium

json-pointer vulnerable to Prototype Pollution

High

Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code

High

dectalk-tts Uses Unencrypted HTTP Request

High

React Native Sms User Consent Intent Redirection Vulnerability

Medium

Summernote vulnerable to cross-site scripting

Medium

Matrix IRC Bridge truncated content of messages can be leaked

Medium

Handling untrusted input can result in a crash, leading to loss of availability / denial of service

High

Prototype pollution in emit function

Low

Stored Cross-site Scripting (XSS) in excalidraw's web embed component

Medium

zcap has incomplete expiration checks in capability chains.

Medium

Insufficient validation when decoding a Socket.IO packet - socket.io-parser

High

Regular Expression Denial Of Service in uri-js

Medium

Regular Expression Denial of Service in remarkable

High

jqueryFileTree vulnerable to Directory Traversal

High

Prototype pollution vulnerability in 'deep-set

High

CKEditor 4 ReDoS Vulnerability

Medium

mootools-more vulnerable to prototype pollution

High

Sanitize-html Vulnerable To REDoS Attacks

High

deep-defaults vulnerable to prototype pollution

High

Joplin vulnerable to Cross-site Scripting in notes

Medium

Joplin Vulnerable to Code Injection

High

Joplin Vulnerable to Cross-site Scripting in Note Content

Medium

Joplin Cross Site Scripting Vulnerability via NOSCRIPT tags

Medium

Joplin Remote Code Execution

High

MediaElement Vulnerable to Reflected XSS

Medium

Prototype Pollution in immer - immer - GHSA-c36v-fmgq-m8hx

High

Prototype Pollution in immer - immer

High

Prototype Pollution in immer

High

Server-Side Template Injection in formio

High

Apache 2.4.49 Path Traversal and RCE

High

Apache Expect Header Cross Site Scripting

High

Apache mod_jk Access Control Bypass

High

Apache mod_proxy 2.4.48 SSRF

Medium

Apache server-info enabled

Medium

Apache server-status enabled

Medium

Apache Struts 2 Forced double OGNL evaluation S2-059

High

Apache Struts 2 RCE S2-045

High

Apache Struts 2 REST plugin XStream RCE S2-052

High

Apache Struts OGNL expression RCE S2-057

High

Apache Tomcat JSP Upload RCE

High

Apache Tomcat Manager Login Found

Medium

Apache Version Disclosure

Informational

Application and Database Error

Medium

Application Error

Medium

Arbitrary Source Code Disclosure

High

ASP.NET Version Disclosure

Informational

Auto Complete Enabled Password Input

Low

Basic Authentication Over HTTP

Medium

Blind OS Command Execution

High

Blind SQL Injection

High

BREACH attack

Low

Broken Link

Informational

Brute Force Prevention Bypassed

Medium

Buffer Overflow

Medium

Content Character Encoding is not Defined

Informational

Content-Security-Policy Header is Missing

Low

Cookie Accessible for Subdomains

Informational

Cookie without HttpOnly Flag

Low

Cookie without SameSite Flag

Low

Cookie without Secure Flag

Low

CRIME (SPDY) attack

Low

CRIME (SSL/TLS) attack

Low

CRLF Injection in URL

High

Cross-Origin Resource Sharing Allowed

Informational

Cross Site Scripting

High

Database Error

Medium

Detailed Application and Database Error

Medium

Detailed Application Error

Medium

Directory Listing of Sensitive Files

Low

Directory Listing

Low

Drupal 4.1/4.2 XSS

High

Drupal 'Drupalgeddon2' Remote Code Execution

High

Drupal Module Cumulus Cross Site Scripting

High

Drupal7 Pre Auth SQLI

High

Email Address Disclosure

Informational

Expression Language Injection

High

File Upload Functionality

Informational

Hidden Resource in Robots.txt

Medium

Host Header Injection

Medium

HTTP Protocol Stack Remote Code Execution Vulnerability (DOS)

High

HTTP Response Splitting

High

Insecure Deserialization Remote Code Execution

High

Insecure Deserialization

High

Insecure Inline Frame

Medium

Internal Server Error

Medium

Joomla! 1.5 < 3.4.5 RCE

High

Joomla! < 1.7.0 XSS

High

Joomla! 3.2.1 SQLI

High

Joomla! Component Advertisement Board 3.1.0 'catname' SQLI

High

Joomla! Component Aist 2.0 'id' SQLI

High

Joomla! Component AllVideos Reloaded 1.2.x 'divid' SQLI

High

Joomla! Component CcNewsletter 2.x.x 'id' SQLI

High

Joomla! Component Com_cbcontact 'contact_id' SQLI

High

Joomla! Component Com_contenthistory SQLI

High

Joomla! Component Com_fields 3.7 SQLI

High

Joomla! Component com_hdwplayer 4.2 SQLI

High

Joomla! Component Com_newsfeeds 1.0 SQLI

High

Joomla! Component Com_rsgallery2 2.0 'catid' SQLI

High

Joomla! Component Com_shop 'editid' SQLI

High

Joomla! Component Com_shop 'id' SQLI

High

Joomla! Component DT Register 3.2.7 'id' SQLI

High

Joomla! Component Fastball 2.5 'season' SQLI

High

Joomla! Component File Download Tracker 3.0 SQLI

High

Joomla! Component Form Maker 3.6.12 SQLI

High

Joomla! Component Google Map Landkarten 4.2.3 SQLI

High

Joomla! Component InviteX 3.0.5 'invite_type' SQLI

High

Joomla! Component JB Bus 2.3 'order_number' SQLI

High

Joomla! Component JCK Editor 6.4.4 'parent' SQLI

High

Joomla! Component JCK Editor 6.4.4 SQLI

High

Joomla! Component JEXTN Video Gallery 3.0.5 'id' SQLI

High

Joomla! Component JGive 2.0.9 SQLI

High

Joomla! Component Jobs Factory 2.0.4 SQLI

High

Joomla! Component JomEstate PRO 3.7 'id' SQLI

High

Joomla! Component JquickContact 1.3.2.2.1 SQLI

High

Joomla! Component Music Collection 3.0.3 SQLI

High

Joomla! Component NextGen Editor 2.1.0 'plname' SQLI

High

Joomla! Component Odudeprofile 2.8 'profession' SQLI

High

Joomla! Component Reverse Auction Factory 4.3.8 SQLI

High

Joomla! Component Timetable Responsive Schedule For Joomla! 1.5 'alias' SQLI

High

Joomla! 'J2Store < 3.3.7' SQL Injection

High

Joomla! Pinterest Clone Social Pinboard 2.0 SQLI

High

Local File Inclusion

High

Microsoft IIS Tilde Directory Enumeration

Medium

Missing or Insecure Cache-Control Header

Informational

Nginx Code Execution due to Misconfiguration

High

Nginx Integer Overflow

High

Nginx Null Byte Code Execution

High

Nginx Restriction Bypass via Space Character in URI

High

Nginx Version Disclosure

Informational

No HTTPS

Medium

No Redirection from HTTP to HTTPS

Medium

Old/Backup Resource Found

Low

Open Redirection In URL

High

OS Command Execution

High

Passive Mixed Content

Low

Password Input on HTTP

Medium

Password Sent in HTTP Query

Medium

Password Sent in Query

Low

Password Sent Over HTTP

Medium

Path Disclosure in Robots.txt

Informational

PHP Version Disclosure

Informational

phpinfo() Found

Medium

Possible SQL Injection

High

Private IPv4 Address Disclosure

Informational

Private IPv6 Address Disclosure

Informational

Profanity

Informational

Public-Key-Pins Header is Set

Informational

Redirection with Body

Low

Referrer-Policy Header is Missing

Informational

Remote File Disclosure

High

Remote File Inclusion

High

Remote URL Inclusion

High

Robots.txt Found

Informational

Secure Renegotiation is not supported

Low

Sensitive Old/Backup Resource Found

Medium

Sensitive Unreferenced Resource Found

Low

Serialized Object Found

High

Server Version Disclosure

Low

Session Cookie Accessible for Subdomains

Low

Session Cookie without HttpOnly Flag

Medium

Session Cookie without SameSite Flag

Medium

Session Cookie without Secure Flag

Medium

Source Code Disclosure

Medium

SQL Command Disclosure

Informational

SQL Injection

High

SSL 2 enabled

High

SSL 3 enabled

Medium

Strict-Transport-Security Header is Missing

Low

Subresource Integrity is Missing

Low

The Heartbleed Bug

High

The POODLE attack

Medium

The ShellShock Bug

High

Time Based SQL Injection

High

TLS 1.0 enabled

Medium

TLS 1.1 enabled

Low

Tomcat Version Disclosure

Informational

TRACE Method Allowed

Low

TRACK Method Allowed

Low

Unicode Transformation Issue

High

Unix Path Disclosure

Informational

Unreferenced Repository Found

High

Unreferenced Resource Found

Informational

Unreferenced Source Code Disclosure

High

Unvalidated Redirection

High

User Controllable URL

Medium

User Enumeration

Medium

ViewState is not Encrypted

Informational

Weak Password

High

Web Server Path Traversal

High

Werkzeug Interactive Debugging is Active

Medium

Windows Path Disclosure

Informational

WordPress 4.6 Blind OS Command Execution

High

WordPress Plugin AdRotate 3.6.5 SQLI

High

WordPress Plugin AdRotate 3.6.6 SQLI

High

WordPress Plugin AdRotate 3.9.4 SQLI

High

WordPress Plugin All Video Gallery 1.1 SQLI

High

WordPress Plugin Bannerize 2.8.6 SQLI

High

WordPress Plugin Bannerize 2.8.7 SQLI

High

WordPress Plugin Business Intelligence SQLI

High

WordPress Plugin Chained Quiz 1.0.8 SQLI

High

WordPress Plugin Community Events 1.2.1 SQLI

High

WordPress Plugin CP Multi View Event Calendar 1.01 SQLI

High

WordPress Plugin CP Multi View Event Calendar 1.1.4 SQLI

High

WordPress Plugin CP Multi View Event Calendar 1.1.7 SQLI

High

WordPress Plugin DS FAQ 1.3.2 SQLI

High

WordPress Plugin Easy Contact Form Lite 1.0.7 SQLI

High

WordPress Plugin Event Registration 5.4.3 SQLI

High

WordPress Plugin Eventify Simple Events 1.7.f SQLI

High

WordPress Plugin Facebook Promotions 1.3.3 SQLI

High

WordPress Plugin File Groups 1.1.2 SQLI

High

WordPress Plugin FireStorm Professional Real Estate 2.06.01 SQLI

High

WordPress Plugin Forum Server 1.7 SQLI

High

WordPress Plugin Glossary SQLI

High

WordPress Plugin Google Document Embedder 2.5.14 SQLI

High

WordPress Plugin Google Document Embedder 2.5.16 SQLI

High

WordPress Plugin Hitasoft_player Ripe HD FLV Player 1.1 SQLI

High

WordPress Plugin Jetpack SQLI

High

WordPress Plugin JTRT Responsive Tables 4.1 SQLI

High

WordPress Plugin KNR Author List Widget 2.0.0 SQLI

High

WordPress Plugin LeagueManager 3.8 SQLI

High

WordPress Plugin Link Library 5.2.1 SQLI

High

WordPress Plugin NEX Forms 3.0 SQLI

High

WordPress Plugin Olimometer 2.56 SQLI

High

WordPress Plugin OQey Headers 0.3 SQLI

High

WordPress Plugin Paid Downloads 2.01 SQLI

High

WordPress Plugin Post Highlights 2.2 SQLI

High

WordPress Plugin SCORM Cloud 1.0.6.6 SQLI

High

WordPress Plugin SH Slideshow 3.1.4 SQLI

High

WordPress Plugin Smart Google Code Inserter 3.5 SQLI

High

WordPress Plugin Tune Library 2.17 SQLI

High

WordPress Plugin Users Ultra 1.5.50 Blind SQLI

High

WordPress Plugin VideoWhisper Video Presentation 1.1 SQLI

High

WordPress Plugin WP Fastest Cache 0.8.4.8 Blind SQLI

High

WordPress Plugin WP Statistics 13.0.7 Time Based SQLI

High

WordPress Plugin WP Support Plus Responsive Ticket System 7.1.3 SQLI

High

WordPress Plugin Wpfilemanager 6.8 RCE

High

WordPress Plugin Yolink Search 1.1.4 SQLI

High

WordPress Plugin Zotpress 4.4 SQLI

High

WordPress Theme Akal XSS

High

WordPress User Enumeration

Medium

X-Content-Type-Options Header is Missing

Informational

X-Frame-Options Header is Missing

Low

X-Powered-By Header Found

Informational

X-XSS-Protection Header is Set

Informational

@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability

High

lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability

High

json-schema-ref-parser Prototype Pollution issue

High

vxe-table Cross-site Scripting vulnerability

Low

Malicious PDF can inject JavaScript into PDF Viewer

High

Trix Editor Arbitrary Code Execution Vulnerability

Medium

javascript-deobfuscator crafted payload can lead to code execution

High

Conform contains a Prototype Pollution Vulnerability in `parseWith...` function - @conform-to/yup

High

Conform contains a Prototype Pollution Vulnerability in `parseWith...` function - @conform-to/zod

High

Conform contains a Prototype Pollution Vulnerability in `parseWith...` function

High

ghtml Cross-Site Scripting (XSS) vulnerability

High

@strapi/plugin-upload has a Denial-of-Service via Improper Exception Handling

Medium

SummerNote Cross Site Scripting Vulnerability

Medium

Lobe Chat API Key Leak

Medium

matrix-appservice-irc IRC command injection via admin commands containing newlines

Medium

datatables.net vulnerable to Prototype Pollution due to incomplete fix

High

Prototype Pollution in Ajv

Medium

Axios Cross-Site Request Forgery Vulnerability

Medium

Cross site scripting in datatables.net

Medium

Prototype Pollution in async

High

Cross-site Scripting in ZenUML

Medium

@fastly/js-compute has a use-after-free in some host call implementations

Medium

glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex

High

protobufjs Prototype Pollution vulnerability

High

adolph_dudu ratio-swiper was discovered to contain a prototype pollution via the function extendDefaults

Medium

@akbr/update Prototype Pollution

Medium

akbr patch-into was discovered to contain a prototype pollution via the function patchInto

High

s3-url-parser vulnerable to Denial of Service via regexes component

High

Blackprint @blackprint/engine Prototype Pollution issue

High

Uncontrolled resource consumption in braces

High

Malicious Matrix homeserver can leak truncated message content of messages it shouldn't have access to

Medium

jsonic was discovered to contain a prototype pollution via the function empty.

High

Jan path traversal vulnerability - @janhq/core

High

EverShop vulnerable to improper authorization in GraphQL endpoints

High

@cat5th/key-serializer Prototype Pollution vulnerability

Medium

Regular Expression Denial of Service in ms

High

(ReDoS) Regular Expression Denial of Service in tf2-item-format

High

VvvebJs Arbitrary File Upload vulnerability

Medium

ejs lacks certain pollution protection

Medium

Badger Database Prototype Pollution

High

obx Prototype Pollution

High

@thi.ng/paths Prototype Pollution vulnerability

High

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

Medium

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

Medium

Plate media plugins has a XSS in media embed element when using custom URL parsers

High

jrburke requirejs vulnerable to prototype pollution

High

XSS vulnerability that affects bootstrap - bootstrap

Medium

XSS vulnerability that affects bootstrap

Medium

Bootstrap Cross-site Scripting vulnerability - bootstrap - GHSA-4p24-vmcr-4gqj

Medium

Bootstrap Cross-site Scripting vulnerability

Medium

bootstrap Cross-site Scripting vulnerability - bootstrap-sass - GHSA-ph58-4vrj-w6hr

Medium

bootstrap Cross-site Scripting vulnerability - bootstrap

Medium

Bootstrap vulnerable to Cross-Site Scripting (XSS)

Medium

Editor.js vulnerable to Code Injection

Medium

Scrypted Cross-site Scripting vulnerability

Medium

Nuxt Devtools has a Path Traversal: '../filedir

High

Nuxt Icon affected by a Server-Side Request Forgery (SSRF)

High

@75lb/deep-merge Prototype Pollution vulnerability

High

robinweser fast-loops vulnerable to prototype pollution

High

Cross-site Scripting in quill

Medium

Server-Side Request Forgery in axios

High

Jan path traversal vulnerability - @janhq/core - GHSA-5jqc-qj57-4hrc

High

Trix has a cross-site Scripting vulnerability on copy & paste

Medium

Jan path traversal vulnerability

High

gettext.js has a Cross-site Scripting injection

High

Vulnerable IIS Version

Medium

React Native Document Picker Directory Traversal vulnerability

High

MiguelCastillo @bit/loader Prototype Pollution issue

High

matrix-js-sdk will freeze when a user sets a room with itself as a its predecessor

Medium

squirrelly Code Injection vulnerability

High

ag-grid packages vulnerable to Prototype Pollution - @ag-grid-enterprise/charts

Medium

ag-grid packages vulnerable to Prototype Pollution - ag-grid-enterprise

Medium

ag-grid packages vulnerable to Prototype Pollution

Medium

Cross-site scripting in Swagger-UI

High

VvvebJs Reflected Cross-Site Scripting (XSS) vulnerability

Medium

Svelte has a potential mXSS vulnerability due to improper HTML escaping

Medium

Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS

Medium

ReDoS in urlregex

Medium

Prototype pollution in ag-grid-community via the _.mergeDeep function - ag-grid-enterprise

High

Prototype pollution in ag-grid-community via the _.mergeDeep function

High

Zod denial of service vulnerability

Medium

Unreferenced Login Page Found

Medium

WordPress Login Page Found

Medium

dset Prototype Pollution vulnerability

High

DOM clobbering could escalate to Cross-site Scripting (XSS) - @pagefind/default-ui

Medium

DOM clobbering could escalate to Cross-site Scripting (XSS) - pagefind

Medium

DOM clobbering could escalate to Cross-site Scripting (XSS)

Medium

DOM Clobbering Gadget found in Rspack's AutoPublicPathRuntimeModule that leads to XSS

Medium

Plate allows arbitrary DOM attributes in element.attributes and leaf.attributes

High

json-logic-js Command Injection vulnerability

High

PHP CGI Argument Injection RCE

High

FUXA vulnerable to Local File Inclusion

High

StimulusReflex arbitrary method call

High

Denial of service in rocket chat message parser

Medium

Layui has DOM Clobbering gadgets that leads to Cross-site Scripting

Medium

DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS

High

lobe-chat implemented an insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)

Medium

Flowise and Flowise Chat Embed vulnerable to Stored Cross-site Scripting

Medium

uPlot Prototype Pollution vulnerability

High

Stored XSS in Jupyter nbdime - nbdime

Medium

Stored XSS in Jupyter nbdime

Medium

Heap-based Buffer Overflow in sqlite-vec

High

Sentry SDK Prototype Pollution gadget in JavaScript SDKs

Medium

@saltcorn/plugins-loader unsanitized plugin name leads to a remote code execution (RCE) vulnerability when creating plug

High

@saltcorn/server Remote Code Execution (RCE) / SQL injection via prototype pollution by manipulating `lang` and `defst

High

@saltcorn/server arbitrary file and directory listing when accessing build mobile app results

Medium

@saltcorn/server arbitrary file zip read and download when downloading auto backups

Medium

Strapi Server-Side Request Forgery (SSRF)

High

Saltcorn Server Stored Cross-Site Scripting (XSS) in event logs page

Medium

Saltcorn Server allows logged-in users to delete arbitrary files because of a path traversal vulnerability

High

ReLaXed Cross-site Scripting vulnerability

Low

Cross-Site Scripting in jquery

Medium

fast-xml-parser vulnerable to ReDOS at currency parsing

High

angular-base64-upload vulnerable to unauthenticated remote code execution

High

Cross-site scripting (XSS) in the clipboard package - ckeditor5

Medium

Cross-site scripting (XSS) in the clipboard package

Medium

Cross site scripting in markdown-to-jsx

Medium

Matrix JavaScript SDK's key history sharing could share keys to malicious devices

High

Signature Malleabillity in elliptic

High

Slim Select has potential Cross-site Scripting issue

Medium

secp256k1-node allows private key extraction over ECDH

High

Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section

Medium

Prototype pollution vulnerability found in Mermaid's bundled version of DOMPurify

High

ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function

Low

Knwl.js Regular Expression Denial of Service vulnerability

Medium

Generation of Error Message Containing Sensitive Information in zsa

Medium

@langchain/community SQL Injection vulnerability

Low

Langchain Path Traversal vulnerability

Medium

Glossarizer Cross-site Scripting vulnerability

Medium

lilconfig Code Injection vulnerability

High

XSS in jQuery as used in Drupal, Backdrop CMS, and other products

Medium

@workos-inc/authkit-nextjs refresh tokens are logged when the debug flag is enabled

Low

happy-dom allows for server side code to be executed by a <script> tag

High

Regular expression denial of service in jquery-validation - jquery-validation

Low

CommonRegexJS Regular Expression Denial of Service vulnerability

Medium

Foundation Regular Expression Denial of Service vulnerability

Medium

insane vulnerable to Regular Expression Denial of Service

Medium

JSZip contains Path Traversal via loadAsync

Medium

Insufficient validation when decoding a Socket.IO packet

Medium

EverShop at risk to unauthorized access via weak HMAC secret

High

socket.io has an unhandled 'error' event

Medium

rejetto HFS vulnerable to OS Command Execution by remote authenticated users

High

webcrack has an Arbitrary File Write Vulnerability on Windows when Parsing and Saving a Malicious Bundle

Medium

CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover

Medium

@blakeembrey/template vulnerable to code injection when attacker controls template input

Medium

node-gettext vulnerable to Prototype Pollution

High

Firebase JavaScript SDK allows attackers to manipulate the "_authTokenSyncURL" to point to their own server

Medium

@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass

High

Open Chinese Convert subject to Denial of Service via Out-of-bounds Read

Medium

Cross-site scripting in bootstrap-select

Medium

@sveltejs/kit has unescaped error message included on error page

Low

Agnai vulnerable to Remote Code Execution via JS Upload using Directory Traversal

High

Agnai File Disclosure Vulnerability: JSON via Path Traversal

Low

Agnai vulnerable to Relative Path Traversal in Image Upload

Low

Nunjucks autoescape bypass leads to cross site scripting

Medium

@lobehub/chat Server Side Request Forgery vulnerability

High

vue-i18n has cross-site scripting vulnerability with prototype pollution - @intlify/core-base

Medium

vue-i18n has cross-site scripting vulnerability with prototype pollution - @intlify/core

Medium

vue-i18n has cross-site scripting vulnerability with prototype pollution - @intlify/vue-i18n-core

Medium

vue-i18n has cross-site scripting vulnerability with prototype pollution - vue-i18n

Medium

vue-i18n has cross-site scripting vulnerability with prototype pollution

Medium

@intlify/shared Prototype Pollution vulnerability - @intlify/shared

Medium

@intlify/shared Prototype Pollution vulnerability - @intlify/vue-i18n-core

Medium

@intlify/shared Prototype Pollution vulnerability - vue-i18n

Medium

@intlify/shared Prototype Pollution vulnerability

Medium

hull.js Code Injection Vulnerability

High

Firepad allows insecure document access

Low

Prototype Pollution in the merge and clone helper methods

Medium

Trix editor subject to XSS vulnerabilities on copy & paste

Medium

Angular Expressions - Remote Code Execution when using locals

High

Marp Core allows XSS by improper neutralization of HTML sanitization

Medium

Trix allows Cross-site Scripting via `javascript:` url in a link

Medium

dom-iterator code execution vulnerability

Medium

json-schema is vulnerable to Prototype Pollution

High

XSS/HTML Injection Vulnerability in Umbraco Backoffice Components

Medium

@sveltejs/kit vulnerable to XSS on dev mode 404 page

Low

path-to-regexp outputs backtracking regular expressions

High

Cross Site Scripting vulnerability in store2

Medium

Opening a malicious website while running a Nuxt dev server could allow read-only access to code - @nuxt/vite-builder

Medium

Opening a malicious website while running a Nuxt dev server could allow read-only access to code - @nuxt/webpack-builder

Medium

Opening a malicious website while running a Nuxt dev server could allow read-only access to code

Medium

Potential DoS when using ContextLines integration - @sentry/astro

Low

Potential DoS when using ContextLines integration - @sentry/bun

Low

Potential DoS when using ContextLines integration - @sentry/nextjs

Low

Potential DoS when using ContextLines integration - @sentry/nuxt

Low

Potential DoS when using ContextLines integration - @sentry/remix

Low

Potential DoS when using ContextLines integration - @sentry/solidstart

Low

Potential DoS when using ContextLines integration

Low

Remote Code Execution on click of <a> Link in markdown preview

High

files.photo.gallery command injection

Medium

JSONPath Plus Remote Code Execution (RCE) Vulnerability

High

Parsed HTML anchor links in Markdown provided to parseMarkdown can result in XSS in @nuxtjs/mdc

High

@ndhoule/defaults prototype pollution

High

vxe-table prototype pollution

High

esbuild enables any website to send any requests to the development server and read the response

Medium

Authentication bypass in @sap/approuter

High

Prototype Pollution in handlebars - handlebars

High

Prototype Pollution in handlebars

High

dot-prop Prototype Pollution vulnerability

High

axios Inefficient Regular Expression Complexity vulnerability

High

Regular Expression Denial of Service in jsoneditor

Medium

Potential memory exposure in dns-packet

High

Uncontrolled Resource Consumption in ansi-html

High

Denial of service in css-what

High

Deserialization of Untrusted Data in bson

High

parse-duration has a Regex Denial of Service that results in event loop delay and out of memory

High

cookiejar Regular Expression Denial of Service via Cookie.parse function

Medium

http-cache-semantics vulnerable to Regular Expression Denial of Service

High

engine.io Uncaught Exception vulnerability

Medium

word-wrap vulnerable to Regular Expression Denial of Service

Medium

browserify-sign upper bound check issue in `dsaVerify` leads to a signature forgery attack

High

Vega allows Cross-site Scripting via the vlSelectionTuples function - vega-selections

Medium

Vega allows Cross-site Scripting via the vlSelectionTuples function

Medium

@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtrack

Medium

Insecure Direct Object Reference (IDOR)

High

smartbanner.js rel noopener vulnerability

Low

Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerability

Medium

@octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Back

Medium

JSONPath Plus allows Remote Code Execution

High

Unwanted access to the entire file system vulnerability due to a missing check in `staticFiles` HTTP handler

Medium

Cross-site scripting (XSS) in the CKEditor 5 real-time collaboration package

Medium

@tanstack/form-core prototype pollution

High

@rpldy/uploader prototype pollution

High

Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)

High

tarteaucitron Cross-site Scripting (XSS)

Low

Solid Lacks Escaping of HTML in JSX Fragments allows for Cross-Site Scripting (XSS)

High

Matrix IRC Bridge allows IRC command injection to own puppeted user

Low

ejson shell parser in MongoDB Compass maybe bypassed

High

Cache variables with the operations when transforms exist on the root level even if variables change in the further requ

Medium

mavo DOM Clobbering vulnerability

Medium

seajs Cross-site Scripting vulnerability

Low

Manifest Uses a One-Way Hash without a Salt

Medium

Prototype pollution in json-pointer - json-pointer

Medium

Vue I18n Allows Prototype Pollution in `handleFlatJson` - @intlify/core-base

High

Vue I18n Allows Prototype Pollution in `handleFlatJson` - @intlify/core

High

Vue I18n Allows Prototype Pollution in `handleFlatJson` - @intlify/message-resolver

High

Vue I18n Allows Prototype Pollution in `handleFlatJson` - @intlify/vue-i18n-core

High

Vue I18n Allows Prototype Pollution in `handleFlatJson` - vue-i18n

High

Vue I18n Allows Prototype Pollution in `handleFlatJson`

High

Froala Editor Cross-site Scripting vulnerability

Medium

Froala WYSIWYG editor allows cross-site scripting (XSS)

Medium

JS Html Sanitizer allows XSS when used with contentEditable

Medium

canvg Prototype Pollution vulnerability

High

jsPDF Bypass Regular Expression Denial of Service (ReDoS)

High

@zag-js/core prototype pollution

High

Open WebUI Uncontrolled Resource Consumption vulnerability

High

GetmeUK ContentTools Cross-Site Scripting (XSS)

Medium

@mozilla/readability Denial of Service through Regex

Low

Directus's S3 assets become unavailable after a burst of HEAD requests

Medium

Directus's S3 assets become unavailable after a burst of malformed transformations

Medium

Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace] - vega

Medium

Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace]

Medium

Jellyfin Web Cross-Site Scripting (XSS) via Collection Name

Medium

Jellyfin Web Cross-Site Scripting (XSS) via Playlist Name

Medium

depath and cool-path vulnerable to Prototype Pollution via `set()` Method - depath

High

depath and cool-path vulnerable to Prototype Pollution via `set()` Method

High

Redoc Prototype Pollution via `Module.mergeObjects` Component

High

gifplayer XSS vulnerability

Medium

Remix and React Router allow URL manipulation via Host / X-Forwarded-Host headers

High

Open WebUI Uncontrolled Resource Consumption vulnerability - open-webui

High

MathLive's Lack of Escaping of HTML allows for XSS

Medium

Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`

High

React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded Button

Low

bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() Function

High

tarteaucitron.js allows UI manipulation via unrestricted CSS injection

Medium

tarteaucitron.js allows prototype pollution via custom text injection

Medium

tarteaucitron.js allows url scheme injection via unfiltered inputs

Medium

ts-asn1-der has Incorrect DER Encoding of Numbers Leading to Denial of Service and Incorrect Value Representation

Medium

node-opcua-alarm-condition prototype pollution vulnerability

High

Flowise Vulnerable to SQL Injection via `tableName` Parameter

High

Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter - vega

Medium

Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter

Medium

YUI Cross-site Scripting (XSS) vulnerability - yui - GHSA-x5hj-47vv-53p8

Medium

YUI Cross-site Scripting (XSS) vulnerability - yui

Medium

YUI Cross-site Scripting (XSS) vulnerability

Medium

Server-Side Request Forgery

High

Cross-site Scripting in jquery-ui

Medium

glob-parent 6.0.0 vulnerable to Regular Expression Denial of Service

High

cookie accepts cookie name, path, and domain with out of bounds characters

Low

jquery-validation vulnerable to Cross-site Scripting

Medium

Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability

High

@sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params

Medium

Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups - @babel/helpers

Medium

Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups - @babel/runtime

Medium

Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups

Medium

QMarkdown Cross-Site Scripting (XSS) vulnerability

Medium

Compromised xrpl.js versions 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2

High

tRPC 11 WebSocket DoS Vulnerability

High

Pug allows JavaScript code execution if an application accepts untrusted input

Medium

Prototype pollution in 101

High

Homograph attack allows Unicode lookalike characters to bypass validation.

High

Information Disclosure via Flags override link - flags

Medium

Information Disclosure via Flags override link

Medium

Trix vulnerable to Cross-site Scripting on copy & paste

Low

OpenPGP.js's message signature verification can be spoofed

High

css-what vulnerable to ReDoS due to use of insecure regular expression

High

radashi Allows Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Medium

Marked allows Regular Expression Denial of Service (ReDoS) attacks

Medium

Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content

Low

Remote code execution via the `pretty` option.

Medium

Strapi allows Server-Side Request Forgery in Webhook function

Medium

Resource exhaustion in engine.io

High

path-to-regexp contains a ReDoS

High

Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpoint

Medium

Suspended Directus user can continue to use session token to access API

Low

Regular Expression Denial of Service in papaparse

High

Passbolt Browser Extension leaks password information

Medium

OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer

Medium

pbkdf2 returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algos

High

PrismJS DOM Clobbering vulnerability

Medium

Stage.js DOM Clobbering vulnerabilty

Medium

string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS)

Low

tiny-secp256k1 vulnerable to private key extraction when signing a malicious JSON-stringifyable message in bundled envir

High

tiny-secp256k1 allows for verify() bypass when running in bundled environment

High

react-native-keys insecurely stores encryption cipher and Base64 chunks

High

tarteaucitron.js vulnerable to DOM Clobbering via document.currentScript

Medium

@clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/astro

High

@clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/backend

High

@clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/nextjs

High

@clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/nuxt

High

@clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/react-router

High

@clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/remix

High

@clerk/backend Performs Insufficient Verification of Data Authenticity

High

MCP Inspector proxy server lacks authentication between the Inspector client and proxy

High

Qwik's unhandled exception vulnerabilty can cause server crashes from malicious requests

High

docusaurus-plugin-content-gists vulnerability exposes GitHub Personal Access Token

High

@pdfme/common vulnerable to to XSS and Prototype Pollution through its expression evaluation

Medium

chromedriver Downloads Resources over HTTP

High

Better Call routing bug can lead to Cache Deception

Medium

DiracX-Web is vulnerable to attack through an Open Redirect on its login page

Medium

vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - @intlify/core-base

Medium

vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - @intlify/core

Medium

vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - @intlify/vue-i18n-core

Medium

vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - vue-i18n

Medium

vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes

Medium

Prototype pollution in min-dash

High

Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering

High

jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label

Medium

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

Medium

pubnub Insufficient Entropy vulnerability

Medium

Bun has an Application-level Prototype Pollution vulnerability in the runtime native API for Glo

Medium

Angular (deprecated package) Cross-site Scripting

Medium

billboard.js allows prototype pollution via the function generate

High

Sensitive Data Disclosure

Medium

webfinger.js Blind SSRF Vulnerability

Medium

mcp-package-docs vulnerable to command injection in several tools

High

IPX Allows Path Traversal via Prefix Matching Bypass

Medium

js-toml Prototype Pollution Vulnerability

High

The Thinbus Javascript Secure Remote Password (SRP) Client Generates Fewer Bits of Entropy Than Intended

Medium

The AuthKit React Router Library rendered sensitive auth data in HTML

High

content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCE

High

HFS user adding a "web link" in HFS is vulnerable to "target=_blank" exploit

Low

Prototype Pollution in lodash - lodash

High

Prototype Pollution in lodash

Medium

Prototype Pollution in lodash - lodash - GHSA-jf85-cpcp-j695

High

Prototype Pollution in lodash - lodash-amd

High

Prototype Pollution in lodash - lodash.defaultsdeep

High

Prototype Pollution in lodash - lodash-es - GHSA-jf85-cpcp-j695

High

Prototype Pollution in lodash - lodash - GHSA-p6mc-m468-83gw

High

Prototype Pollution in lodash - lodash-es

High

Prototype Pollution in lodash - lodash.set

High

Prototype Pollution in lodash - lodash.update

High

Prototype Pollution in lodash - lodash.updatewith

High

Command Injection in lodash - lodash-es

High

Command Injection in lodash - lodash-template

High

Command Injection in lodash

High

sweetalert2 contains potentially undesirable behavior

Low

Prototype Pollution in jquery-deparam

High

Mermaid does not properly sanitize architecture diagram iconText leading to XSS

Medium

x402 SDK vulnerable in outdated versions in resource servers for builders - x402

High

x402 SDK vulnerable in outdated versions in resource servers for builders

High

sweetalert2 v10.16.10 and above contains hidden functionality

Low

sweetalert2 v11.4.9 and above contains hidden functionality

Low

Liferay Portal Reflected XSS in CKeditor 4.21.0 endpoint

Medium

devalue prototype pollution vulnerability

High

Payload does not invalidate JWTs after log out - payload

Medium

Payload does not invalidate JWTs after log out - @payloadcms/next

Medium

Payload does not invalidate JWTs after log out

Medium

Payload's SQLite adapter Session Fixation vulnerability - payload

Medium

Payload's SQLite adapter Session Fixation vulnerability - @payloadcms/next

Medium

Payload's SQLite adapter Session Fixation vulnerability

Medium

Spoofing attack in swagger-ui

Medium

Denial of Service in jquery

High

parse-uri Regular expression Denial of Service (ReDoS) - parse-uri

Medium

parse-uri Regular expression Denial of Service (ReDoS)

Medium

domain-suffix RegEx Denial of Service

High

useragent Regular Expression Denial of Service vulnerability

Medium

Mermaid improperly sanitizes sequence diagram labels leading to XSS

Medium

CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package - ckeditor5

Low

CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package

Low

Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapter

High

Webrecorder packages are vulnerable to XSS through 404 error handling logic - replaywebpage

High

Webrecorder packages are vulnerable to XSS through 404 error handling logic - @webrecorder/wabac

High

Webrecorder packages are vulnerable to XSS through 404 error handling logic

High

KaTeX \htmlData does not validate attribute names

Medium

jsPDF Denial of Service (DoS)

High

DuckDB NPM packages 1.3.3 and 1.29.2 briefly compromised with malware

High

Angular SSR: Global Platform Injector Race Condition Leads to Cross-Request Data Leakage

High

Prebid.js NPM package briefly compromised

High

Prebid-universal-creative latest on npm briefly compromised

High

sanitize-html is vulnerable to XSS through incomprehensive sanitization

Medium

MetaMask SDK indirectly exposed via malicious [email protected] dependency - @metamask/sdk-react

Medium

MetaMask SDK indirectly exposed via malicious [email protected] dependency - @metamask/sdk

Medium

MetaMask SDK indirectly exposed via malicious [email protected] dependency

Medium

[email protected] contains malware after npm account takeover

High

[email protected] contains malware after npm account takeover

High

[email protected] contains malware after npm account takeover

High

Bootstrap Vulnerable to Cross-Site Scripting in its Popover and Tooltip Components

Medium

jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin

Medium

matrix-js-sdk has insufficient validation when considering a room to be upgraded by another

Medium

CodeceptJS's incomprehensive sanitation can lead to Command Injection

High

Decap CMS Cross Site Scripting (XSS) vulnerability

Medium

sweetalert2 v9.17.4 and above contains hidden functionality

Low

sweetalert2 v8.19.1 and above contains hidden functionality

Low

Malicious versions of Nx were published

High

messageformat has a prototype pollution vulnerability

Low

ts-fns has prototype pollution vulnerability

Medium

node-cube vulnerable to prototype pollution

Low

mpregular vulnerable to prototype pollution

High

Cattown is Vulnerable to Uncontrolled Resource Consumption through Inefficient Regular Expression Complexity

High

private-ip vulnerable to Server-Side Request Forgery

High

csvjson vulnerable to prototype injection

High

json-schema-editor-visual vulnerable to prototype pollution

Medium

dref is vulnerable to prototype pollution

High

lobe-chat has an Open Redirect

Medium

Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages

Medium

counterpart vulnerable to prototype pollution

Medium

MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server

High

Regular Expression Denial of Service (ReDoS) in lodash - lodash-amd

Medium

Regular Expression Denial of Service (ReDoS) in lodash - lodash-es - GHSA-x5rq-j2xg-h7qm

Medium

Regular Expression Denial of Service (ReDoS) in lodash - lodash

Medium

Regular Expression Denial of Service (ReDoS) in lodash - lodash-es

Medium

Regular Expression Denial of Service (ReDoS) in lodash - lodash.trim

Medium

Regular Expression Denial of Service (ReDoS) in lodash - lodash.trimend

Medium

Regular Expression Denial of Service (ReDoS) in lodash

Medium

Denial of Service in content

High

algoliasearch-helper is vulnerable to Prototype Pollution in _merge()

Medium

Finance.js vulnerable to DoS via the seekZero() parameter

High

Fiora chat group avatar is vulnerable to XSS via SVG files

Low

@plone/volto vulnerable to potential DoS by invoking specific URL by anonymous user

High

DocsGPT Allows Remote Code Execution

High

SillyTavern Web Interface Vulnerable DNS Rebinding

High

Finance.js vulnerable to DoS via the IRR function’s depth parameter

High

pdfmake is vulnerable to Throttling via repeatedly redirecting URL in file embedding

High

MCPHub has an Improper Authorization vulnerability via its handleSseConnection function

Medium

MCPHub's ServerController is vulnerable to Command Injection

Low

Fiora chat user avatar is vulnerable to XSS via SVG files

Low

Happy DOM: VM Context Escape can lead to Remote Code Execution

High

QGIS QWC2 Cross-Site Scripting vulnerability

Medium

Parse Javascript SDK vulnerable to prototype pollution in `Parse.Object` and internal APIs

Medium

Expo SDK has an OAuth vulnerability

High

`sveltekit-superforms` has Prototype Pollution in `parseFormData` function of `formData.js`

High

ReDoS Vulnerability in ua-parser-js version

High

Mammoth is vulnerable to Directory Traversal

Medium

Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch module

Low

rollbar vulnerable to prototype pollution

Low

Potential XSS vulnerability in jQuery

Medium

Strapi is vulnerable to Insufficient Session Expiration

Medium

rollbar vulnerable to Prototype Pollution in merge()

Medium

Playwright downloads and installs browsers without verifying the authenticity of the SSL certificate

High

validator.js has a URL validation bypass vulnerability in its isURL function

Medium

messageformat prototype pollution vulnerability

Medium

TypeORM vulnerable to SQL injection via crafted request to repository.save or repository.update

High

Bootstrap Cross-Site Scripting (XSS) vulnerability for data-* attributes

Medium

cipher-base is missing type checks, leading to hash rewind and passing on crafted data

High

AngularJS improperly sanitizes SVG elements

Low

AngularJS Incomplete Filtering of Special Elements vulnerability

Medium

sha.js is missing type checks leading to hash rewind and passing on crafted data

High

angular vulnerable to regular expression denial of service (ReDoS)

Medium

angular vulnerable to regular expression denial of service via the <input type="url"> element

Medium

angular vulnerable to regular expression denial of service via the $resource service

Medium

angular vulnerable to regular expression denial of service via the angular.copy() utility

Medium

angular vulnerable to super-linear runtime due to backtracking

High

AngularJS allows attackers to bypass common image source restrictions

Low

AngularJS allows attackers to bypass common image source restrictions - angular

Low

ansi_up cross-site scripting vulnerability

Medium

Arbitrary Code Execution in underscore

High

Prototype Pollution in jquery-bbq

High

Exposure of Sensitive Information to an Unauthorized Actor in nanoid

Medium

Path Traversal: 'dir/../../filename' in moment.locale

High

Moment.js vulnerable to Inefficient Regular Expression Complexity

High

Vercel ms Inefficient Regular Expression Complexity vulnerability

Medium

PostCSS line return parsing error

Medium

Elliptic's EDDSA missing signature length check

Low

Elliptic's ECDSA missing check for whether leading bit of r and s is zero

Low

Elliptic allows BER-encoded signatures

Low

matrix-js-sdk has insufficient MXC URI validation which allows client-side path traversal

Medium

Predictable results in nanoid generation when given non-integer values

Medium

XSS in the `of` option of the `.position()` util in jquery-ui

Medium

Volto affected by possible DoS by invoking specific URL by anonymous user

High

min-document vulnerable to prototype pollution

Low

Nuxt DevTools vulnerable to cross-site scripting (XSS)

Medium

Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia - vega-expression

High

Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia - vega-interpreter

High

Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia

High

Flowise doesn't Prevent Bypass of Password Confirmation through Unverified Email Change (credentials)

High

Flowise does not Prevent Bypass of Password Confirmation - Unverified Password Change

High

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

High

Flowise is vulnerable to arbitrary file write through its WriteFileTool

High

expr-eval vulnerable to Prototype Pollution - expr-eval

High

expr-eval vulnerable to Prototype Pollution

High

@dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via welcome message

Medium

Bootstrap Cross-site Scripting vulnerability - bootstrap - GHSA-pj7m-g53m-7638

Medium

angular Prototype Pollution vulnerability

High

Angular vulnerable to Cross-site Scripting

Medium

Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage

Medium

authkit-nextjs may let session cookies be cached in CDNs

High

@hpke/core reuses AEAD nonces

High

Regular Expression Denial of Service (ReDoS) in braces

Low

Valibot has a ReDoS vulnerability in `EMOJI_REGEX`

High

Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` - @sentry/astro

Medium

Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` - @sentry/bun

Medium

Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` - @sentry/nextjs

Medium

Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` - @sentry/node-core

Medium

Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` - @sentry/nuxt

Medium

Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` - @sentry/remix

Medium

Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` - @sentry/solidstart

Medium

Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true`

Medium

Elliptic's verify function omits uniqueness validation

Low

Valid ECDSA signatures erroneously rejected in Elliptic

Low

axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL

High

happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript

High

parse is vulnerable to prototype pollution

Medium

OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation

Medium

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

High

OneUptime Unauthorized User Creation via API

High

Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files

Low

Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF

High

expr-eval does not restrict functions passed to the evaluate function - expr-eval

High

expr-eval does not restrict functions passed to the evaluate function

High

Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments

Medium

Elysia vulnerable to prototype pollution with multiple standalone schema validation

High

Elysia affected by arbitrary code injection through cookie config

High

@tiptap/extension-link vulnerable to Cross-site Scripting (XSS)

Low

Formio improperly authorized permission elevation through specially crafted request path

High

EverShop is vulnerable to Unauthorized Order Information Access (IDOR)

Low

Altcha Proof-of-Work obfuscation mode cryptanalytic break

Medium

Vuetify has a Cross-site Scripting (XSS) vulnerability in the VDatePicker component

Medium

Vuetify has a Prototype Pollution vulnerability

High

tRPC has possible prototype pollution in `experimental_nextAppDirCaller`

High

tinacms is vulnerable to arbitrary code execution - tinacms

High

tinacms is vulnerable to arbitrary code execution

High

uppy's companion module is vulnerable to Server-Side Request Forgery (SSRF)

High

plotly.js prototype pollution vulnerability

High

Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass - @apollo/sandbox

High

Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass

High

hemmelig allows SSRF Filter bypass via Secret Request functionality

Medium

vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)

Medium

axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header

Medium

evershop allows unauthenticated attackers to exhaust application server's resources via "GET /images" API

High

evershop allows unauthenticated attackers to force server to initiate HTTP request via "GET /images" API

Medium

Vega XSS via expression abusing vlSelectionTuples function array map calls in environments with satisfactory function ga

High

`vega-functions` vulnerable to Cross-site Scripting via `setdata` function

High

misskey.js's export data contains private post data

High

Misskey has a login rate limit bypass via spoofed X-Forwarded-For header

Medium

Storybook manager bundle may expose environment variables during build

High

Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server Tools

High

Preact has JSON VNode Injection issue

High

Trix has a stored XSS vulnerability through its attachment attribute

Medium

Elliptic Uses a Cryptographic Primitive with a Risky Implementation

Low

React Router has XSS Vulnerability

High

React Router has Path Traversal in File Session Storage

High

React Router SSR XSS in ScrollRestoration

High

Orejime has executable code in HTML attributes

Low

QuestDB UI's Web Console is Vulnerable to Cross-Site Scripting

Low

orval MCP client is vulnerable to a code injection attack.

High

tarteaucitron.js has Regular Expression Denial of Service (ReDoS) vulnerability

Medium

jQuery vulnerable to Cross-Site Scripting (XSS)

Medium

enclave-vm Vulnerable to Sandbox Escape via Host Error Prototype Chain

High

devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse

High

SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering

High

Devalue is vulnerable to denial of service due to memory exhaustion in devalue.parse

High

@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sve

High

Sandbox Breakout / Arbitrary Code Execution in localeval

High

Axios is vulnerable to DoS attack through lack of data size check

High

@octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtrac

Medium

Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability

Medium

svelte is vulnerable to XSS with textarea bind:value

High

Veramo is Vulnerable to SQL Injection in Veramo Data Store ORM

Medium

jsPDF has Local File Inclusion/Path Traversal vulnerability

High

Unknown vulnerability in Coinbase Wallet SDK

High

Cross-Site Scripting in backbone

Medium

svelte vulnerable to Cross-site Scripting

Medium

Lobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File Deletion

Low

flat vulnerable to Prototype Pollution

High

@envelop/graphql-modules has a Race Condition vulnerability

High

html2pdf.js contains a cross-site scripting vulnerability

High

Turbo Frame responses can restore stale session cookies

Low

seroval Affected by Prototype Pollution via JSON Deserialization

High

seroval Affected by Remote Code Execution via JSON Deserialization

High

Seroval affected by Denial of Service via Array serialization

High

Seroval affected by Denial of Service via Deeply Nested Objects

High

Modified package published to npm, containing malware that exfiltrates private key material

High

Prototype Pollution in extend

Medium

eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall have embedded malicious code

High

File restriction bypass in socket.io-file

High

Open Redirect in url-parse

High

Code Injection in node-rules

High

Saltcorn's Reflected XSS and Command Injection vulnerabilities can be chained for 1-click-RCE

High

CSVTOJSON has a prototype pollution vulnerability

Medium

billboard.js is vulnerable to XSS during chart option binding

High

elysia-cors Origin Validation Error

Medium

dcap-qvl has Missing Verification for QE Identity

High

StudioCMS has Authorization Bypass Through User-Controlled Key

Medium

Maker.js has Unsafe Property Copying in makerjs.extendObject

Medium

Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements

High

Orval has Code Injection via unsanitized x-enum-descriptions using JS comments

High

LobeHub Vulnerable to Improper Authorization in Presigned Upload

Medium

React2Shell (CVE-2025-66478)

High

XML External Entity Injection (XXE)

High

Flowise is vulnerable to arbitrary file exposure through its ReadFileTool

High

jsPDF has Shared State Race Condition in addJS Plugin

Medium

jsPDF Vulnerable to Stored XMP Metadata Injection (Spoofing & Integrity Violation)

Medium

jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder

High

jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript Execution

High

Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email Routing

Medium

url-parse incorrectly parses hostname / protocol due to unstripped leading control characters.

Medium

Path traversal in url-parse

Medium

Open redirect in url-parse - url-parse

Medium

Improper Validation and Sanitization in url-parse

Medium

Qwik SSR XSS via Unsafe Virtual Node Serialization

Medium

Prototype Pollution via FormData Processing in Qwik City

High

Qwik City has a CSRF Protection Bypass via Content-Type Header Validation

Medium

Qwik City Open Redirect via fixTrailingSlash

Low

@isaacs/brace-expansion has Uncontrolled Resource Consumption

High

Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE)

High

KaTeX's maxExpand bypassed by `\edef`

Medium

survey-pdf Upgraded jsPDF Version Due to Security Vulnerability

High

webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence

Low

webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior

Low

SCEditor has DOM XSS via emoticon URL/HTML injection

Medium

Open Chinese Convert has Out-of-bounds Write

Low

Sandbox escape via infinite recursion and error objects - @enclave-vm/core

Medium

Sandbox escape via infinite recursion and error objects

Medium

@payloadcms/drizzle has SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters

High

payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments)

Medium

LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection

Medium

Cube Core is vulnerable to privilege escalation via a specially crafted request

High

Cube Core is vulnerable to Denial of Service (DoS) via crafted request

Medium

Lightning Flow Scanner Vulnerable to Code Injection via Unsafe Use of `new Function()` in APIVersion Rule

High

Qwik City CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-

Medium

nanotar is vulnerable to path traversal in parseTar() and parseTarGzip()

Medium

CASL Ability is Vulnerable to Prototype Pollution

High

SQL Injection in typeorm - typeorm

High

fast-xml-parser has RangeError DoS Numeric Entities Bug

High

@langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validation

Medium

set-in Affected by Prototype Pollution

High

cap-go/capacitor-native-biometric Authentication Bypass

Medium

@farmfe/core is Missing Origin Validation in WebSocket

Medium

markdown-it is has a Regular Expression Denial of Service (ReDoS)

Medium

Cloudflare Agents is Vulnerable to Reflected Cross-Site Scripting in the AI Playground's OAuth callback handler

Medium

Cloudflare Agents has a Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground site

Medium

beautiful-mermaid contains an SVG attribute injection issue that can lead to cross-site scripting (XSS)

Medium

@octokit/endpoint has a Regular Expression in parse that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Medium

pbkdf2 silently disregards Uint8Array input, returning static keys

High

BSV Blockchain SDK has an Authentication Signature Data Preparation Vulnerability

Medium

Unauthorized npm publish of [email protected] with modified postinstall script

Low

jsPDF has a PDF Object Injection via Unsanitized Input in addJS Method

High

devalue `uneval`ed code can create objects with polluted prototypes when `eval`ed

Low

devalue affected by CPU and memory amplification from sparse arrays

Low

Memory exhaustion in SvelteKit remote form deserialization (experimental only)

Medium

CPU exhaustion in SvelteKit remote form deserialization (experimental only)

Medium

jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions

High

Fabric.js Affected by Stored XSS via SVG Export

High

LangChain serialization injection vulnerability enables secret extraction - @langchain/core

High

LangChain serialization injection vulnerability enables secret extraction

High

Improper Control of Generation of Code ('Code Injection') in @tygo-van-den-hurk/slyde

High

Authorization bypass in url-parse

Medium

url-parse Incorrectly parses URLs that include an '@

Medium

RediSearch Query Injection in @langchain/langgraph-checkpoint-redis

Medium

Svelte affected by XSS in SSR `<option>` element

Medium

Svelte affected by cross-site scripting via spread attributes in Svelte SSR

Medium

Svelte SSR does not validate dynamic element tag names in `<svelte:element>`

Medium

Svelte SSR attribute spreading includes inherited properties from prototype chain

Medium

Feathers has an open redirect in OAuth callback enables account takeover

High

Feathers has an origin validation bypass via prefix matching

High

Feathers exposes internal headers via unencrypted session cookie

High

Prototype pollution in swiper - swiper

High

Pannellum has a XSS vulnerability in hot spot attributes

Medium

bn.js affected by an infinite loop

Medium

OneUptime:: node:vm sandbox escape in probe allows any project member to achieve RCE

High

Payload: Server-Side Request Forgery (SSRF) in External File URL Uploads

Medium

repostat: Reflected Cross-Site Scripting (XSS) via repo prop in RepoCard

Medium

Rollup 4 has Arbitrary File Write via Path Traversal

High

Angular SSR is vulnerable to SSRF and Header Injection via request handling pipeline

High

LangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoader

Medium

Storybook Dev Server is Vulnerable to WebSocket Hijacking

High

FUXA has JWT Authentication Bypass via HTTP Referer header spoofing

High

dottie is vulnerable to Prototype Pollution bypass via non-first path segments in set() and transform()

Medium

Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data

Medium

Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers

Medium

fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)

High

fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names

High

deepHas vulnerable to Prototype Pollution via constructor.prototype

High

OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in traceroute exec()

High

Orval has a code injection via unsanitized x-enum-descriptions in enum generation

High

Orval Mock Generation Code Injection via const

High

SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimenta

Low

CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function

High

CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage

High

Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()

High

ajv has ReDoS when using `$data` option

Medium

Dark Reader gives users the ability to request style sheets from local web servers

Low

OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing cre

High

Vercel Workflow Allows Webhook Creation with Predictable User-Specified Tokens - workflow

Medium

Vercel Workflow Allows Webhook Creation with Predictable User-Specified Tokens

Medium

fast-xml-parser has stack overflow in XMLBuilder with preserveOrder

Low

Backstage vulnerable to potential reading of SCM URLs using built in token

Low

fast-xml-parser vulnerable to Regex Injection via Doctype Entities

High

OneUpTime's Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCE

High

OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding

High

OneUptime: Synthetic Monitor RCE via exposed Playwright browser object

High

OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header that leads to cross‑tenant data ex

High

OneUptime has Synthetic Monitor RCE via exposed Playwright browser object

High

OneUptime has WhatsApp Resend Verification Authorization Bypass

Medium

StudioCMS has Privilege Escalation via Insecure API Token Generation

High

Feathers has an OAuth Callback Account Takeover issue

High

Feathers has a NoSQL Injection via WebSocket id Parameter in MongoDB Adapter

High

Elysia has a string URL format ReDoS

High

StudioCMS: IDOR — Arbitrary API Token Revocation Leading to Denial of Service

High

@appium/support has a Zip Slip arbitrary file write in its ZIP extraction

Medium

jsPDF has a PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" pr

High

@siteboon/claude-code-ui is Vulnerable to Shell Command Injection in Git Routes

High

@siteboon/claude-code-ui Vulnerable to Unauthenticated RCE via WebSocket Shell Injection

High

Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`

Medium

devalue has prototype pollution in devalue.parse and devalue.unflatten

Medium

liquidjs has a path traversal fallback vulnerability

High

StudioCMS S3 Storage Manager Authorization Bypass via Missing `await` on Async Auth Check

High

StudioCMS: IDOR — Admin-to-Owner Account Takeover via Password Reset Link Generation

Medium

StudioCMS: IDOR in User Notification Preferences Allows Any Authenticated User to Modify Any User's Settings

Medium

StudioCMS: REST API Missing Rank Check Allows Admin to Create Peer Admin Accounts

Medium

Tina: Path Traversal in Media Upload Handle

High

@tinacms/graphql has a Path Traversal issue

Medium

Unhead has XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol check

Medium

Unhead Vulnerable to Bypass of URI Scheme Sanitization in makeTagSafe via Case-Sensitivity

Low

flatted vulnerable to unbounded recursion DoS in parse() revive phase

High

es5-ext vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`

Low

@nfid/embed has compromised private key due to @dfinity/auth-client producing insecure session keys

High

XSS in @leanprover/unicode-input-component

Low

OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")

High

OneUptime ClickHouse SQL Injection via Aggregate Query Parameters

High

OneUptime: Password Reset Token Logged at INFO Level

Medium

crypto-js uses insecure random numbers

Medium

mapshaper Path Traversal vulnerability

Medium

Cross-Site Scripting (XSS) via Select Schema Option Value Injection in @pdfme/schemas

Medium

Cross-Site Scripting (XSS) via SVG Schema innerHTML Injection in @pdfme/schemas

Medium

StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens

Low

NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability

Medium

MCP Connect has unauthenticated remote OS command execution via /bridge endpoint

High

pdfmake is vulnerable to server-side request forgery (SSRF)

High

CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support package - @ckeditor/ckeditor5-html-support

Medium

CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support package

Medium

jsPDF has a PDF Object Injection via FreeText color

High

Uncontrolled memory allocation via crafted SVG dimensions in @dicebear/converter

High

jsPDF has HTML Injection in New Window paths

High

Qwik City has array method pollution in FormData processing allows type confusion and DoS

High

PDFME has XSS via Unsanitized i18n Label Injection into innerHTML in multiVariableText propPanel

Medium

PDFME has SSRF via Unvalidated URL Fetch in `getB64BasePdf` When `basePdf` Is Attacker-Controlled

Medium

Vulnogram contains a stored cross-site scripting vulnerability in comment hypertext handling

Medium

SQL Injection via unsanitized JSON path keys when ignoring/silencing compilation errors or using `Kysely<any>`.

High

OneUptime ClickHouse vulnerable to SQL Injection via unvalidated column identifiers in sort, select, and groupBy paramet

High

OneUptime WhatsApp Webhook Missing Signature Verification

High

socket.io allows an unbounded number of binary attachments

High

agent-js: Insecure Key Generation in `Ed25519KeyIdentity.generate` - @dfinity/identity

High

agent-js: Insecure Key Generation in `Ed25519KeyIdentity.generate`

High

Potential leakage of Sentry auth tokens by React Native SDK with Expo plugin

Low

Elysia Cookie Value Prototype Pollution

Medium

sanitize-html Information Exposure vulnerability

Medium

PowerSync: Some sync filters ignored on 1.20.0 using `config.edition: 3` - @powersync/service-core

Medium

PowerSync: Some sync filters ignored on 1.20.0 using `config.edition: 3`

Medium

`@backstage/backend-common` vulnerable to path traversal through symlinks

High

fido2-lib is vulnerable to DoS via cbor-extract heap buffer over-read in CBOR attestation parsing

High

fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-

High

sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey

High

Effect `AsyncLocalStorage` context lost/contaminated inside Effect fibers under concurrent load with RPC

High

Prototype Pollution via parse() in NodeJS flatted

High

SVG Injection via Unsanitized Options in @dicebear/core and @dicebear/initials - @dicebear/core

Medium

SVG Injection via Unsanitized Options in @dicebear/core and @dicebear/initials

Medium

SVG Dimension Capping Bypass via XML Comment Injection in @dicebear/converter ensureSize()

High

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters

High

Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that

High

Kysely has a MySQL SQL Injection via Backslash Escape Bypass in non-type-safe usage of JSON path keys.

High

yaml is vulnerable to Stack Overflow via deeply nested YAML collections

Medium

Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection

Medium

Handlebars.js has JavaScript Injection via AST Type Confusion

High

Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block

High

path-to-regexp vulnerable to Denial of Service via sequential optional groups

High

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards

Medium

Handlebars.js has a Property Access Validation Bypass in container.lookup

Low

Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry

Medium

Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies

High

OpenCC has an Out-of-bounds read when processing truncated UTF-8 input

Medium

jsrsasign: Missing cryptographic validation during DSA signing enables private key extraction

High

Cloud Metadata Disclosure

High

Possible Server-Side Request Forgery

High

LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern

High

LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash

High

jsrsasign: Division by Zero Allows Invalid JWK Modulus to Cause Deterministic Zero Output in RSA Operations

Low

Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code

High

Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation

High

Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial

High

Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options

High

NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node

High

Nuxt OG Image vulnerable to Server-Side Request Forgery via user-controlled parameters

Medium

Payload has a CSRF Protection Bypass in Authentication Flow

Medium

Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints - @payloadcms/storage-azure

Medium

Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints - @payloadcms/storage-gcs

Medium

Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints - @payloadcms/storage-r2

Medium

Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints

Medium

lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - lodash-amd

Medium

lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - lodash-es

Medium

lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - lodash.unset

Medium

lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`

Medium

lodash vulnerable to Code Injection via `_.template` imports key names - lodash-amd

High

lodash vulnerable to Code Injection via `_.template` imports key names - lodash-es

High

lodash vulnerable to Code Injection via `_.template` imports key names

High

Axios supply chain attack - dependency in @lightdash/cli may resolve to compromised axios versions

High

Nuxt OG Image is vulnerable to Denial of Service via unbounded image dimensions

Medium

Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes

Medium

@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files

High

Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host - @clerk/hono

High

Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host

High

@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions

High

@tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions

High

Payload has an SQL Injection via Query Handling

High

@payloadcms/next has Stored XSS in Admin Panel

High

Payload has Authenticated SSRF via Upload Functionality

High

SillyTavern: Path Traversal allows file existence oracle

Medium

SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user

High

SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory

High

SillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and IPv6

Medium

dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration

High

@elgentos/magento2-dev-mcp vulnerable to command injection

Low

@stablelib/cbor: Stack exhaustion Denial of Service via deeply nested CBOR arrays, maps, or tags

High

@stablelib/cbor: Prototype poisoning via `__proto__` map keys in CBOR decoding

High

StableLib Ed25519 Signature Malleability via Missing S < L Check

Medium

RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests

High

Drizzle ORM has SQL injection via improperly escaped SQL identifiers

High

@delmaredigital/payload-puc is missing authorization on /api/puck/* CRUD endpoints allows unauthenticated access to Puck

High

x402 SDK Security Advisory

High

Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery - payload

High

Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery

High

Pretext: Algorithmic Complexity (DoS) in the text analysis phase

High

Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser

Medium

LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter

Low

LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header

Medium

LiquidJS: ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting sid

Medium

LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read

Medium

Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()

Medium

Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access

High

Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read

High

@saltcorn/data vulnerable to SQL Injection via jsexprToSQL Literal Handler

Low

Quill is vulnerable to XSS via HTML export feature

Low

@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass

High

@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service

Medium

Zod jsVideoUrlParser vulnerable to ReDoS in util.js

Medium

LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates

High

LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set(

Medium

unhead: Streaming SSR `streamKey` injected into inline script without identifier validation

Low

DbGate has cross site scripting via the SVG Icon String Handler component

Low

MCPHub has an authentication bypass

Medium

Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF

Medium

sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements

Medium

Flowise: Authenticated RCE Via MCP Adapters

High

Flowise: Path Traversal in Vector Store basePath

Medium

Flowise Execute Flow function has an SSRF vulnerability

Medium

Paperclip: Arbitrary File Read via Agent-Controlled adapterConfig.instructionsFilePath

Medium

Paperclip: Stored XSS via javascript: URLs in MarkdownBody — urlTransform override disables react-markdown sanitization

Medium

Cross-site Scripting (XSS) in serialize-javascript

Medium

@saltcorn/data: Tenant user role is used for tenant creation role check

High

Deep Merge is Vulnerable to Prototype Pollution Through Lack of Sanitization

Medium

PostCSS has XSS via Unescaped </style> in its CSS Stringify Output

Medium

Flowise: Cypher Injection in GraphCypherQAChain

High

Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing

Medium

Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering) - @excalidraw/mermaid-to-excalidraw

Medium

Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering)

Medium

Flowise: Code Injection in CSVAgent leads to Authenticated RCE

High

Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas

High

Immutable is vulnerable to Prototype Pollution

High

LangSmith SDK: Streaming token events bypass output redaction

Medium

Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability

High

Flowise: Parameter Override Bypass Remote Command Execution

High

Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains

High

Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)

High

xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion - xmldom

High

xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion

High

Official Clerk JavaScript SDKs: Middleware-based route protection bypass - @clerk/astro

High

Official Clerk JavaScript SDKs: Middleware-based route protection bypass - @clerk/nextjs

High

Official Clerk JavaScript SDKs: Middleware-based route protection bypass - @clerk/shared

High

Official Clerk JavaScript SDKs: Middleware-based route protection bypass

High

Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox

High

Saltcorn: SQL Injection via Unparameterized Sync Endpoints (maxLoadedId)

High

Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

High

Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4)

Low

Axios HTTP/2 Session Cleanup State Corruption Vulnerability

Medium

Unsafe object property setter in mathjs

High

Marked Vulnerable to OOM Denial of Service via Infinite Recursion in marked Tokenizer

High

copilot-api has Reliance on Reverse DNS Resolution for a Security-Critical Action

Low

Arbitrary code execution in protobufjs

High

Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams

Low

Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`

Medium

Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Ax

High

Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy

Medium

Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion

Medium

Axios: Header Injection via Prototype Pollution

High

Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking

High

Axios: HTTP adapter streamed responses bypass maxContentLength

Medium

Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0

Medium

Axios: no_proxy bypass via IP alias allows SSRF

Medium

Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream

Medium

auth-js Vulnerable to Insecure Path Routing from Malformed User Input

Low

@tdurieux/anonymous_github Vulnerable to XSS via Unsanitized GitHub Repository Content Rendering in Anonymous GitHub Ori

High

MCPHub has Path Traversal via Malicious MCPB Manifest Name

High

Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack

High

mcp-data-vis vulnerable to denial of service via unsanitized `select` key lookup on `Object.prototype` with `precompile:

Low

BigSweetPotatoStudio HyperChat has a Server-Side Request Forgery issue

Medium

CyberChef has a Cross-site Scripting issue

High

@diplodoc/search-extension allows stored XSS via Markdown file title

Medium

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

High

Electerm runWidget has a path traversal that leads to arbitrary code execution

High

Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click

High

Electerm's full process.env exposed to renderer via window.pre.env

Medium

Electerm Security Vulnerability: RCE via malicious SSH server filename in openFileWithEditor

High

Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS

High

@nocobase/database has SQL Injection via String Concatenation through Recursive Eager Loading

High

mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes

High

xmldom has XML node injection through unvalidated comment serialization - xmldom

High

xmldom has XML node injection through unvalidated comment serialization

High

xmldom has XML node injection through unvalidated processing instruction serialization - xmldom

High

xmldom has XML node injection through unvalidated processing instruction serialization

High

xmldom has XML injection through unvalidated DocumentType serialization - xmldom

High

xmldom has XML injection through unvalidated DocumentType serialization

High

xmldom: Uncontrolled recursion in XML serialization leads to DoS - xmldom

High

xmldom: Uncontrolled recursion in XML serialization leads to DoS

High

fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters

Medium

Saltcorn: Open Redirect in `POST /auth/login` due to incomplete `is_relative_url` validation (backslash bypass)

Medium

i18next-http-backend has Path Traversal & URL Injection via Unsanitised lng/ns

Medium

i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes

Medium

Inngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTTP methods

High

electerm: electerm_install_script_CommandInjection Vulnerability Report

High

OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment

High

FUXA has a hardcoded fallback JWT signing secret

High

electerm has Command Injection via runLinux funtion

High

Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking

High

protobuf.js: Code injection through bytes field defaults in generated toObject code

High

query-parser-string is vulnerable to Prototype Pollution

High

youtube-regex vulnerable to Regex Denial of Service

High

SillyTavern has a Path Traversal issue

High

Marko: XSS via case-insensitive script/style closing tag bypass in runtime HTML escaping - marko

Medium

Marko: XSS via case-insensitive script/style closing tag bypass in runtime HTML escaping

Medium

i18next-locize-backend has URL Injection via Unsanitized Path Parameters

Medium

locize Client SDK: Cross-origin DOM XSS & Handler Hijack Through Missing e.origin Validation in InContext Editor

High

Electerm users can run dangrous code through link or command line

High

RedwoodSDK has Same-site CSRF through lack of origin validation in its server actions

Medium

liquidjs has a Denial of Service via circular block reference in layout

High

Angular Expressions - Remote Code Execution using filters

High

Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)

Medium

@workos/authkit-session has an Open Redirect via state-derived redirect target

Medium

link-preview-js vulnerable to IPv6 and internal loopback attacks

High

PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF

High

LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution

Medium

Karakeep SDK has SSRF via metascraper-logo-favicon that bypasses validateUrl protections

High

Svelte: SSR XSS via Insecure Promise Serialization in hydratable

Medium

protobuf.js: Denial of service through unbounded protobuf recursion

High

protobufjs has overlong UTF-8 decoding - @protobufjs/utf8

Medium

protobufjs has overlong UTF-8 decoding

Medium

protobuf.js: Process-wide denial of service through unsafe option paths

High

protobuf.js: Code generation gadget after prototype pollution

High

protobuf.js: Prototype injection in generated message constructors

Medium

protobuf.js: Denial of service from crafted field names in generated code

Medium

NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins

Medium

Nitro has a proxy scope bypass via percent-encoded path traversal in `routeRules` - nitro

Medium

Nitro has a proxy scope bypass via percent-encoded path traversal in `routeRules`

Medium

@samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User Imperson

High

Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks - @backstage/plugin-catalog-unprocessed-entities-common

Medium

Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks

Medium

Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying

Medium

Strapi: Password Reset Does Not Revoke Existing Refresh Sessions - @strapi/plugin-users-permissions

Low

Strapi: Password Reset Does Not Revoke Existing Refresh Sessions

Low

nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)

Low

Flowise has an MCP Security Bypass that Enables RCE

High

open-webui Vulnerable to Stored XSS via Model Description

High

Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Ex

High

Sveltia CMS: Stored XSS in entry summary rendering via entity-decoded HTML

Low

automagik-genie has a command injection vulnerability

High

@tmlmobilidade/utils has prototype pollution in its setValueAtPath

High

Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp - @mistralai/mistralai-azure

Low

Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp - @mistralai/mistralai

Low

Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp

Low

Open WebUI Has Stored Cross-Site Scripting in SVG Renderer

Medium

Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order

High

protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion

Medium

PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE

High

Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain

Medium

seroval affected by Denial of Service via RegExp serialization

High

electerm allows unauthorized users to execute arbitrary commands

High

Strapi may leak sensitive data via relational filtering due to lack of query sanitization

High

@tootallnate/once vulnerable to Incorrect Control Flow Scoping

Low

uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

Medium

Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects

Medium

@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty

High

CryptPad has a Sanitizer Bypass in Diffmarked.js that Allows Arbitrary HTML Injection and Potential XSS

Medium

FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection

High

LiquidJS is Vulnerable to Remote Code Execution

High

@kilocode/cli Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Low

@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue

Low

AgenticMail API/storage and outbound relay hardening fixes

High

Bootstrap Vulnerable to Cross-Site Scripting - bootstrap

Medium

Bootstrap Vulnerable to Cross-Site Scripting

Medium

React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint

High

React Router vulnerable to Denial of Service via reflected user input in single-fetch

High

DbGate: Unauthenticated Remote Code Execution via JSON Script Runner

High

DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE

High

Authenticated Remote Code Execution via loadReader functionName code injection in DbGate

High

TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs

High

Insufficient Entropy in cryptiles

High

Axios: unbounded recursion in toFormData causes DoS via deeply nested request data

Medium

TeleJSON: DOM XSS via unsanitised constructor name in `new Function()`

Low

MagicMirror vulnerable to unauthenticated SSRF via /cors endpoint

High

Bootstrap Cross-site Scripting vulnerability - bootstrap - GHSA-7mvr-5x2g-wfc8

Medium

Bootstrap Cross-site Scripting vulnerability - bootstrap-sass

Medium

Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection

Medium

Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection

Medium

@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input

High

Velocity.js has a Prototype Pollution vulnerability through #set path assignment

High

Auth.js SDK has Improper Permission Checking

High

Cinny vulnerable to access token disclosure via invalidated emoji pack avatar URL in service worker

High

@rvf/set-get has a prototype pollution issue that's reachable via @rvf/core preprocessFormData (HTTP form data)

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/arktype-adapter

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/eslint-plugin-router

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/history

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/react-router-devtools

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/react-router-ssr-query

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/react-router

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/react-start-client

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/react-start-rsc

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/react-start

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-core

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-devtools-core

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-devtools

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-generator

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-plugin

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-ssr-query-core

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-utils

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-vite-plugin

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/solid-router-devtools

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/solid-router-ssr-query

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/solid-router

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/solid-start-client

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/solid-start

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/start-client-core

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/start-storage-context

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/valibot-adapter

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/virtual-file-routes

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/vue-router-devtools

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/vue-router-ssr-query

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/vue-router

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/vue-start-client

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/vue-start

High

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys

High

Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()`

High

LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning

High

OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover

Medium

Nitro has an Open Redirect via Protocol-Relative URL Bypass in Wildcard Route Rules - nitro

Medium

Nitro has an Open Redirect via Protocol-Relative URL Bypass in Wildcard Route Rules

Medium

Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark

High

electerm's encrypt method not safe enough

Medium

@ranfdev/deepobj has a Prototype Pollution vulnerability

High

form-data-objectizer: Prototype pollution in form-data-objectizer via bracket-notation form keys

High

Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS

Medium

Mermaid: Improper sanitization of configuration leads to CSS injection

Medium

Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass

Medium

React Router has CSRF issue in Action/Server Action Request Processing

Medium

SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover

High

SillyTavern has Authentication Bypass via SSO Header Injection

High

SillyTavern has a reflected XSS vulnerability in the CORS proxy middleware

Medium

SillyTavern has a SSRF vulnerability in the CORS proxy middleware

Medium

SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl

High

Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/astro

High

Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/backend

High

Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/chrome-extension

High

Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/clerk-expo

High

Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/clerk-js

High

Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/clerk-react

High

Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/expo

High

Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/hono

High

Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/nextjs

High

Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/nuxt

High

Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/react-router

High

Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/react

High

Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/shared

High

Clerk has an authorization bypass when combining organization, billing, or reverification checks - @clerk/vue

High

Clerk has an authorization bypass when combining organization, billing, or reverification checks

High

Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability

High

Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions - lodash-amd

Medium

Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions - lodash-es

Medium

Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions - lodash.unset

Medium

Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions

Medium

Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution

High

HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis

High

HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft

Medium

Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover - @haxtheweb/video-player

High

Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover

High

Svelte: ReDoS in `<svelte:element>` Tag Validation

Medium

Svelte devalue: DoS via sparse array deserialization

High

Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State

Medium

Svelte SSR vulnerable to cross-site scripting via spread attributes

Medium

md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)

High

Papra HTTP redirect bypass can lead to SSRF via webhook delivery system

Low

Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection

High

Element Call reports full URLs of visited pages to analytics server

High

OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts

High

@cyntler/react-doc-viewer's TXTRenderer fails to sanitize file content and explicitly casts raw data as a ReactNode

Medium

JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection

High

Cross-site scripting in Survey Creator

Medium

wangEditor was discovered to contain a cross-site scripting (XSS) vulnerability via the image upload function

Medium

LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access

Medium

Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection

High

Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter

High

Allocation of Resources Without Limits or Throttling in Axios

High

Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix

Low

axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions

Medium

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

High

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

High

joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas

Medium

esbuild allows arbitrary file read when running the development server on Windows

Low

Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser

High

actual Allows Electron to Run As Node

Medium

Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`

High

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

Low

UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`

Medium

OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation

Medium

markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations

Medium

@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Re - @nuxt/webpack-builder

Medium

@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Re

Medium

TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes - @tinacms/mdx

Medium

TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes

Medium

Privilege Escalation in cordova-plugin-inappbrowser

High

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated s - @openzeppelin/wizard-cairo

Low

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated s - @openzeppelin/wizard-stellar

Low

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated s - @openzeppelin/wizard-stylus

Low

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated s

Low

TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB)

Medium

[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat - @theia/ai-chat-ui

Medium

[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat - @theia/ai-chat

Medium

[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat - @theia/ai-claude-code

Medium

[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat - @theia/ai-code-completion

Medium

[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat - @theia/ai-core

Medium

[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat - @theia/ai-ide

Medium

[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat

Medium

[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-chat-ui

High

[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-chat

High

[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-claude-code

High

[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-code-completion

High

[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-core

High

[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-ide

High

[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat

High

[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions - @theia/debug

High

[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions - @theia/task

High

[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions

High

[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat - @theia/ai-chat-ui

High

[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat - @theia/ai-chat

High

[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat - @theia/ai-claude-code

High

[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat - @theia/ai-code-completion

High

[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat - @theia/ai-core

High

[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat

High

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover - @tinacms/app

High

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

High

ts-deepmerge: Prototype Method Override leads to DoS

Medium

Sveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe

Low

Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests

High

scimPatch vulnerable to prototype pollution via unfiltered keys in patch

High

devbridge-autocomplete has XSS in its default formatters: formatGroup and formatResult fail to escape HTML in untrusted

Medium

neotoma has tenant isolation gap in relationship query endpoints

Low

Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)

High

MJML allows mj-include directory traversal due to an incomplete fix for CVE-2020-12827

Medium

Sveltejs devalue's `devalue.parse` and `devalue.unflatten` emit objects with `__proto__` own properties

Low

LinkifyIt#match scan loop has quadratic algorithmic complexity

High

better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server

High

Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication

High

js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals

High

@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub

Medium

TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection

High

@sveltejs/kit: `query.batch` cross-talk

Medium

@jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization

Medium

wetty vulnerable to DOM XSS via file-download filename

High

sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced

High

@asymmetric-effort/specifyjs: URL parse failure silently allows request

High

@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection

Medium

@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state

Medium

@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)

Medium

@asymmetric-effort/specifyjs: `data:` URI allowed without size restriction

Medium

@asymmetric-effort/specifyjs: No redirect target validation in secureFetch

Medium

@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString

Medium

@conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields

High

electerm has Path Traversal in Zmodem and Trzsz Download Filename Handling

High

electerm has Command Injection in File System Operations (rmrf, mv, cp)

High

Electerm Local code through electerm's single-instance socket

High

@enclave-vm/core is vulnerable to Sandbox Escape

High

karma-mojo enables OS Command Injection

High

Injection in op-browser

High

Decompress: Archive extraction can create files and links outside of the target directory

High

TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes

High

Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99) - @nuxt/webpack-builder

Medium

Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)

Medium

Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning

Low

Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`

Medium

DbGate: Remote Code Execution via functionName injection in loadReader endpoint

High

Waku: Cross-Origin CSRF on RSC Server Action Dispatch

Medium

Waku has an Open Redirect via `unstable_redirect` Helper

Low

Claw Orchestrator is missing authentication for the component API Endpoint

Medium

Claw Orchestrator has inefficient regular expression complexity via validateRegex()

Medium

Potential XSS vulnerability in jQuery - jquery

Medium

LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS

Medium

LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body

Medium

LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`

Medium

LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)

High

LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex

High

tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies

Medium

DesktopCommanderMCP is vulnerable to Uncontrolled Resource Consumption

Low

DesktopCommanderMCP is vulnerable to SSRF

Low

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

High

Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__

Low

TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments

High

obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/wr

High

Embedded malware in ua-parser-js

High

protobufjs: Denial of service through unbounded Any expansion during JSON conversion

High

@babel/core: Arbitrary File Read via sourceMappingURL Comment

Low

protobufjs : Schema-derived names can shadow runtime-significant properties

Medium

protobufjs: Memory amplification from preserved unknown fields in binary decode

Medium

websocket-driver: Message corruption via abuse of protocol length headers

High

websocket-driver: Resource limit bypass via message compression

Medium

ExifReader is vulnerable to denial of service via crafted ICC `mluc` tag

High

ExifReader is vulnerable to denial of service via unbounded decompression of image metadata

Medium

TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification g

Medium

Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader

High

ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes

Medium

CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification

High

Angular's deprecated package has a Cross-Site Scripting issue

High

@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default

High

Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization

Medium

axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CV

High

Dash apps vulnerable to Cross-site Scripting - dash-core-components

Medium

Dash apps vulnerable to Cross-site Scripting

Medium

Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

Medium

Axios: Excessive recursion in formDataToJSON can cause denial of service

Medium

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

High

LobeHub: Unauthenticated SSRF in `/webapi/proxy`

High

@better-auth/sso: SSO provider may allow registration for any org member without a checking their role

High

defuddle vulnerable to XSS via unescaped string interpolation in _findContentBySchemaText image tag

Low

Socket.IO: Engine.IO Polling Transport Connection Exhaustion

High

protobufjs: Denial of Service via infinite loop in .proto option parsing

Medium

protobufjs: Text Format string map parsing can mutate returned map object prototype

Medium

Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

Medium

Axios: Prototype pollution gadgets can alter axios request construction

Medium

Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`

Medium

Axios: HTTP/2 streamed uploads bypass `maxBodyLength`

Medium

Axios: Nested axios option objects can consume polluted prototype values

Medium

Axios form serializer maxDepth bypass via {} metatoken

Medium

Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning

High

AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridg

High

Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory

Medium

jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputs

High

jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce Generation

High

jsrsasign: Negative Exponent Handling Leads to Signature Verification Bypass

High

jsrsasign: DSA signatures or X.509 certificates can be forged via DSA domain-parameter validation in KJUR.crypto.DSA.set

High

js-toml has silent type confusion via falsy-primitive duplicate-key bypass

Medium

Immutable.js `List` 32-bit trie overflow → unrecoverable DoS

High

Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set

High

linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text

High

OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header

High

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

High

fast-uri vulnerable to host confusion via literal backslash authority delimiter

High

PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments

High

LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce

High

SvelteKit: Big remote form function payloads can cause Node process to crash

Medium

SvelteKit: Prototype pollution in file input deletion path in remote-function forms

Medium

seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization

High

Valibot: record() issue paths can make flatten() throw for inherited Object property names

Medium

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

High

mathlive's Lack of Escaping of HTML allows for XSS - mathlive

Medium

degit has a Command Injection issue

High

d3-color vulnerable to ReDoS

High

AWS Amplify Studio UI Component Properties Has an Input Validation Issue

High

jodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()

Medium

@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging

High

Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS

Medium

Jodit has prototype pollution via Jodit.configure() / ConfigMerge

Medium

Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier

High

Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization

Medium

sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, pos

Medium

Prompty: Arbitrary file read via file reference expansion

High

PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `f

Medium

Socket.IO: Zero-attachment Memory Exhaustion

High

fast-uri vulnerable to host confusion via backslash authority introducer

High

jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion

High

Flowise RCE via TypeORM DataSource

High

Flowise Sandbox Escape to RCE

High

Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override

High

Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified

High

Flowise RCE via SQLite Record Manager Node

High

Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)

High

Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE

High

Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys

High

Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation

High

Flowise: Remote Code Execution Vulnerability in CSVAgent

High

Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability - flowise-components

High

@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

High

@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration

Medium

Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host

High

Mermaid XY Charts are vulnerable to an infinite loop DoS

Medium

Mermaid Architecture diagrams are vulnerable to prototype pollution

Medium

Mermaid allows CSS injection applying to sibling elements of the diagram

Medium

Mermaid configuration APIs allow prototype pollution

Low

Mermaid radar diagrams are vulnerable to DoS

Medium

PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF

High

ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633

High

SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header

Medium

Axios: Prototype pollution auth subfields can inject Basic auth

Medium

crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain

High

nanoid: non-secure generators can loop indefinitely with negative size

High

showdown allows stored cross-site scripting through table header ID injection

Medium

showdown metadata title handling allows cross-site scripting

Medium

fast-uri vulnerable to path traversal via percent-encoded dot segments

High

Trix has a Stored XSS vulnerability through serialized attributes

Medium

Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)

Low

Trix: Stored XSS via HTMLParser attribute injection on paste

Medium

ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header

Medium

ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-

Medium

ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartex

Medium

fast-uri vulnerable to host confusion via percent-encoded authority delimiters

High

nanoid: custom generators can loop indefinitely when size is zero

High

@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion

High

fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits

High

PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure

High

Quasar: Prototype pollution in the extend() utility

Medium

Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)

High

TypeORM: migration:generate template-literal code injection

Medium

fast-uri vulnerable to host confusion via failed IDN canonicalization

High

Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set

High

Vulnerable Apache Version

Medium

Vulnerable Nginx Version

Medium

Vulnerable OpenSSL Version

Medium

Vulnerable PHP Version

Medium

Vulnerable Tomcat Version

Medium

Vulnerable WordPress Version

High

Download Free SmartScanner and test for vulnerabilities

Download