sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.…
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper t…
@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route w…
frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by a…
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a us…
Hub is a Node.js WebSocket server and client with added features. Prior to 0.2.16, every incoming unauthenticated WebSocket connection triggers loadD…
Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauth…
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote atta…
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query …
The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By Type Response received from …
Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attacke…
ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL b…
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by ma…
SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a rece…
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
Private Repository Existence Disclosure via go-get Meta Endpoint
Public-only repository tokens can update private PR head branches
Repository migration SSRF via multi-answer DNS allow-list bypass
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplet…
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
Repository Visibility Manipulation via Git Push Options
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
Gitea LFS Deploy-Key Privilege Escalation
Private Repository Metadata Remains Accessible After Access Revocation
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of …
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)