Unauthenticated Broken Access Control in JobSearch
Unauthenticated Cross Site Scripting (XSS) in Enfold
Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and appli...
Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob i...
ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from...
Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip v...
Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-s...
Unauthenticated PHP Object Injection in Valeska
Unauthenticated PHP Object Injection in Behold
Unauthenticated PHP Object Injection in Esmée
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.