SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but extracts native libraries wit...
A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Ma...
The /v1/upload/sbom endpoint extracts the iss claim from the attacker-supplied JWT with signature verification disabled, then interpolates that str...
libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function pro...
Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce
Unauthenticated Broken Access Control in Japanized For WooCommerce
Unauthenticated Broken Access Control in Business Directory
Unauthenticated Cross Site Scripting (XSS) in ARForms
Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder
Unauthenticated Cross Site Scripting (XSS) in Jobify
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.