Recent
Published 2026-03-12 by canonical
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
Published 2026-03-12 by GitHub_M
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
Published 2026-03-12 by GitHub_M
shopware/commercial: `/api/_info/config` route exposes information about licenses
Published 2026-03-12 by GitHub_M
Inductive Automation Ignition Software Deserialization of Untrusted Data
Published 2026-03-12 by icscert
Uptime Kuma is Missing Authorization Checks on Ping Badge Endpoint, Leaks Ping times of monitors without needing to be on a status page
Published 2026-03-12 by GitHub_M
swag/platform-security: `/api/_info/config` route exposes information about licenses and active security fixes
Published 2026-03-12 by GitHub_M
flatted: Unbounded recursion DoS in parse() revive phase
Published 2026-03-12 by GitHub_M
Dataease: Redshift JDBC RCE Bypass
Published 2026-03-12 by GitHub_M
tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling
Published 2026-03-12 by PSF
Load more ↓