| GHSA-2m67-wjpj-xhg9 | |
| GHSA-pwqr-wmgm-9rr8 | |
| HTTP Request Smuggling | |
| Improper Certificate Validation | |
| Improper Cross-boundary Removal of Sensitive Data | |
| GHSA-7xrh-hqfc-g7qr | |
| Information Exposure Through Log Files | |
| GHSA-w9fj-cfpg-grvv | |
| Allocation of Resources Without Limits or Throttling | |
| Arbitrary Code Injection | |
| GHSA-x27p-5f68-m644 | |
| GHSA-crhr-qqj8-rpxc | |
| GHSA-c87w-642h-m97h | |
| Resource Exhaustion | |
| GHSA-xxh7-fcf3-rj7f | |
| Cross-site Scripting (XSS) | |
| Directory Traversal | |
| GHSA-j4j7-vw47-rhfq | |
| Direct Request ('Forced Browsing') | |
| GHSA-rv83-g57w-fr8j | |
| GHSA-j3gx-2473-5fp8 | |
| GHSA-72hv-8253-57qq | |
| GHSA-h355-32pf-p2xm | |
| GHSA-qqpg-mvqg-649v | |
| CVE-2025-68121 | |
| GHSA-8jvr-vh7g-f8gx | |
| CVE-2025-61732 | |
| CVE-2026-1225 | |
| GHSA-7286-pgfv-vxvh | |
| GHSA-mm8h-8587-p46h | |
| Authorization Bypass Through User-Controlled Key | |
| Resource Exhaustion | |
| Improper Input Validation | |
| GHSA-m494-w24q-6f7w | |
| GHSA-84h7-rjj3-6jx4 | |
| CRLF Injection | |
| GHSA-vx9q-rhv9-3jvg | |
| Out-of-bounds Read | |
| CVE-2025-11226 | |
| CRLF Injection | |
| Improper Handling of Insufficient Permissions or Privileges | |
| HTTP Request Smuggling | |
| Improper Handling of Highly Compressed Data (Data Amplification) | |
| Resource Exhaustion | |
| Allocation of Resources Without Limits or Throttling | |
| Race Condition | |
| CVE-2025-48734 | |
| External Control of File Name or Path | |
| CVE-2025-22871 | |
| Information Exposure Through Log Files | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| CVE-2024-32888 | |
| CVE-2024-6763 | |
| GHSA-qh8g-58pp-2wxh | |
| Deserialization of Untrusted Data | |
| Deserialization of Untrusted Data | |
| CVE-2024-57699 | |
| CVE-2025-24970 | |
| CVE-2024-45336 | |
| CVE-2024-34155 | |
| CVE-2024-34156 | |
| CVE-2024-45341 | |
| CVE-2024-34158 | |
| Untrusted Search Path | |
| Incorrect Conversion between Numeric Types | |
| Incorrect Default Permissions | |
| CVE-2024-12798 | |
| CVE-2024-12801 | |
| Out-of-bounds Write | |
| CVE-2024-43382 | |
| XML External Entity (XXE) Injection | |
| Improper Initialization | |
| Missing Encryption of Sensitive Data | |
| Race Condition | |
| CVE-2024-36114 | |
| Deserialization of Untrusted Data | |
| Improper Certificate Validation | |
| Out-of-bounds Write | |
| Out-of-bounds Write | |
| CVE-2024-23450 | |
| CVE-2023-42503 | |
| Missing Authorization | |
| Resource Exhaustion | |
| File and Directory Information Exposure | |
| CVE-2020-13956 | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| SQL Injection | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Allocation of Resources Without Limits or Throttling | |
| Deserialization of Untrusted Data | |
| CVE-2022-3510 | |
| CVE-2021-22569 | |
| CVE-2022-3509 | |
| CVE-2022-3171 | |
| Deserialization of Untrusted Data | |
| CVE-2023-51074 | |
| Deserialization of Untrusted Data | |
| Directory Traversal | |