| Unchecked Input for Loop Condition | |
| CVE-2026-19693 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| CVE-2026-45819 | |
| Directory Traversal | |
| Directory Traversal | |
| GHSA-2xp9-vwfh-vxw4 | |
| GHSA-rgj7-g3m4-5g8c | |
| Uncontrolled Recursion | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| CVE-2026-16732 | |
| CVE-2026-18504 | |
| Integer Overflow or Wraparound | |
| Improper Resource Shutdown or Release | |
| Uncaught Exception | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2026-8657 | |
| Improper Input Validation | |
| GHSA-5p4m-2wfm-xmqj | |
| CVE-2026-13676 | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| GHSA-c2j3-45gr-mqc4 | |
| GHSA-mmx7-hfxf-jppx | |
| Use of Less Trusted Source | |
| Improper Resource Shutdown or Release | |
| Information Exposure | |
| Protection Mechanism Failure | |
| Algorithmic Complexity | |
| Improper Input Validation | |
| CVE-2026-16221 | |
| Algorithmic Complexity | |
| GHSA-42h9-826w-cgv3 | |
| GHSA-mwf2-3pr3-8698 | |
| Improper Input Validation | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Resource Exhaustion | |
| Inefficient Regular Expression Complexity | |
| GHSA-pmv8-rq9r-6j72 | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| CVE-2026-18446 | |
| Race Condition | |
| Resource Exhaustion | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| CVE-2026-14257 | |
| GHSA-gcfj-64vw-6mp9 | |
| Improper Input Validation | |
| GHSA-7q8q-rj6j-mhjq | |
| Cross-site Scripting (XSS) | |
| GHSA-55q2-fjhq-7xh7 | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Uncontrolled Recursion | |
| Trust Boundary Violation | |
| Improper Input Validation | |
| Exposure of Data Element to Wrong Session | |
| Cross-site Scripting (XSS) | |
| Algorithmic Complexity | |
| GHSA-f4gw-2p7v-4548 | |
| GHSA-hcpx-6fm6-wx23 | |
| CVE-2026-13149 | |
| GHSA-jqh4-m9w3-8hp9 | |
| Cross-site Scripting (XSS) | |
| GHSA-fv92-fjc5-jj9h | |
| CVE-2025-47914 | |
| Information Exposure | |
| CVE-2024-10846 | |
| CVE-2025-22872 | |
| CVE-2025-58181 | |
| CVE-2025-47911 | |
| CVE-2024-45338 | |
| CVE-2024-24786 | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Server-Side Request Forgery (SSRF) | |
| Cross-site Scripting (XSS) | |
| CVE-2022-33987 | |
| Interpretation Conflict | |
| Directory Traversal | |
| CVE-2023-45289 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Untrusted Search Path | |
| Incorrect Calculation | |
| CVE-2024-24785 | |
| Directory Traversal | |
| CVE-2025-46653 | |
| CVE-2026-14643 | |
| Directory Traversal | |
| Resource Exhaustion | |
| Directory Traversal | |
| CVE-2024-31207 | |
| CVE-2026-13311 | |
| Directory Traversal | |
| Cross-site Request Forgery (CSRF) | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Cross-site Scripting (XSS) | |
| Improper Input Validation | |
| Resource Exhaustion | |
| CVE-2026-13697 | |
| Improper Handling of Exceptional Conditions | |
| Allocation of Resources Without Limits or Throttling | |
| Directory Traversal | |
| GHSA-g7r4-m6w7-qqqr | |
| Directory Traversal | |
| Cross-site Scripting (XSS) | |
| Information Exposure | |
| CVE-2023-39326 | |
| CVE-2023-45290 | |
| Resource Exhaustion | |
| CVE-2024-24789 | |
| CVE-2024-24787 | |
| Cross-site Scripting (XSS) | |
| CVE-2023-45284 | |
| Server-Side Request Forgery (SSRF) | |
| Resource Exhaustion | |
| CVE-2026-7120 | |
| CVE-2026-6410 | |
| CVE-2026-15074 | |
| External Control of File Name or Path | |
| Information Exposure | |
| CVE-2026-6414 | |
| CVE-2024-24783 | |
| Directory Traversal | |
| Information Exposure | |
| Origin Validation Error | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Arbitrary Code Injection | |
| Arbitrary Code Injection | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Unchecked Input for Loop Condition | |
| Arbitrary Code Injection | |
| CVE-2026-56876 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| CVE-2026-41149 | |
| Resource Exhaustion | |
| Uncaught Exception | |
| Interpretation Conflict | |
| Incorrect Type Conversion or Cast | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Cross-site Scripting (XSS) | |
| Excessive Iteration | |
| Algorithmic Complexity | |
| Information Exposure | |
| Open Redirect | |
| Allocation of Resources Without Limits or Throttling | |
| Information Exposure Through Caching | |
| Server-Side Request Forgery (SSRF) | |
| Improper Encoding or Escaping of Output | |
| Uncaught Exception | |
| GHSA-f88m-g3jw-g9cj | |
| Allocation of Resources Without Limits or Throttling | |
| OS Command Injection | |
| GHSA-wqvq-jvpq-h66f | |
| CVE-2026-9678 | |
| CVE-2026-39410 | |
| Incorrect Regular Expression | |
| HTTP Request Smuggling | |
| Directory Traversal | |
| Incorrect Regular Expression | |
| Arbitrary Code Injection | |
| Inappropriate Comment Style | |
| GHSA-gq3j-xvxp-8hrf | |
| Cleartext Transmission of Sensitive Information | |
| GHSA-268h-hp4c-crq3 | |
| Improper Authorization | |
| Insufficient Verification of Data Authenticity | |
| Improper Encoding or Escaping of Output | |
| Cross-site Scripting (XSS) | |
| Resource Exhaustion | |
| Incorrect Behavior Order: Validate Before Canonicalize | |
| CVE-2026-56761 | |
| HTTP Response Splitting | |
| Information Exposure | |
| Arbitrary Code Injection | |
| Use of Less Trusted Source | |
| Use of Uninitialized Resource | |
| GHSA-26pp-8wgv-hjvm | |
| Information Exposure Through Caching | |
| Resource Exhaustion | |
| Arbitrary Code Injection | |
| Directory Traversal | |
| GHSA-v8w9-8mx6-g223 | |
| Information Exposure | |
| Cross-site Request Forgery (CSRF) | |
| Improper Validation of Specified Quantity in Input | |
| GHSA-r7g4-qg5f-qqm2 | |
| GHSA-q7jf-gf43-6x6p | |
| Uncaught Exception | |
| Directory Traversal | |
| Information Exposure Through Caching | |
| CVE-2024-55565 | |
| CVE-2024-28863 | |
| Inefficient Regular Expression Complexity | |
| CVE-2021-23368 | |
| Arbitrary Code Injection | |
| Cross-site Scripting (XSS) | |
| Server-Side Request Forgery (SSRF) | |
| Inefficient Regular Expression Complexity | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| CVE-2026-1525 | |
| Information Exposure | |
| Server-Side Request Forgery (SSRF) | |
| Directory Traversal | |
| Inefficient Regular Expression Complexity | |
| CVE-2026-8723 | |
| CVE-2026-4926 | |
| GHSA-h25m-26qc-wcjf | |
| Uncaught Exception | |
| Inefficient Regular Expression Complexity | |
| CVE-2025-9910 | |
| Authentication Bypass | |
| Directory Traversal | |
| Information Exposure | |
| CVE-2026-3635 | |
| CVE-2025-48068 | |
| CVE-2026-2229 | |
| Improper Handling of Unicode Encoding | |
| Allocation of Resources Without Limits or Throttling | |
| Race Condition | |
| Improper Verification of Cryptographic Signature | |
| Information Exposure Through Caching | |
| Inefficient Regular Expression Complexity | |
| CVE-2025-22869 | |
| GHSA-6v7q-wjvx-w8wg | |
| Authentication Bypass | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Deserialization of Untrusted Data | |
| Interpretation Conflict | |
| GHSA-8h8q-6873-q5fj | |
| Resource Exhaustion | |
| Race Condition | |
| CVE-2026-6734 | |
| Improper Certificate Validation | |
| Access of Resource Using Incompatible Type ('Type Confusion') | |
| Directory Traversal | |
| Arbitrary Code Injection | |
| Reachable Assertion | |
| Improper Authorization | |
| Uncontrolled Recursion | |
| GHSA-p6gq-j5cr-w38f | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2024-37890 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| CVE-2025-59471 | |
| Resource Exhaustion | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| Link Following | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Cross-site Request Forgery (CSRF) | |
| Cross-site Scripting (XSS) | |
| Algorithmic Complexity | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| CVE-2024-34351 | |
| Uncontrolled Recursion | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-5j59-xgg2-r9c4 | |
| Improper Handling of URL Encoding (Hex Encoding) | |
| Algorithmic Complexity | |
| Incorrect Authorization | |
| Improper Certificate Validation | |
| GHSA-q4gf-8mx6-v5v3 | |
| Uncontrolled Recursion | |
| Improper Verification of Cryptographic Signature | |
| OS Command Injection | |
| GHSA-w37m-7fhw-fmv9 | |
| Directory Traversal | |
| Interpretation Conflict | |
| Resource Exhaustion | |
| Arbitrary Code Injection | |
| Improper Handling of Exceptional Conditions | |
| Resource Exhaustion | |
| Inefficient Regular Expression Complexity | |
| Allocation of Resources Without Limits or Throttling | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| CVE-2026-33806 | |
| Improper Input Validation | |
| Directory Traversal | |
| OS Command Injection | |
| Directory Traversal | |
| CVE-2026-1526 | |
| CVE-2026-32280 | |
| Allocation of Resources Without Limits or Throttling | |
| Server-Side Request Forgery (SSRF) | |
| Uncaught Exception | |
| XML Injection | |
| Improper Verification of Cryptographic Signature | |
| Open Redirect | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2026-9697 | |
| Direct Request ('Forced Browsing') | |
| Cross-site Scripting (XSS) | |
| Information Exposure | |
| Improper Input Validation | |
| CVE-2026-12143 | |
| Overly Permissive Cross-domain Whitelist | |
| CVE-2026-6322 | |
| Directory Traversal | |
| CVE-2025-1302 | |
| Improper Certificate Validation | |
| Exposure of Resource to Wrong Sphere | |
| CVE-2025-22868 | |
| Arbitrary Code Injection | |
| Allocation of Resources Without Limits or Throttling | |
| Symlink Following | |
| HTTP Request Smuggling | |
| Race Condition | |
| GHSA-mwv6-3258-q52c | |
| XML Injection | |
| Cross-site Scripting (XSS) | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Directory Traversal | |
| Incorrect Execution-Assigned Permissions | |
| Cross-site Scripting (XSS) | |
| CVE-2026-6321 | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Acceptance of Extraneous Untrusted Data With Trusted Data | |
| Resource Exhaustion | |
| CVE-2026-2391 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Improper Authorization | |
| Allocation of Resources Without Limits or Throttling | |
| Resource Exhaustion | |
| CVE-2025-48985 | |
| Reversible One-Way Hash | |
| Uncontrolled Recursion | |
| GHSA-5c6j-r48x-rmvq | |
| Incorrect Authorization | |
| Authentication Bypass | |
| Use of a Broken or Risky Cryptographic Algorithm | |
| CVE-2024-41110 | |
| Out-of-Bounds | |
| Missing Authorization | |
| Deserialization of Untrusted Data | |
| GHSA-9qr9-h5gf-34mp | |
| Improper Authorization | |
| CVE-2026-39821 | |
| CVE-2025-68121 | |
| Missing Authorization | |
| Authorization Bypass Through User-Controlled Key | |
| Improper Certificate Validation | |
| Directory Traversal | |
| CVE-2026-9277 | |
| CVE-2026-27143 | |
| CVE-2026-46595 | |
| Integer Overflow or Wraparound | |
| CVE-2024-21534 | |
| CVE-2023-45288 | |
| Information Exposure | |
| Incorrect Authorization | |
| CVE-2025-31125 | |