Vulnerability Database & Alerts

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors

Recently

....... NLTK (Python library)........ <= 3.9.2 Vulnerability :...... Path Traversal (CWE-22) Severity: ....... 7.5 (High) date: .......... March 4, 2026 Prediction: Fixed in NLTK 3.9.3 What Undercode Say: Analytics The vulnerability stems from a logical error where path validation is performed before URL decoding. [bash] Vulnerable code in nltk/data.py The regex check operates on the raw, encoded string. if UNSAFE_NO_PROTOCOL_RE.search(resource_name): raise ValueError("...") Later, url2pathname() decodes the string. p = os.path.join(path, url2pathname(resource_name)) [/bash] This flaw allows attackers to bypass the security regex. The following Python script demonstrates the75highView or DownloadUNDERCODE2026-06-16
Hono<4.12.4Cookie InjectionmediumView or DownloadUNDERCODE2026-03-06
D-Link DIR-513v1.10Stack buffer overflowcriticalView or DownloadUNDERCODE2026-03-06
D-Link DIR-5131.10Path TraversalcriticalView or DownloadUNDERCODE2026-03-06
D-Link DIR-513critical98View or DownloadUNDERCODE2026-03-06
FreePBX GUI86highView or DownloadUNDERCODE2026-05-03
D-Link DIR-513criticalView or DownloadUNDERCODE2026-03-06
D-Link DIR-5131.10 onlyStack Buffer Overflowcritical98View or DownloadUNDERCODE2026-03-06
CoreDNS77highView or DownloadUNDERCODE2026-03-06
Traefikmoderatecvss44View or DownloadUNDERCODE2026-03-05
Traefik2.11.9-2.11.37, 3.1.3-3.6.8Case-sensitivity bypasshighcvss31avnaclprnuinsucnihanView or DownloadUNDERCODE2026-03-05
TraefikhighView or DownloadUNDERCODE2026-03-05
Gogs<0.14.2Option injectionmediumView or DownloadUNDERCODE2026-03-05
Gogs< 0.14.2Stored XSSmediumView or DownloadUNDERCODE2026-03-05
GogshighView or DownloadUNDERCODE2026-03-05
OpenClaw (npm)criticalView or DownloadUNDERCODE2026-03-03
Geth<1.16.9ECIES Key ExtractionhighView or DownloadUNDERCODE2026-02-19
go-ethereumPrior to 1.14.13Denial of ServicemoderateView or DownloadUNDERCODE2026-02-19
LangChain Redis Checkpointer< 1.0.2Query Injection BypasscriticalView or DownloadUNDERCODE2026-02-19
filippo.io/edwards25519Prior to v1.2.0MultiScalarMult initialization failurelowView or DownloadUNDERCODE2026-02-19
TensorFlow/Keras2.20.0/3.11.3Information DisclosuremediumView or DownloadUNDERCODE2025-10-19
LibreNMSbefore 24.4.0time-based blind SQLihigh71-88View or DownloadUNDERCODE2024-04-22
Windows<5.27.14Command Injectionhigh81View or DownloadUNDERCODE2025-12-16
PHP ApplicationNot specifiedSQL Injection IPv6criticalView or DownloadUNDERCODE2025-02-18
OpenClaw<=2026.2.14Token LeakmoderateView or DownloadUNDERCODE2026-02-18

🦑 WANT MORE ?

Loading…
Scroll to Top