
CVE-2022-45354
Download Monitor <= 4.7.60 - Sensitive Information Exposure via REST API

Download Monitor <= 4.7.60 - Sensitive Information Exposure via REST API

Fast, configurable HTML sanitization library for preventing XSS and malicious code injection from untrusted user input. Provides a policy-driven API…

OAuth and OAuth2 support library for Spring Security, enabling secure API authentication and authorization for consumer and provider implementations…

Open source identity and access management solution providing single sign-on, user federation, and centralized authentication for modern applications…

Open-source identity and access management solution providing authentication, user federation, single sign-on, and fine-grained authorization for…

Centralized configuration server for distributed systems with HTTP API, Git-backed storage, property encryption/decryption, and integration with…

Open source identity and access management platform providing single sign-on, user federation, and centralized authentication for modern applications…

Open source identity and access management solution providing single sign-on, user federation, and centralized authentication for modern applications…

Open source identity and access management solution providing single sign-on, user federation, and centralized authentication for modern applications…

Agent-based JMX access via JSON/HTTP with bulk requests, fine-grained security policies, and proxy mode for remote MBeanServer monitoring and…

Proof-of-concept for CVE-2025-492030: account takeover via session token validation bypass in SecureVPN API endpoint /api/v1/authenticate.

Open-source services framework for building and developing SOAP, RESTful, and CORBA services with support for WS-Security, JAX-WS, and JAX-RS APIs.

Apache ShenYu 管理员认证绕过

Automated data flow platform for processing and distributing data with built-in provenance tracking, secure configuration, and scalable pipeline…

Centralized configuration server for distributed systems with HTTP API, encryption/decryption of properties, and support for Git, Vault, JDBC, and…

Proof-of-concept for CVE-2025-30144: JWT issuer validation bypass in fast-jwt library allowing attackers to forge tokens with array-based iss claims.

CVE-2016-1000229

Jenkins plugin providing shared API for Docker credential management, registry authentication, daemon configuration, and image fingerprinting across…