Vulnerabilities
18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-8888 | Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new Re Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2025-11563 | URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly as URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool. NVD description · AI analysis pending | 4.6 | <1% |
| — | ||
| CVE-2021-30134 | php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimens php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php. NVD description · AI analysis pending | 6.1 | 1% | PoC |
| — | |
| CVE-2020-28425 | This affects all versions of package curljs. This affects all versions of package curljs. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2020-36474 | SafeCurl before 0.9.2 has a DNS rebinding vulnerability. SafeCurl before 0.9.2 has a DNS rebinding vulnerability. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2021-23416 | This affects all versions of package curly-bracket-parser. This affects all versions of package curly-bracket-parser. When used as a template library, it does not properly sanitize the user input. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2020-7646 | curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input. curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2019-10789 | All versions of curling.js are vulnerable to Command Injection via the run function. All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization. NVD description · AI analysis pending | 9.8 | 5% | PoC ×2 |
| — | |
| CVE-2018-6651 | In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting an arbitrar In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting an arbitrary substring match) for WebSocket API requests allows remote attackers to bypass intended access restrictions. In Parsec, this means full control over the victim's computer. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2017-0907 | The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerabil The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.EscapeUriString" that could result in compromise of API keys or other critical resources. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2017-0906 | The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the " The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other critical resources. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2017-0905 | The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Server-Side R The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource#find" method that could result in compromise of API keys or other critical resources. NVD description · AI analysis pending | 9.8 | 3% |
| — |