Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
436802
AlmaLinux
4043
Alpaquita
6967
Alpine
3865
Android
2912
BellSoft Hardened Containers
241
Bitnami
6128
Chainguard
27848
CRAN
11
crates.io
1858
Debian
49989
Echo
1968
GHC
3
GIT
72710
GitHub Actions
37
Go
4893
Hackage
24
Hex
44
Julia
197
Linux
21625
Mageia
5704
Maven
6013
MinimOS
6491
npm
70441
NuGet
1481
openEuler
5379
openSUSE
10243
OSS-Fuzz
3671
Packagist
4925
Pub
10
PyPI
16745
Red Hat
17310
Rocky Linux
2334
RubyGems
1794
SUSE
16921
SwiftURL
42
Ubuntu
47722
Wolfi
14213
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-qv78-c8hc-438r
Packagist/openmage/magento-lts
OpenMage vulnerable to XSS in Admin Notifications
4 days ago
Fix available
Severity - 4.6 (Medium)
GHSA-g582-8vwr-68h2
Packagist/mantisbt/mantisbt
MantisBT unauthorized disclosure of private project column configuration
4 days ago
Fix available
Severity - 5.3 (Medium)
GHSA-q747-c74m-69pr
Packagist/mantisbt/mantisbt
MantisBT lacks verification when changing a user's email address
4 days ago
Fix available
Severity - 5.4 (Medium)
GHSA-r3jf-hm7q-qfw5
Packagist/mantisbt/mantisbt
MantisBT Vulnerable to Denial-of-Service (DoS) via Excessive Note Length
4 days ago
Fix available
Severity - 6.5 (Medium)
GHSA-4v8w-gg5j-ph37
Packagist/mantisbt/mantisbt
MantisBT vulnerable to authentication bypass for some passwords due to PHP type juggling
4 days ago
Fix available
Severity - 8.8 (High)
GHSA-g59r-24g3-h7cm
Packagist/statamic/cms
Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validation
30 Oct
Fix available
Severity - 8.0 (High)
GHSA-h72q-cq3w-h3wc
Packagist/drupal/civictheme
Drupal CivicTheme Design System allows Cross-Site Scripting (XSS)
30 Oct
Fix available
Severity - 6.1 (Medium)
GHSA-jqmq-fpwv-p925
Packagist/drupal/simple_oauth
Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass
30 Oct
Fix available
Severity - 7.5 (High)
GHSA-x957-32v9-m7vg
Packagist/drupal/acquia_dam
Drupal Acquia DAM allows Forceful Browsing
30 Oct
Fix available
Severity - 7.5 (High)
GHSA-27fv-rpgj-4c6m
Packagist/drupal/currency
Drupal Currency allows Cross Site Request Forgery
30 Oct
Fix available
Severity - 6.5 (Medium)
GHSA-27mc-9399-r9mx
Packagist/drupal/access_code
Drupal Access code allows Brute Force Attempts
30 Oct
Fix available
Severity - 6.3 (Medium)
GHSA-fg8x-q69g-4qp3
Packagist/drupal/reverse_proxy_header
Drupal Reverse Proxy Header allows Manipulating User-Controlled Variables
30 Oct
Fix available
Severity - 5.3 (Medium)
GHSA-jxp8-4jw5-5xjc
Packagist/drupal/umami_analytics
Drupal Umami Analytics allows Cross-Site Scripting (XSS)
30 Oct
Fix available
Severity - 3.8 (Low)
GHSA-m3f2-xjgc-2wp2
Packagist/drupal/json_field
Drupal JSON Field is vulnerable to XSS
30 Oct
Fix available
Severity - 6.1 (Medium)
GHSA-pr6m-qwrr-mrw9
Packagist/drupal/plausible_tracking
Drupal Plausible tracking is vulnerable to XSS
30 Oct
Fix available
Severity - 6.1 (Medium)
GHSA-qxr9-f877-9842
Packagist/drupal/civictheme
Drupal CivicTheme Design System allows Forceful Browsing
30 Oct
Fix available
Severity - 7.5 (High)
Load more...
Packagist - OSV