Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2238751
AlmaLinux
5956
Alpaquita
15755
Alpine
4608
Android
2912
Azure Linux
17638
BellSoft Hardened Containers
746
Bitnami
9308
Chainguard
1025208
CleanStart
3846
CRAN
14
crates.io
2734
Debian
68391
Docker Hardened Images
1
Echo
3987
GHC
3
GIT
106208
GitHub Actions
55
Go
9245
Hackage
32
Hex
364
Julia
1713
Linux
29267
Mageia
6231
Maven
7044
MinimOS
144474
npm
228783
NuGet
1869
opam
29
openEuler
8800
openSUSE
14459
OSS-Fuzz
4003
Packagist
7101
Pub
11
PyPI
25171
Red Hat
23355
Rocky Linux
4300
Root
19562
RubyGems
5326
SUSE
23213
SwiftURL
60
TuxCare
9711
Ubuntu
65395
VSCode
21
Wolfi
331842
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-g7vj-c29h-3h5m
Packagist/fof/oauth
FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider
3 days ago
Fix available
Severity - 9.8 (Critical)
GHSA-v65j-hff3-753c
Packagist/starcitizenwiki/embedvideo
Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled
3 days ago
Fix available
Severity - 7.5 (High)
GHSA-qxg3-46rw-79j8
Packagist/code16/sharp
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute
3 days ago
Fix available
Severity - 7.3 (High)
GHSA-vj3q-vp3g-j9c8
Packagist/code16/sharp
code16/sharp has a stored XSS via data-html-content Sanitizer Bypass
3 days ago
Fix available
Severity - 8.7 (High)
GHSA-87mg-5grr-rhwh
Packagist/contao/contao
Packagist/contao/core-bundle
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module
4 days ago
Fix available
Severity - 3.1 (Low)
GHSA-36h5-qg4p-q2qf
Packagist/zbateson/mail-mime-parser
zbateson/mail-mime-parser has CRLF header injection via attachment filename
4 days ago
Fix available
Severity - 7.2 (High)
GHSA-f6v3-2qmr-vfjx
Packagist/zbateson/mail-mime-parser
zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME
4 days ago
Fix available
Severity - 7.5 (High)
GHSA-rw77-vq4g-x3hp
Packagist/phpmyfaq/phpmyfaq
Packagist/thorsten/phpmyfaq
phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion
4 days ago
Fix available
Severity - 8.5 (High)
GHSA-8gpw-xvpf-hvx5
Packagist/phpmyfaq/phpmyfaq
Packagist/thorsten/phpmyfaq
phpMyFAQ's two-factor authentication login bypasses the password factor
4 days ago
Fix available
Severity - 8.1 (High)
GHSA-pgwp-vc7q-cvj3
Packagist/phpmyfaq/phpmyfaq
Packagist/thorsten/phpmyfaq
phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission
4 days ago
Fix available
Severity - 8.2 (High)
GHSA-396x-xmvh-p563
Packagist/snipe/snipe-it
Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API
4 days ago
Fix available
Severity - 8.7 (High)
GHSA-p9h3-gvpq-5539
Packagist/snipe/snipe-it
Snipe-IT: Stored XSS via Custom Field name in asset-list column headers
4 days ago
Fix available
Severity - 8.1 (High)
GHSA-hxcx-9h4f-42xx
Packagist/snipe/snipe-it
Snipe-IT: 2FA bypass via the API token flow
4 days ago
Fix available
Severity - 8.6 (High)
GHSA-4f5f-j737-pm58
Packagist/redaxo/source
REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration
4 days ago
Fix available
Severity - 4.3 (Medium)
GHSA-9rg8-2wvr-fgjh
Packagist/verbb/formie
Formie: Missing authorization on sent notification resend modal exposes submission PII
5 days ago
Fix available
Severity - 7.7 (High)
GHSA-584p-f93j-wpgc
Packagist/verbb/formie
Formie: Unauthenticated users can overwrite incomplete submissions via submit action
5 days ago
Fix available
Severity - 8.2 (High)
Load more...
Packagist - OSV