Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2062766
AlmaLinux
5637
Alpaquita
13590
Alpine
4444
Android
2912
Azure Linux
12016
BellSoft Hardened Containers
632
Bitnami
8936
Chainguard
925559
CleanStart
1987
CRAN
14
crates.io
2654
Debian
63692
Docker Hardened Images
1
Echo
4360
GHC
3
GIT
98584
GitHub Actions
55
Go
8731
Hackage
32
Hex
236
Julia
1673
Linux
27085
Mageia
6105
Maven
6858
MinimOS
127899
npm
226453
NuGet
1833
opam
26
openEuler
8163
openSUSE
13928
OSS-Fuzz
3990
Packagist
6831
Pub
11
PyPI
24470
Red Hat
22233
Rocky Linux
3970
Root
18993
RubyGems
4584
SUSE
22354
SwiftURL
58
TuxCare
8588
Ubuntu
61118
VSCode
20
Wolfi
311448
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-hq84-x37p-j6q5
Packagist/winter/wn-backend-module
Winter: Reflected XSS through the search query parameter in the backend Table widget
23 hours ago
Fix available
Severity - 4.5 (Medium)
GHSA-p2ch-c2c3-4xm5
Packagist/winter/wn-backend-module
Winter: CSRF through AJAX handler names reachable as backend page actions
23 hours ago
Fix available
Severity - 6.1 (Medium)
GHSA-5cwr-5jxg-pcf6
Packagist/winter/wn-backend-module
Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles
23 hours ago
Fix available
Severity - 4.5 (Medium)
GHSA-fm29-4mq3-phg6
Packagist/winter/wn-backend-module
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
23 hours ago
Fix available
Severity - 5.3 (Medium)
GHSA-mpmw-f6h6-3g26
Packagist/winter/wn-backend-module
Winter: My Account preview exposes another backend user's profile by record ID
23 hours ago
Fix available
Severity - 4.3 (Medium)
GHSA-7mpf-4465-7fc2
Packagist/winter/wn-backend-module
Winter: Stored XSS through Backend List widget image columns
23 hours ago
Fix available
Severity - 2.0 (Low)
GHSA-8cfw-pcwh-v63w
Packagist/winter/wn-system-module
Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)
23 hours ago
Fix available
Severity - 8.4 (High)
GHSA-2223-f22x-24cq
Packagist/winter/wn-system-module
Winter: Local File Inclusion through =include directives in JavaScript asset compilation
23 hours ago
Fix available
Severity - 4.9 (Medium)
GHSA-58fp-mcx6-7qf9
Packagist/winter/wn-backend-module
Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets
23 hours ago
Fix available
Severity - 4.9 (Medium)
GHSA-42vx-43vc-x6pr
Packagist/backpack/crud
Laravel Backpack CRUD: HasMany/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelation
23 hours ago
Fix available
Severity - 6.5 (Medium)
GHSA-3277-h8g9-qj5f
Packagist/winter/wn-backend-module
Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata
23 hours ago
Fix available
Severity - 5.4 (Medium)
GHSA-mrc5-3mm3-45c5
Packagist/backpack/crud
Laravel Backpack CRUD: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)
23 hours ago
Fix available
Severity - 8.1 (High)
GHSA-mmg4-322v-6jvc
Packagist/backpack/crud
Laravel Backpack CRUD: Stored XSS in the color column — the `@if($column['escaped'])` branches are inverted
23 hours ago
Fix available
Severity - 5.4 (Medium)
GHSA-vgmv-8xjc-6rch
Packagist/backpack/crud
Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)
23 hours ago
Fix available
Severity - 7.6 (High)
GHSA-8hw4-7qjr-3wxg
Packagist/backpack/crud
Laravel Backpack CRUD: SingleBase64Image accepts any base64 payload behind a `data:image` prefix — SVG-with-script lands on the public disk
23 hours ago
Fix available
Severity - 4.4 (Medium)
GHSA-8xjm-wqrp-2f25
Packagist/backpack/crud
Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisk
23 hours ago
Fix available
Severity - 8.1 (High)
Load more...
Packagist - OSV