Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2232730
AlmaLinux
5946
Alpaquita
15522
Alpine
4594
Android
2912
Azure Linux
17378
BellSoft Hardened Containers
744
Bitnami
9303
Chainguard
1022998
CleanStart
3591
CRAN
14
crates.io
2732
Debian
68308
Docker Hardened Images
1
Echo
3105
GHC
3
GIT
105756
GitHub Actions
55
Go
9205
Hackage
32
Hex
361
Julia
1713
Linux
29205
Mageia
6224
Maven
7040
MinimOS
143928
npm
228730
NuGet
1869
opam
29
openEuler
8800
openSUSE
14458
OSS-Fuzz
4003
Packagist
7101
Pub
11
PyPI
25152
Red Hat
23316
Rocky Linux
4286
Root
19535
RubyGems
5326
SUSE
23078
SwiftURL
60
TuxCare
9578
Ubuntu
65379
VSCode
21
Wolfi
331328
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-g7vj-c29h-3h5m
Packagist/fof/oauth
FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider
13 hours ago
Fix available
Severity - 9.8 (Critical)
GHSA-v65j-hff3-753c
Packagist/starcitizenwiki/embedvideo
Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled
14 hours ago
Fix available
Severity - 7.5 (High)
GHSA-qxg3-46rw-79j8
Packagist/code16/sharp
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute
14 hours ago
Fix available
Severity - 7.3 (High)
GHSA-vj3q-vp3g-j9c8
Packagist/code16/sharp
code16/sharp has a stored XSS via data-html-content Sanitizer Bypass
14 hours ago
Fix available
Severity - 8.7 (High)
GHSA-87mg-5grr-rhwh
Packagist/contao/contao
Packagist/contao/core-bundle
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module
yesterday
Fix available
Severity - 3.1 (Low)
GHSA-36h5-qg4p-q2qf
Packagist/zbateson/mail-mime-parser
zbateson/mail-mime-parser has CRLF header injection via attachment filename
yesterday
Fix available
Severity - 7.2 (High)
GHSA-f6v3-2qmr-vfjx
Packagist/zbateson/mail-mime-parser
zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME
yesterday
Fix available
Severity - 7.5 (High)
GHSA-rw77-vq4g-x3hp
Packagist/phpmyfaq/phpmyfaq
Packagist/thorsten/phpmyfaq
phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion
yesterday
Fix available
Severity - 8.5 (High)
GHSA-8gpw-xvpf-hvx5
Packagist/phpmyfaq/phpmyfaq
Packagist/thorsten/phpmyfaq
phpMyFAQ's two-factor authentication login bypasses the password factor
yesterday
Fix available
Severity - 8.1 (High)
GHSA-pgwp-vc7q-cvj3
Packagist/phpmyfaq/phpmyfaq
Packagist/thorsten/phpmyfaq
phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission
yesterday
Fix available
Severity - 8.2 (High)
GHSA-396x-xmvh-p563
Packagist/snipe/snipe-it
Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API
yesterday
Fix available
Severity - 8.7 (High)
GHSA-p9h3-gvpq-5539
Packagist/snipe/snipe-it
Snipe-IT: Stored XSS via Custom Field name in asset-list column headers
yesterday
Fix available
Severity - 8.1 (High)
GHSA-hxcx-9h4f-42xx
Packagist/snipe/snipe-it
Snipe-IT: 2FA bypass via the API token flow
yesterday
Fix available
Severity - 8.6 (High)
GHSA-4f5f-j737-pm58
Packagist/redaxo/source
REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration
yesterday
Fix available
Severity - 4.3 (Medium)
GHSA-9rg8-2wvr-fgjh
Packagist/verbb/formie
Formie: Missing authorization on sent notification resend modal exposes submission PII
2 days ago
Fix available
Severity - 7.7 (High)
GHSA-584p-f93j-wpgc
Packagist/verbb/formie
Formie: Unauthenticated users can overwrite incomplete submissions via submit action
2 days ago
Fix available
Severity - 8.2 (High)
Load more...
Packagist - OSV