Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242520
AlmaLinux
5975
Alpaquita
16176
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9501
Chainguard
1048512
CleanStart
5432
CRAN
14
crates.io
2768
Debian
68992
Echo
7853
GHC
3
GIT
109121
GitHub Actions
55
Go
9332
Hackage
33
Hex
365
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148659
npm
229266
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4344
Root
19650
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9974
Ubuntu
66090
VSCode
21
Wolfi
293807
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-16052
npm/open-item-validator
Malicious code in open-item-validator (npm)
08 Sep
No fix available
MAL-2026-12963
npm/bnpl-blocks-independent-bnpl-open-api
Malicious code in bnpl-blocks-independent-bnpl-open-api (npm)
05 Aug
No fix available
MAL-2026-12366
npm/dolyame-boxy-independent-bnpl-open-api
Malicious code in dolyame-boxy-independent-bnpl-open-api (npm)
05 Aug
No fix available
MAL-2026-11183
npm/def-open-client
Malicious code in def-open-client (npm)
29 Jul
No fix available
MAL-2026-11188
npm/open-worker-cli
Malicious code in open-worker-cli (npm)
29 Jul
No fix available
MAL-2026-5392
npm/@open-banking/cabinet-providers
Malicious code in @open-banking/cabinet-providers (npm)
09 Jun
No fix available
MAL-2026-4340
npm/wm-plugin-open-teach-me-after-deployable-played
Malicious code in wm-plugin-open-teach-me-after-deployable-played (npm)
25 May
No fix available
GHSA-4fg7-f244-3j49
npm/@haxtheweb/open-apis
HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis
19 May
Fix available
Severity - 8.7 (High)
GHSA-cqp4-qqvg-3787
npm/open-webui
Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order
14 May
Fix available
Severity - 8.1 (High)
GHSA-p4fx-23fq-jfg6
npm/open-webui
Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution
14 May
Fix available
Severity - 7.2 (High)
GHSA-r29h-37fj-x2w6
npm/open-webui
Open WebUI Has Stored Cross-Site Scripting in SVG Renderer
14 May
Fix available
Severity - 5.1 (Medium)
GHSA-gf5m-wcrh-7928
PyPI/open-webui
npm/open-webui
open-webui Vulnerable to Stored XSS via Model Description
08 May
Fix available
Severity - 7.3 (High)
MAL-2026-3399
npm/money-badger-open-rpc-test-bugbount
Malicious code in money-badger-open-rpc-test-bugbount (npm)
08 May
No fix available
MAL-2026-3353
npm/money-badger-open-rpc
Malicious code in money-badger-open-rpc (npm)
06 May
No fix available
GHSA-v228-72c7-fx8j
npm/open-websearch
open-websearch has SSRF in `fetchWebContent` MCP tool: bracketed IPv6 literals and non-resolving hostname check bypass `isPrivateOrLocalHostname`
05 May
Fix available
Severity - 8.2 (High)
MAL-2026-886
npm/open-answer-engine-frontend
Malicious code in open-answer-engine-frontend (npm)
13 Feb
No fix available
Load more...
npm - OSV