Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
601617
AlmaLinux
4228
Alpaquita
7767
Alpine
3921
Android
3136
BellSoft Hardened Containers
285
Bitnami
6283
Chainguard
33008
CRAN
12
crates.io
1906
Debian
51517
Echo
2452
GHC
3
GIT
75344
GitHub Actions
37
Go
5195
Hackage
26
Hex
45
Julia
332
Linux
22782
Mageia
5769
Maven
6088
MinimOS
8839
npm
213697
NuGet
1505
openEuler
5599
openSUSE
10308
OSS-Fuzz
3734
Packagist
5530
Pub
10
PyPI
17443
Red Hat
17789
Rocky Linux
2514
RubyGems
1835
SUSE
17048
SwiftURL
42
Ubuntu
49137
VSCode
15
Wolfi
16436
ID
Packages
Summary
Published
arrow_upward
Attributes
GO-2025-4254
Go/github.com/mattermost/mattermost-plugin-calls
Mattermost has CSRF vulnerability via Calls Widget page in github.com/mattermost/mattermost-plugin-calls
yesterday
Fix available
GO-2025-4255
Go/github.com/mattermost/mattermost-plugin-calls
Mattermost fails to check Websocket request for proper UTF-8 format potentially crashing Calls plug-in in github.com/mattermost/mattermost-plugin-calls
yesterday
Fix available
GO-2025-4256
Go/github.com/mattermost/mattermost
Go/github.com/mattermost/mattermost-server
Go/github.com/mattermost/mattermost-server/v5
Go/github.com/mattermost/mattermost-server/v6
Go/github.com/mattermost/mattermost/server/v8
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost
yesterday
Fix available
GO-2025-4257
Go/github.com/kedacore/keda
Go/github.com/kedacore/keda/v2
KEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account Credential in github.com/kedacore/keda
yesterday
Fix available
GO-2025-4258
Go/code.gitea.io/gitea
Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
yesterday
Fix available
GO-2025-4261
Go/code.gitea.io/gitea
Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
yesterday
No fix available
GO-2025-4262
Go/code.gitea.io/gitea
Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
yesterday
Fix available
GO-2025-4263
Go/code.gitea.io/gitea
Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
yesterday
Fix available
GO-2025-4264
Go/code.gitea.io/gitea
Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
yesterday
Fix available
GO-2025-4265
Go/code.gitea.io/gitea
Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
yesterday
Fix available
GO-2025-4266
Go/code.gitea.io/gitea
Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
yesterday
Fix available
GO-2025-4267
Go/code.gitea.io/gitea
Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
yesterday
Fix available
GO-2025-4268
Go/code.gitea.io/gitea
Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
yesterday
Fix available
GO-2025-4249
Go/github.com/golang/vscode-go
Unexpected untrusted code execution in github.com/golang/vscode-go
yesterday
Fix available
GHSA-43h9-hc38-qph5
Go/github.com/actiontech/sqle
SQLE's JWT Secret Handler can be manipulated to use hard-coded cryptographic key
3 days ago
No fix available
Severity - 2.9 (Low)
GHSA-7xq4-mwcp-q8fx
Go/code.gitea.io/gitea
Gitea: anonymous user can visit private user's project
5 days ago
Fix available
Severity - 5.8 (Medium)
Load more...
Go - OSV