Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
592743
AlmaLinux
4463
Alpaquita
8402
Alpine
3971
Android
3265
BellSoft Hardened Containers
361
Bitnami
6585
Chainguard
4966
CleanStart
271
CRAN
13
crates.io
2039
Debian
52627
Echo
2970
GHC
3
GIT
82492
GitHub Actions
40
Go
5726
Hackage
27
Hex
46
Julia
332
Linux
21774
Mageia
5816
Maven
6179
MinimOS
14829
npm
215267
NuGet
1557
opam
11
openEuler
5945
openSUSE
10382
OSS-Fuzz
3790
Packagist
5730
Pub
10
PyPI
17970
Red Hat
18599
Rocky Linux
2708
Root
10554
RubyGems
1861
SUSE
17204
SwiftURL
47
Ubuntu
50807
VSCode
15
Wolfi
3089
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-hx9w-f2w9-9g96
Hex/hex_core
hex_core has Unsafe Deserialization of Erlang Terms
4 days ago
Fix available
Severity - 2.0 (Low)
EEF-CVE-2026-21619
Hex/hex_core
github.com/erlang/rebar3
github.com/hexpm/hex
github.com/hexpm/hex_core
Unsafe Deserialization of Erlang Terms in hex_core
5 days ago
Fix available
Severity - 2.0 (Low)
GHSA-6gvq-jcmp-8959
Go/github.com/altcha-org/altcha-lib-go
Hex/altcha
Maven/org.altcha:altcha
Packagist/altcha-org/altcha
PyPI/altcha
... 2 more
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
16 Dec 2025
Fix available
Severity - 6.5 (Medium)
GHSA-pcxq-fjp3-r752
Hex/ash
Ash has authorization bypass when bypass policy condition evaluates to true
17 Oct 2025
Fix available
Severity - 8.6 (High)
EEF-CVE-2025-48044
Hex/ash
github.com/ash-project/ash
Authorization bypass when bypass policy condition evaluates to true
17 Oct 2025
Fix available
Severity - 8.6 (High)
GHSA-7r7f-9xpj-jmr7
Hex/ash
Ash Framework: Filter authorization misapplies impossible bypass/runtime policies
13 Oct 2025
Fix available
Severity - 8.6 (High)
EEF-CVE-2025-48043
Hex/ash
github.com/ash-project/ash
Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization
10 Oct 2025
Fix available
Severity - 8.6 (High)
GHSA-jj4j-x5ww-cwh9
Hex/ash
Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden
15 Sep 2025
Fix available
Severity - 7.1 (High)
EEF-CVE-2025-48042
Hex/ash
github.com/ash-project/ash
Before action hooks may execute in certain scenarios despite a request being forbidden
07 Sep 2025
Fix available
Severity - 7.1 (High)
EEF-CVE-2025-4754
Hex/ash_authentication_phoenix
github.com/team-alembic/ash_authentication_phoenix
Missing Session Revocation on Logout in ash_authentication_phoenix
17 Jun 2025
Fix available
Severity - 2.3 (Low)
GHSA-f7gq-h8jv-h3cq
Hex/ash_authentication_phoenix
ash_authentication_phoenix has Insufficient Session Expiration
17 Jun 2025
Fix available
Severity - 2.3 (Low)
GHSA-9fm9-hp7p-53mf
Hex/hackney
Hackney fails to properly release HTTP connections to the pool
28 May 2025
Fix available
Severity - 2.3 (Low)
GHSA-3988-q8q7-p787
Hex/ash_authentication
ash_authentication has email link auto-click account confirmation vulnerability
14 Apr 2025
Fix available
Severity - 5.3 (Medium)
GHSA-qrm9-f75w-hg4c
Hex/ash_authentication
Ash Authentication has flawed token revocation checking logic in actions generated by
`
mix ash_authentication.install
`
11 Feb 2025
Fix available
Severity - 6.3 (Medium)
GHSA-vq52-99r9-h5pw
Hex/hackney
Server-side Request Forgery (SSRF) in hackney
11 Feb 2025
Fix available
Severity - 2.9 (Low)
GHSA-pj33-75x5-32j4
Hex/rabbit_common
RabbitMQ HTTP API's queue deletion endpoint does not verify that the user has a required permission
06 Nov 2024
Fix available
Severity - 7.1 (High)
Load more...
(2 pages left)
Hex - OSV