Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2200007
AlmaLinux
5928
Alpaquita
15755
Alpine
4608
Android
3677
Azure Linux
17638
BellSoft Hardened Containers
746
Bitnami
9292
Chainguard
1023639
CleanStart
3591
CRAN
14
crates.io
2734
Debian
68402
Echo
7425
GHC
3
GIT
108138
GitHub Actions
55
Go
9243
Hackage
32
Hex
364
Julia
1713
Linux
29974
Mageia
6231
Maven
7044
MinimOS
144508
npm
228783
NuGet
1869
opam
29
openEuler
8800
openSUSE
14455
OSS-Fuzz
4013
Packagist
7095
Pub
11
PyPI
25172
Red Hat
23355
Rocky Linux
4300
Root
19561
RubyGems
5326
SUSE
23214
SwiftURL
60
TuxCare
9552
Ubuntu
65376
VSCode
21
Wolfi
288261
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-g7vj-c29h-3h5m
Packagist/fof/oauth
FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider
3 days ago
Fix available
Severity - 9.8 (Critical)
CLSA-2026-1790350388
TuxCare:Packagist/zendframework/zend-session
TuxCare security update for zendframework/zend-session (1 CVE)
3 days ago
Fix available
GHSA-v65j-hff3-753c
Packagist/starcitizenwiki/embedvideo
Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled
3 days ago
Fix available
Severity - 7.5 (High)
GHSA-qxg3-46rw-79j8
Packagist/code16/sharp
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute
3 days ago
Fix available
Severity - 7.3 (High)
GHSA-vj3q-vp3g-j9c8
Packagist/code16/sharp
code16/sharp has a stored XSS via data-html-content Sanitizer Bypass
3 days ago
Fix available
Severity - 8.7 (High)
GHSA-87mg-5grr-rhwh
Packagist/contao/contao
Packagist/contao/core-bundle
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module
4 days ago
Fix available
Severity - 3.1 (Low)
GHSA-36h5-qg4p-q2qf
Packagist/zbateson/mail-mime-parser
zbateson/mail-mime-parser has CRLF header injection via attachment filename
4 days ago
Fix available
Severity - 7.2 (High)
GHSA-f6v3-2qmr-vfjx
Packagist/zbateson/mail-mime-parser
zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME
4 days ago
Fix available
Severity - 7.5 (High)
GHSA-rw77-vq4g-x3hp
Packagist/phpmyfaq/phpmyfaq
Packagist/thorsten/phpmyfaq
phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion
4 days ago
Fix available
Severity - 8.5 (High)
GHSA-8gpw-xvpf-hvx5
Packagist/phpmyfaq/phpmyfaq
Packagist/thorsten/phpmyfaq
phpMyFAQ's two-factor authentication login bypasses the password factor
4 days ago
Fix available
Severity - 8.1 (High)
GHSA-pgwp-vc7q-cvj3
Packagist/phpmyfaq/phpmyfaq
Packagist/thorsten/phpmyfaq
phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission
4 days ago
Fix available
Severity - 8.2 (High)
GHSA-396x-xmvh-p563
Packagist/snipe/snipe-it
Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API
4 days ago
Fix available
Severity - 8.7 (High)
GHSA-p9h3-gvpq-5539
Packagist/snipe/snipe-it
Snipe-IT: Stored XSS via Custom Field name in asset-list column headers
4 days ago
Fix available
Severity - 8.1 (High)
GHSA-hxcx-9h4f-42xx
Packagist/snipe/snipe-it
Snipe-IT: 2FA bypass via the API token flow
4 days ago
Fix available
Severity - 8.6 (High)
GHSA-4f5f-j737-pm58
Packagist/redaxo/source
REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration
4 days ago
Fix available
Severity - 4.3 (Medium)
CLSA-2026-1790259386
TuxCare:Packagist/mongodb/mongodb
TuxCare security update for mongodb/mongodb (1 CVE)
4 days ago
Fix available
Load more...
Vulnerability Database - OSV