Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • H
Improper Input Validation
spatie/browsershot<5.0.3Composer19 Dec 2024
  • H
Directory Traversal
spatie/browsershot<5.0.2Composer16 Dec 2024
  • C
Remote Code Execution (RCE)
unisharp/laravel-filemanager<2.9.1Composer16 Dec 2024
  • H
Arbitrary Code Injection
laravel/pulse<1.3.1Composer15 Dec 2024
  • M
User Interface (UI) Misrepresentation of Critical Information
thorsten/phpmyfaq<3.2.10Composer13 Dec 2024
  • M
Cross-site Scripting (XSS)
shuchkin/simplexlsx>=1.0.12, <1.1.12Composer13 Dec 2024
  • M
Cross-site Scripting (XSS)
mojo42/jirafeau>=4.5.0, <4.6.1Composer12 Dec 2024
  • H
Improper Input Validation
spatie/browsershot<5.0.1Composer12 Dec 2024
  • M
Cross-site Scripting (XSS)
oro/platform>=0.0.0Composer11 Dec 2024
  • C
Credential Exposure
thorsten/phpmyfaq<4.0.0Composer11 Dec 2024
  • M
SQL Injection
nette/database>=0.0.0Composer11 Dec 2024
  • H
Inefficient Algorithmic Complexity
league/commonmark<2.6.0Composer10 Dec 2024
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes
drupal/core>=8.8.0, <10.2.11>=10.3.0, <10.3.9Composer10 Dec 2024
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes
drupal/core>=8.8.0, <10.2.11>=10.3.0, <10.3.9>=11.0.0, <11.0.8Composer10 Dec 2024
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes
drupal/core>=8.8.0, <10.2.11>=10.3.0, <10.3.9>=11.0.0, <11.0.8Composer10 Dec 2024
  • H
Improper Handling of Case Sensitivity
drupal/core>=8.8.0, <10.2.11>=10.3.0, <10.3.9>=11.0.0, <11.0.8Composer10 Dec 2024
  • M
Cross-site Scripting (XSS)
drupal/core>=8.8.0, <10.2.11>=10.3.0, <10.3.9>=11.0.0, <11.0.8Composer10 Dec 2024
  • M
Incomplete List of Disallowed Inputs
winter/wn-system-module<1.2.7Composer10 Dec 2024
  • M
Incomplete List of Disallowed Inputs
winter/wn-cms-module<1.2.7Composer10 Dec 2024
  • M
Cross-site Scripting (XSS)
drupal-pattern-lab/add-attributes-twig-extension>=0.0.0Composer9 Dec 2024
  • L
Cross-site Scripting (XSS)
drupal-pattern-lab/bem-twig-extension>=0.0.0Composer9 Dec 2024
  • M
Cross-site Scripting (XSS)
drupal-pattern-lab/unified-twig-extensions>=0.0.0Composer9 Dec 2024
  • L
Cross-site Scripting (XSS)
pattern-lab/drupal-twig-components>=0.0.0Composer9 Dec 2024
  • M
Server-side Request Forgery (SSRF)
j0k3r/httplug-ssrf-plugin>=0.0.0Composer9 Dec 2024
  • M
Cross-site Scripting (XSS)
aptoma/twig-markdown>=0.0.0Composer9 Dec 2024
  • H
Infinite loop
drupal/core>=10.1.0, <10.1.8>=10.2.0, <10.2.2Composer6 Dec 2024
  • H
Detection of Error Condition Without Action
drupal/core>=10.0.0, <10.2.10Composer6 Dec 2024
  • M
Cross-site Scripting (XSS)
librenms/librenms>=24.9.0, <24.10.1Composer6 Dec 2024
  • M
Cross-site Scripting (XSS)
samwilson/unlinked-wikibase>=1.0.0, <2.0.0Composer5 Dec 2024
  • H
XML External Entity (XXE) Injection
simplesamlphp/simplesamlphp<2.0.15>=2.1.0, <2.1.7>=2.2.0, <2.2.4>=2.3.0, <2.3.4Composer3 Dec 2024