Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Cross-site Scripting (XSS)
CVE-2025-54476
Affects
joomla/filter
| Versions
<2.0.6
>=3.0.0, <3.0.5
>=4.0.0, <4.0.1
M
Cross-site Scripting (XSS)
CVE-2024-23173
Affects
mediawiki/cargo
| Versions
<3.4.4
M
Cross-site Scripting (XSS)
Affects
shopware/storefront
| Versions
>=6.6.10.0, <6.7.2.1
M
Cross-site Scripting (XSS)
CVE-2025-59839
Affects
starcitizenwiki/embedvideo
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2025-10909
Affects
novosga/novosga
| Versions
<2.2.13
M
Cross-site Scripting (XSS)
CVE-2025-57407
Affects
s-cart/core
| Versions
>=4.0.0-beta
M
Cross-site Scripting (XSS)
CVE-2025-57407
Affects
gp247/core
| Versions
<1.1.24
H
Arbitrary File Upload
CVE-2025-10009
Affects
hillelcoren/invoice-ninja
| Versions
<5.11.73
H
Deserialization of Untrusted Data
CVE-2025-59713
Affects
snipe/snipe-it
| Versions
<8.1.18
M
Cross-site Scripting (XSS)
CVE-2025-59712
Affects
snipe/snipe-it
| Versions
<8.1.18
C
Improper Input Validation
CVE-2025-54236
Affects
magento/community-edition
| Versions
<2.4.7-p8
C
Improper Input Validation
CVE-2025-54236
Affects
magento/project-community-edition
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2025-9103
Affects
zencart/zencart
| Versions
>=0.0.0
M
SQL Injection
CVE-2025-59397
Affects
open-web-analytics/open-web-analytics
| Versions
<1.8.1
L
Cross-site Scripting (XSS)
CVE-2025-10316
Affects
lavitto/typo3-form-to-database
| Versions
<2.2.5
>=3.0.0, <3.2.2
>=4.0.0, <4.2.3
>=5.0.0, <5.0.2
M
Cross-site Scripting (XSS)
CVE-2025-52277
Affects
yeswiki/yeswiki
| Versions
>=0.0.0
M
Missing Authorization
CVE-2025-59019
Affects
typo3/cms-recordlist
| Versions
>=11.3.0
M
Missing Authorization
CVE-2025-59019
Affects
typo3/cms-backend
| Versions
>=12.0.0, <12.4.37
>=13.0.0, <13.4.18
M
Uncaught Exception
CVE-2025-59014
Affects
typo3/cms-backend
| Versions
>=11.3.0, <12.4.37
>=13.0.0, <13.4.18
H
Missing Authorization
CVE-2025-59018
Affects
typo3/cms-workspaces
| Versions
<12.4.37
>=13.0.0, <13.4.18
M
Missing Authorization
CVE-2025-59017
Affects
typo3/cms-workspaces
| Versions
<12.4.37
>=13.0.0, <13.4.18
M
Missing Authorization
CVE-2025-59017
Affects
typo3/cms-recycler
| Versions
<12.4.37
>=13.0.0, <13.4.18
M
Missing Authorization
CVE-2025-59017
Affects
typo3/cms-dashboard
| Versions
<12.4.37
>=13.0.0, <13.4.18
M
Missing Authorization
CVE-2025-59017
Affects
typo3/cms-beuser
| Versions
<12.4.37
>=13.0.0, <13.4.18
M
Missing Authorization
CVE-2025-59017
Affects
typo3/cms-backend
| Versions
<12.4.37
>=13.0.0, <13.4.18
M
Information Exposure
CVE-2025-59016
Affects
typo3/cms-core
| Versions
<12.4.37
>=13.0.0, <13.4.18
M
Insufficient Entropy
CVE-2025-59015
Affects
typo3/cms-core
| Versions
>=12.1.0, <12.4.37
>=13.0.0, <13.4.18
M
Open Redirect
CVE-2025-59013
Affects
typo3/cms-core
| Versions
<12.4.37
>=13.0.0, <13.4.18
M
Authorization Bypass Through User-Controlled SQL Primary Key
CVE-2025-56556
Affects
intelliants/subrion
| Versions
>=0.0.0
M
Improper Input Validation
CVE-2025-58759
Affects
datahihi1/tiny-env
| Versions
>=1.0.9, <1.0.11