Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • C
Arbitrary Code Injection
tecnickcom/tc-lib-pdf-font<2.6.4Composer27 Dec 2024
  • C
Arbitrary Code Injection
tecnickcom/tcpdf<6.8.0Composer27 Dec 2024
  • C
Improper Input Validation
tecnickcom/tcpdf<6.8.0Composer27 Dec 2024
  • C
Deserialization of Untrusted Data
tecnickcom/tcpdf<6.8.0Composer27 Dec 2024
  • C
Cross-site Scripting (XSS)
tecnickcom/tcpdf<6.8.0Composer27 Dec 2024
  • M
Cross-site Scripting (XSS)
tltneon/lgsl>=0.0.0Composer27 Dec 2024
  • M
Cross-site Request Forgery (CSRF)
wordpress-premium/advanced-custom-fields-pro<3.6.10>=5.7.13, <6.3.4Composer25 Dec 2024
  • M
Cross-site Scripting (XSS)
shuchkin/simplexlsx>=1.0.12, <1.1.13Composer24 Dec 2024
  • H
Improper Authentication
joelbutcher/socialstream<6.2.0Composer22 Dec 2024
  • C
Command Injection
craftcms/cms>=4.0.0-RC1, <4.13.2>=5.0.0-RC1, <5.5.2Composer19 Dec 2024
  • H
Improper Neutralization of Special Elements Used in a Template Engine
opencart/opencart>=0.0.0Composer19 Dec 2024
  • H
Improper Input Validation
spatie/browsershot<5.0.3Composer19 Dec 2024
  • H
Directory Traversal
spatie/browsershot<5.0.2Composer16 Dec 2024
  • C
Remote Code Execution (RCE)
unisharp/laravel-filemanager<2.9.1Composer16 Dec 2024
  • H
Arbitrary Code Injection
laravel/pulse<1.3.1Composer15 Dec 2024
  • M
User Interface (UI) Misrepresentation of Critical Information
thorsten/phpmyfaq<3.2.10Composer13 Dec 2024
  • M
Cross-site Scripting (XSS)
shuchkin/simplexlsx>=1.0.12, <1.1.12Composer13 Dec 2024
  • M
Cross-site Scripting (XSS)
mojo42/jirafeau>=4.5.0, <4.6.1Composer12 Dec 2024
  • H
Improper Input Validation
spatie/browsershot<5.0.1Composer12 Dec 2024
  • M
Cross-site Scripting (XSS)
oro/platform>=0.0.0Composer11 Dec 2024
  • C
Credential Exposure
thorsten/phpmyfaq<4.0.0Composer11 Dec 2024
  • H
Inefficient Algorithmic Complexity
league/commonmark<2.6.0Composer10 Dec 2024
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes
drupal/core>=8.8.0, <10.2.11>=10.3.0, <10.3.9Composer10 Dec 2024
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes
drupal/core>=8.8.0, <10.2.11>=10.3.0, <10.3.9>=11.0.0, <11.0.8Composer10 Dec 2024
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes
drupal/core>=8.8.0, <10.2.11>=10.3.0, <10.3.9>=11.0.0, <11.0.8Composer10 Dec 2024
  • H
Improper Handling of Case Sensitivity
drupal/core>=8.8.0, <10.2.11>=10.3.0, <10.3.9>=11.0.0, <11.0.8Composer10 Dec 2024
  • M
Cross-site Scripting (XSS)
drupal/core>=8.8.0, <10.2.11>=10.3.0, <10.3.9>=11.0.0, <11.0.8Composer10 Dec 2024
  • M
Incomplete List of Disallowed Inputs
winter/wn-system-module<1.2.7Composer10 Dec 2024
  • M
Incomplete List of Disallowed Inputs
winter/wn-cms-module<1.2.7Composer10 Dec 2024
  • M
Cross-site Scripting (XSS)
drupal-pattern-lab/add-attributes-twig-extension>=0.0.0Composer9 Dec 2024