Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • C
Information Exposure Through Timing Discrepancy
paragonie/ecc<2.0.1Composer12 Nov 2024
  • M
Exposed Dangerous Method or Function
orchid/platform>=8.0, <14.43.0Composer12 Nov 2024
  • M
Improper Authentication
moodle/moodle>=4.4.0, <4.4.2>=4.3.0, <4.3.6Composer11 Nov 2024
  • M
Information Exposure
moodle/moodle>=4.4.0, <4.4.2>=4.3.0, <4.3.6>=4.2.0, <4.2.9>=4.1.0, <4.1.12Composer11 Nov 2024
  • M
Cross-site Scripting (XSS)
moodle/moodle>=4.4.0, <4.4.2>=4.3.0, <4.3.6>=4.2.0, <4.2.9>=4.1.0, <4.1.12Composer11 Nov 2024
  • M
Improper Privilege Management
moodle/moodle>=4.4.0, <4.4.2>=4.3.0, <4.3.6>=4.2.0, <4.2.9>=4.1.0, <4.1.12Composer11 Nov 2024
  • M
Access Control Bypass
moodle/moodle>=4.4.0, <4.4.2Composer11 Nov 2024
  • M
Open Redirect
moodle/moodle>=4.4.0, <4.4.2>=4.3.0, <4.3.6>=4.2.0, <4.2.9>=4.1.0, <4.1.12Composer11 Nov 2024
  • M
Information Exposure
moodle/moodle>=4.4.0, <4.4.2>=4.3.0, <4.3.6>=4.2.0, <4.2.9>=4.1.0, <4.1.12Composer11 Nov 2024
  • H
Arbitrary File Upload
alexstack/laravel-cms>=0.0.0Composer10 Nov 2024
  • H
XML External Entity (XXE) Injection
phpoffice/phpexcel<1.8.1Composer8 Nov 2024
  • H
Improper Input Validation
moodle/moodle<4.1.12>=4.2.0, <4.2.9>=4.3.0, <4.3.6>=4.4.0, <4.4.2Composer8 Nov 2024
  • L
Insecure Default Initialization of Resource
filament/actions>=3.2.0, <3.2.123Composer8 Nov 2024
  • H
SQL Injection
moodle/moodle<4.1.12>=4.2.0, <4.2.9>=4.3.0, <4.3.6>=4.4.0, <4.4.2Composer7 Nov 2024
  • H
Access Control Bypass
moodle/moodle<4.1.12>=4.2.0, <4.2.9>=4.3.0, <4.3.6>=4.4.0, <4.4.2Composer7 Nov 2024
  • H
Cross-site Request Forgery (CSRF)
moodle/moodle<4.1.12>=4.2.0, <4.2.9>=4.3.0, <4.3.6>=4.4.0, <4.4.2Composer7 Nov 2024
  • H
Improper Input Validation
moodle/moodle<4.1.12>=4.2.0, <4.2.9>=4.3.0, <4.3.6>=4.4.0, <4.4.2Composer7 Nov 2024
  • H
Access Control Bypass
moodle/moodle<4.1.12>=4.2.0, <4.2.9>=4.3.0, <4.3.6>=4.4.0, <4.4.2Composer7 Nov 2024
  • M
Cross-site Scripting (XSS)
unopim/unopim<0.1.4Composer7 Nov 2024
  • L
Protection Mechanism Failure
twig/twig<3.11.2>=3.12.0, <3.14.1Composer7 Nov 2024
  • L
Protection Mechanism Failure
twig/twig<3.11.2>=3.12.0, <3.14.1Composer7 Nov 2024
  • M
Access Restriction Bypass
symfony/symfony<5.4.46>=6.0.0-BETA1, <6.4.14>=7.0.0-BETA1, <7.1.7Composer6 Nov 2024
  • M
Improper Authorization
symfony/security-bundle>=6.2.0-BETA1, <6.4.10>=7.0.0-BETA1, <7.0.10>=7.1.0-BETA1, <7.1.3Composer6 Nov 2024
  • M
Insertion of Sensitive Information Into Sent Data
symfony/http-client<5.4.46>=6.0.0-BETA1, <6.4.14>=7.0.0-BETA1, <7.1.7Composer6 Nov 2024
  • M
Misinterpretation of Input
symfony/validator<5.4.43>=6.0.0-BETA1, <6.4.11>=7.0.0-BETA1, <7.1.4Composer6 Nov 2024
  • M
Open Redirect
symfony/http-foundation<5.4.46>=6.0.0-BETA1, <6.4.14>=7.0.0-BETA1, <7.1.7Composer6 Nov 2024
  • M
Arbitrary Code Injection
symfony/process<5.4.46>=6.0.0-BETA1, <6.4.14>=7.0.0-BETA1, <7.1.7Composer6 Nov 2024
  • M
Cross-site Scripting (XSS)
athlon1600/youtube-downloader>=0.0.0Composer4 Nov 2024
  • M
Prototype Pollution
maximebf/debugbar<1.19.0Composer4 Nov 2024
  • M
Cross-site Scripting (XSS)
maximebf/debugbar<1.19.0Composer4 Nov 2024