Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • M
Cross-site Scripting (XSS)
moodle/moodle>=0.0.0Composer21 Jun 2024
  • M
Access Control Bypass
studiomitte/friendlycaptcha<0.1.4Composer21 Jun 2024
  • M
Observable Response Discrepancy
nasirkhan/laravel-starter>=0.0.0Composer21 Jun 2024
  • H
Arbitrary File Creation
opencart/opencart>=4.0.0.0Composer21 Jun 2024
  • H
Arbitrary File Write via Archive Extraction (Zip Slip)
opencart/opencart>=4.0.0.0Composer21 Jun 2024
  • L
Reflected Cross-site Scripting
opencart/opencart>=4.0.0.0, <4.1.0.0Composer21 Jun 2024
  • L
Reflected Cross-site Scripting
opencart/opencart>=4.0.0.0, <4.1.0.0Composer21 Jun 2024
  • L
Reflected Cross-site Scripting
opencart/opencart>=4.0.0.0, <4.1.0.0Composer21 Jun 2024
  • H
SQL Injection
opencart/opencart<3.0.4.0Composer21 Jun 2024
  • M
Improper Access Control
moodle/moodle<4.1.11>=4.2.0, <4.2.8>=4.3.0, <4.3.5>=4.4.0, <4.4.1Composer20 Jun 2024
  • M
Cross-Site Request Forgery (CSRF)
moodle/moodle<4.1.11>=4.2.0, <4.2.8>=4.3.0, <4.3.5>=4.4.0, <4.4.1Composer20 Jun 2024
  • M
Use of a Key Past its Expiration Date
moodle/moodle<4.1.11>=4.2.0, <4.2.8>=4.3.0, <4.3.5>=4.4.0, <4.4.1Composer20 Jun 2024
  • M
Cross-site Scripting (XSS)
moodle/moodle<4.1.11>=4.2.0, <4.2.8>=4.3.0, <4.3.5>=4.4.0, <4.4.1Composer20 Jun 2024
  • M
Improper Authorization
moodle/moodle<4.1.11>=4.2.0, <4.2.8>=4.3.0, <4.3.5>=4.4.0, <4.4.1Composer20 Jun 2024
  • M
Cross-site Scripting (XSS)
tinymce/tinymce<6.8.4>=7.0.0, <7.2.0Composer20 Jun 2024
  • M
Reliance on a Single Factor in a Security Decision
grumpydictator/firefly-iii<6.1.17Composer19 Jun 2024
  • H
SQL Injection
dolibarr/dolibarr<19.0.2Composer19 Jun 2024
  • H
Deserialization of Untrusted Data
nukeviet/nukeviet>=0.0.0Composer14 Jun 2024
  • C
XML External Entity (XXE) Injection
magento/community-edition<2.4.4-p9>=2.4.5, <2.4.5-p8>=2.4.6, <2.4.6-p6>=2.4.7, <2.4.7-p1Composer14 Jun 2024
  • H
Missing Authorization
snipe/snipe-it<6.4.2Composer14 Jun 2024
  • M
Cross-site Scripting (XSS)
woocommerce/woocommerce>=8.8.0, <8.8.5>=8.9.0, <8.9.3Composer13 Jun 2024
  • C
Improper Control of Generation of Code ('Code Injection')
nukeviet/nukeviet>=0.0.0Composer12 Jun 2024
  • M
Privilege Context Switching Error
aimeos/aimeos-core>=2022.04.1, <2022.10.17>=2023.04.1, <2023.10.17>=2024.04.1, <2024.04.7Composer12 Jun 2024
  • H
Command Injection
composer/composer>=2.0, <2.2.24>=2.3, <2.7.7Composer11 Jun 2024
  • H
Command Injection
composer/composer>=2.0, <2.2.24>=2.3, <2.7.7Composer11 Jun 2024
  • M
Cross-site Scripting (XSS)
getformwork/formwork<1.13.1Composer9 Jun 2024
  • H
External Control of File Name or Path
aimeos/aimeos-core>=2024.04.1, <2024.04.5Composer9 Jun 2024
  • M
Cross-site Scripting (XSS)
sulu/form-bundle>=2.0.0, <2.5.3Composer7 Jun 2024
  • L
Insufficiently Protected Credentials
craft-twofactorauthentication>=3.3.1, <3.3.4Composer6 Jun 2024
  • M
Improper Authentication
craft-twofactorauthentication<3.3.4Composer6 Jun 2024