Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
C
Arbitrary Code Injection
CVE-2025-54068
Affects
livewire/livewire
| Versions
>=3.0.0-beta.1, <3.6.4
C
Improper Neutralization of Special Elements Used in a Template Engine
CVE-2025-53833
Affects
binarytorch/larecipe
| Versions
<2.8.1
M
Cross-site Scripting (XSS)
CVE-2018-20755
Affects
modx/revolution
| Versions
<2.7.1-pl
M
Cross-site Scripting (XSS)
CVE-2018-20757
Affects
modx/revolution
| Versions
<2.7.1-pl
L
Command Injection
CVE-2025-52994
Affects
james-heinrich/phpthumb
| Versions
>=0.0.0, <v1.7.24
H
Exposure of Private Personal Information to an Unauthorized Actor
CVE-2025-53625
Affects
universal-omega/dynamic-page-list3
| Versions
<3.6.4
H
Arbitrary Code Injection
CVE-2025-34086
Affects
bolt/bolt
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2025-7053
Affects
cockpit-hq/cockpit
| Versions
<2.11.4
M
Arbitrary File Upload
CVE-2025-5108
Affects
shopxo/shopxo
| Versions
>=0.0.0
H
Cross-site Scripting (XSS)
CVE-2025-53370
Affects
starcitizentools/citizen-skin
| Versions
<3.4.0
M
Cross-site Scripting (XSS)
CVE-2025-53368
Affects
starcitizentools/citizen-skin
| Versions
<3.4.0
M
SQL Injection
CVE-2025-28057
Affects
slowlyo/owl-admin
| Versions
<4.1.0
M
Cross-site Scripting (XSS)
CVE-2025-28073
Affects
phplist/phplist3
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2025-28074
Affects
phplist/phplist3
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2025-47110
Affects
magento/community-edition
| Versions
>=2.4.5, <2.4.5-p13
>=2.4.6-p1, <2.4.6-p11
>=2.4.7-beta1, <2.4.7-p6
>=2.4.8-beta1, <2.4.8-p1
H
XML External Entity (XXE) Injection
CVE-2025-48882
Affects
phpoffice/math
| Versions
<0.3.0
M
Cross-site Scripting (XSS)
CVE-2025-47931
Affects
librenms/librenms
| Versions
<25.5.0
H
Improper Use of Validation Framework
CVE-2025-48490
Affects
lomkit/laravel-rest-api
| Versions
<2.13.0
L
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2025-49597
Affects
handcraftedinthealps/goodby-csv
| Versions
<1.4.3
H
Arbitrary File Upload
CVE-2025-4102
Affects
hipdevteam/bb-plugin
| Versions
<2.9.1.1
H
Information Exposure
CVE-2024-56526
Affects
oxid-esales/oxideshop-ce
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2025-5420
Affects
juzaweb/cms
| Versions
>=0.0.0
C
Arbitrary Code Injection
CVE-2025-49132
Affects
pterodactyl/panel
| Versions
>=0.0.0, <1.11.11
M
Incorrect Authorization
CVE-2025-27188
Affects
magento/community-edition
| Versions
<2.4.4-p13
>=2.4.5, <2.4.5-p12
>=2.4.6, <2.4.6-p10
>=2.4.7-beta1, <2.4.7-p5
>=2.4.8-beta1, <2.4.8-beta2
M
Cross-site Scripting (XSS)
CVE-2025-48206
Affects
nitsan/ns-backup
| Versions
<13.0.1
H
Direct Request ('Forced Browsing')
CVE-2025-48201
Affects
nitsan/ns-backup
| Versions
<13.0.1
H
Command Injection
CVE-2025-48204
Affects
nitsan/ns-backup
| Versions
<13.0.1
M
Authorization Bypass Through User-Controlled Key
CVE-2025-48207
Affects
renolit/reint-downloadmanager
| Versions
<4.0.2
>=5.0.0, <5.0.1
M
Cross-site Scripting (XSS)
CVE-2025-29746
Affects
koillection/koillection
| Versions
<1.6.11
H
External Control of File Name or Path
CVE-2025-49138
Affects
elmsln/haxcms
| Versions
>=0.0.0