Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
External Control of File Name or Path
CVE-2025-49138
Affects
elmsln/haxcms
| Versions
>=0.0.0
H
Cross-site Scripting (XSS)
CVE-2025-49577
Affects
starcitizentools/citizen-skin
| Versions
>=2.13.0, <3.3.1
H
Cross-site Scripting (XSS)
CVE-2025-49579
Affects
starcitizentools/citizen-skin
| Versions
>=2.4.2, <3.3.1
H
Cross-site Scripting (XSS)
CVE-2025-49578
Affects
starcitizentools/citizen-skin
| Versions
>=3.3.0, <3.3.1
H
Cross-site Scripting (XSS)
CVE-2025-49576
Affects
starcitizentools/citizen-skin
| Versions
>=2.31.0, <3.3.1
H
Cross-site Scripting (XSS)
Affects
starcitizentools/citizen-skin
| Versions
>=2.4.2, <3.3.1
H
Arbitrary Code Injection
CVE-2025-29661
Affects
litepubl/cms
| Versions
>=5.97
L
Cross-site Scripting (XSS)
CVE-2016-7111
Affects
mantisbt/mantisbt
| Versions
<1.3.1
M
Cross-site Scripting (XSS)
CVE-2017-7241
Affects
mantisbt/mantisbt
| Versions
<1.3.9
>=2.0.0, <2.1.3
>=2.2.0, <2.2.3
M
Cross-site Scripting (XSS)
CVE-2017-6973
Affects
mantisbt/mantisbt
| Versions
<1.3.8
>=2.0.0, <2.1.2
>=2.2.0, <2.2.2
M
Cross-site Scripting (XSS)
CVE-2022-33910
Affects
mantisbt/mantisbt
| Versions
<2.25.5
M
Cross-site Scripting (XSS)
CVE-2017-12062
Affects
mantisbt/mantisbt
| Versions
>=2.0.0, <2.5.2
M
Cross-site Scripting (XSS)
CVE-2017-7309
Affects
mantisbt/mantisbt
| Versions
<1.3.9
>=2.1.0, <2.1.3
>=2.2.0, <2.2.3
M
Cross-site Scripting (XSS)
CVE-2022-28508
Affects
mantisbt/mantisbt
| Versions
<2.25.7
M
Cross-site Scripting (XSS)
CVE-2025-5096
Affects
tobiasbg/tablepress
| Versions
<2.3.2
M
Cross-site Scripting (XSS)
CVE-2025-32699
Affects
wikimedia/parsoid
| Versions
<0.16.5
>=0.17.0-a1, <0.19.2
>=0.20.0-a1, <0.20.2
M
Cross-site Scripting (XSS)
CVE-2025-32699
Affects
mediawiki/core
| Versions
<1.39.12
>=1.42.0-rc.0, <1.42.6
>=1.43.0-rc.0, <1.43.1
L
Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2025-32698
Affects
mediawiki/core
| Versions
>=1.31, <1.39.12
>=1.42.0-rc.0, <1.42.6
>=1.43.0-rc.0, <1.43.1
L
Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2025-32700
Affects
mediawiki/abuse-filter
| Versions
>=1.43.0, <1.44
L
Improper Preservation of Permissions
CVE-2025-32696
Affects
mediawiki/core
| Versions
<1.39.12
>=1.42.0-rc.0, <1.42.6
>=1.43.0-rc.0, <1.43.1
M
Improper Encoding or Escaping of Output
CVE-2025-32072
Affects
mediawiki/core
| Versions
<1.39.12
>=1.42.0-rc.0, <1.42.6
>=1.43.0-rc.0, <1.43.1
C
Improper Encoding or Escaping of Output
CVE-2025-32071
Affects
wikibase/wikibase
| Versions
>=1.39, <1.44
M
Direct Request ('Forced Browsing')
CVE-2025-47226
Affects
snipe/snipe-it
| Versions
<8.1.0
M
Arbitrary File Upload
CVE-2024-51991
Affects
october/october
| Versions
<3.7.10
M
Cross-site Scripting (XSS)
CVE-2025-26159
Affects
nasirkhan/laravel-starter
| Versions
<11.11.0
M
Cross-site Scripting (XSS)
CVE-2025-3568
Affects
krayin/laravel-crm
| Versions
<2.1.1
M
Cross-site Scripting (XSS)
CVE-2025-46041
Affects
anchorcms/anchor-cms
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2025-44115
Affects
cotonti/cotonti
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2025-3469
Affects
mediawiki/core
| Versions
<1.39.12
>=1.42.0-rc.0, <1.42.6
>=1.43.0-rc.0, <1.43.1
M
Cross-site Scripting (XSS)
CVE-2025-49130
Affects
barryvdh/laravel-translation-manager
| Versions
<0.6.8