Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Improper Handling of Insufficient Permissions or Privileges
CVE-2025-67848
Affects
moodle/moodle
| Versions
<4.1.22
>=4.4.0-beta, <4.4.12
>=4.5.0-beta, <4.5.8
>=5.0.0-beta, <5.0.4
>=5.1.0-beta, <5.1.1
H
Cross-site Scripting (XSS)
CVE-2025-67850
Affects
moodle/moodle
| Versions
<4.1.22
>=4.4.0-beta, <4.4.12
>=4.5.0-beta, <4.5.8
>=5.0.0-beta, <5.0.4
>=5.1.0-beta, <5.1.1
M
Insertion of Sensitive Information Into Sent Data
CVE-2025-67857
Affects
moodle/moodle
| Versions
<4.1.22
>=4.4.0-beta, <4.4.12
>=4.5.0-beta, <4.5.8
>=5.0.0-beta, <5.0.4
>=5.1.0-beta, <5.1.1
H
SQL Injection
CVE-2026-25513
Affects
facturascripts/facturascripts
| Versions
<2025.8
M
Cross-site Scripting (XSS)
CVE-2020-11023
Affects
components/jquery
| Versions
<3.5.1
H
Arbitrary File Upload
CVE-2026-25510
Affects
ci4-cms-erp/ci4ms
| Versions
<0.28.5.0
H
SQL Injection
CVE-2026-25514
Affects
facturascripts/facturascripts
| Versions
<2025.8
>=2025.11, <2025.81
M
Information Exposure
CVE-2026-25523
Affects
openmage/magento-lts
| Versions
>=0.0.0
H
SQL Injection
CVE-2020-36947
Affects
librenms/librenms
| Versions
<1.69
M
Information Exposure
CVE-2026-25509
Affects
ci4-cms-erp/ci4ms
| Versions
<0.28.5.0
H
Cross-site Scripting (XSS)
CVE-2026-23997
Affects
facturascripts/facturascripts
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2026-23476
Affects
facturascripts/facturascripts
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2020-11022
Affects
components/jquery
| Versions
<3.5.1
M
Uncontrolled Search Path Element
CVE-2026-25129
Affects
psy/psysh
| Versions
<0.11.23
>=0.12.0, <0.12.19
M
Arbitrary Argument Injection
CVE-2026-24739
Affects
symfony/process
| Versions
<5.4.51
>=6.4.0-BETA1, <6.4.33
>=7.3.0-BETA1, <7.3.11
>=7.4.0-BETA1, <7.4.5
>=8.0.0-BETA1, <8.0.5
M
Cross-site Scripting (XSS)
CVE-2020-36978
Affects
froxlor/froxlor
| Versions
>=0.10.16, <0.10.17
H
SQL Injection
CVE-2026-22243
Affects
egroupware/egroupware
| Versions
<23.1.20260113
>=26.0.20251208, <26.0.20260113
H
Deserialization of Untrusted Data
CVE-2026-24765
Affects
phpunit/phpunit
| Versions
<8.5.52
>=9.0.0, <9.6.33
>=10.0.0, <10.5.62
>=11.0.0, <11.5.50
>=12.0.0, <12.5.8
M
Cross-site Scripting (XSS)
Affects
solspace/craft-freeform
| Versions
<5.14.7
M
Information Exposure
CVE-2026-24422
Affects
thorsten/phpmyfaq
| Versions
<4.1.0-alpha
H
Improper Authorization
CVE-2026-24421
Affects
thorsten/phpmyfaq
| Versions
<4.1.0-alpha
H
Access Control Bypass
CVE-2026-24420
Affects
thorsten/phpmyfaq
| Versions
<4.1.0-alpha
M
Cross-site Scripting (XSS)
CVE-2025-71177
Affects
lavalite/cms
| Versions
>=0.0.0
H
Arbitrary Code Injection
CVE-2025-67847
Affects
moodle/moodle
| Versions
<4.1.22
>=4.2.0-beta, <4.4.12
>=4.5.0-beta, <4.5.8
>=5.0.0-beta, <5.0.4
>=5.1.0-beta, <5.1.1
L
Insufficient Verification of Data Authenticity
CVE-2026-1195
Affects
mineadmin/mineadmin
| Versions
>=0.0.0
C
Deserialization of Untrusted Data
CVE-2026-23524
Affects
laravel/reverb
| Versions
<1.7.0
M
SQL Injection: Hibernate
CVE-2026-23959
Affects
coreshop/core-shop
| Versions
<4.1.9
M
Deserialization of Untrusted Data
CVE-2026-0895
Affects
cpsit/typo3-mailqueue
| Versions
<0.4.3
>=0.5.0, <0.5.1
M
Improper Resource Locking
CVE-2025-69198
Affects
pterodactyl/panel
| Versions
<1.12.0
H
Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-23626
Affects
kimai/kimai
| Versions
>=0.8, <2.46.0