Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Cross-site Request Forgery (CSRF)
CVE-2025-3638
Affects
moodle/moodle
| Versions
>=4.1.0-beta, <4.1.18
>=4.3.0-beta, <4.3.12
>=4.4.0-beta, <4.4.8
>=4.5.0-beta, <4.5.4
M
Cross-site Scripting (XSS)
CVE-2025-3643
Affects
moodle/moodle
| Versions
>=4.1.0-beta, <4.1.18
>=4.3.0-beta, <4.3.12
>=4.4.0-beta, <4.4.8
>=4.5.0-beta, <4.5.4
M
Incorrect Authorization
CVE-2025-3645
Affects
moodle/moodle
| Versions
>=4.1.0-beta, <4.1.18
>=4.3.0-beta, <4.3.12
>=4.4.0-beta, <4.4.8
>=4.5.0-beta, <4.5.4
M
Incorrect Authorization
CVE-2025-3644
Affects
moodle/moodle
| Versions
>=4.1.0-beta, <4.1.18
>=4.3.0-beta, <4.3.12
>=4.4.0-beta, <4.4.8
>=4.5.0-beta, <4.5.4
M
Authorization Bypass Through User-Controlled Key
CVE-2025-3640
Affects
moodle/moodle
| Versions
>=4.1.0-beta, <4.1.18
>=4.3.0-beta, <4.3.12
>=4.4.0-beta, <4.4.8
>=4.5.0-beta, <4.5.4
M
Incorrect Authorization
CVE-2025-3647
Affects
moodle/moodle
| Versions
>=4.1.0-beta, <4.1.18
>=4.3.0-beta, <4.3.12
>=4.4.0-beta, <4.4.8
>=4.5.0-beta, <4.5.4
H
Arbitrary Code Injection
CVE-2025-3642
Affects
moodle/moodle
| Versions
>=4.1.0-beta, <4.1.18
>=4.3.0-beta, <4.3.12
>=4.4.0-beta, <4.4.8
>=4.5.0-beta, <4.5.4
M
Cross-site Request Forgery (CSRF)
CVE-2025-3635
Affects
moodle/moodle
| Versions
>=4.1.0-beta, <4.1.18
>=4.3.0-beta, <4.3.12
>=4.4.0-beta, <4.4.8
>=4.5.0-beta, <4.5.4
M
Improper Authentication
CVE-2025-3627
Affects
moodle/moodle
| Versions
>=4.3.0-beta, <4.3.12
>=4.4.0-beta, <4.4.8
>=4.5.0-beta, <4.5.4
M
Authorization Bypass Through User-Controlled Key
CVE-2025-3636
Affects
moodle/moodle
| Versions
>=4.1.0-beta, <4.1.18
>=4.3.0-beta, <4.3.12
>=4.4.0-beta, <4.4.8
>=4.5.0-beta, <4.5.4
H
Information Exposure
CVE-2025-32044
Affects
moodle/moodle
| Versions
>=4.5.0-beta, <4.5.3
M
Information Exposure
CVE-2025-3628
Affects
moodle/moodle
| Versions
>=4.5.0-beta, <4.5.4
M
Improper Authentication
CVE-2025-3634
Affects
moodle/moodle
| Versions
>=4.3.0-beta, <4.3.12
>=4.4.0-beta, <4.4.8
>=4.5.0-beta, <4.5.4
M
External Control of Assumed-Immutable Web Parameter
CVE-2025-35939
Affects
craftcms/cms
| Versions
<4.15.3
>=5.0.0-alpha.1, <5.7.5
M
Missing Authorization
CVE-2025-32045
Affects
moodle/moodle
| Versions
>=4.1.0, <4.1.17
>=4.3.0-beta, <4.3.11
>=4.4.0-beta, <4.4.7
>=4.5.0-beta, <4.5.3
C
Improper Authentication
CVE-2025-47275
Affects
auth0/auth0-php
| Versions
>=8.0.0-BETA1, <8.14.0
H
XML External Entity (XXE) Injection
CVE-2025-47778
Affects
sulu/sulu
| Versions
>=2.5.21, <2.5.25
>=2.6.5, <2.6.9
>=3.0.0-alpha1, <3.0.0-alpha3
M
Directory Traversal
CVE-2025-31493
Affects
getkirby/cms
| Versions
<3.9.8.3
>=3.10.0, <3.10.1.2
>=4.0.0-alpha.1, <4.7.1
M
Directory Traversal
CVE-2025-30159
Affects
getkirby/cms
| Versions
<3.9.8.3
>=3.10.0, <3.10.1.2
>=4.0.0-alpha.1, <4.7.1
L
Directory Traversal
CVE-2025-30207
Affects
getkirby/cms
| Versions
<3.9.8.3
>=3.10.0, <3.10.1.2
>=4.0.0, <4.7.1
M
Improper Input Validation
CVE-2025-29448
Affects
alextselegidis/easyappointments
| Versions
>=0.0.0, <1.5.2
H
Improper Neutralization of Special Elements Used in a Template Engine
CVE-2025-46731
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.14.13
>=5.0.0-RC1, <5.6.15
M
Insertion of Sensitive Information Into Sent Data
CVE-2016-5739
Affects
phpmyadmin/phpmyadmin
| Versions
>=4.0.10, <4.7.0
M
Cross-site Scripting (XSS)
CVE-2016-5733
Affects
phpmyadmin/phpmyadmin
| Versions
>=4.0.10, <4.7.0
H
Server-side Request Forgery (SSRF)
CVE-2016-6621
Affects
phpmyadmin/phpmyadmin
| Versions
>=4.0.0, <4.7.0
M
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2016-5701
Affects
phpmyadmin/phpmyadmin
| Versions
>=4.0.10, <4.7.0
C
SQL Injection
CVE-2014-6295
Affects
web-tp3/wec_map
| Versions
<3.3.0
M
Cross-site Scripting (XSS)
CVE-2014-6296
Affects
web-tp3/wec_map
| Versions
<3.3.0
H
Arbitrary Argument Injection
CVE-2025-32931
Affects
tcg/voyager
| Versions
>=1.0.0
M
Cross-site Scripting (XSS)
CVE-2025-46734
Affects
league/commonmark
| Versions
>=1.5.0, <2.7.0