Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Improper Resource Locking
CVE-2025-69198
Affects
pterodactyl/panel
| Versions
<1.12.0
H
Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-23626
Affects
kimai/kimai
| Versions
>=0.8, <2.46.0
H
Arbitrary Code Injection
CVE-2025-14894
Affects
livewire-filemanager/filemanager
| Versions
<1.0.5
H
SQL Injection
CVE-2021-47763
Affects
aimeos/aimeos-laravel
| Versions
>=2021.10
M
Cross-site Scripting (XSS)
CVE-2026-23643
Affects
cakephp/cakephp
| Versions
>=5.2.10, <5.2.12
>=5.3.0-RC1, <5.3.1
H
Cross-site Request Forgery (CSRF)
CVE-2026-23622
Affects
alextselegidis/easyappointments
| Versions
>=1.1.0-beta.1
M
Insufficient Granularity of Access Control
CVE-2026-23495
Affects
pimcore/admin-ui-classic-bundle
| Versions
<1.7.16
>=2.0.0-RC1, <2.2.3
M
Insufficient Granularity of Access Control
CVE-2026-23496
Affects
pimcore/web2print-tools-bundle
| Versions
<5.2.2
>=6.0.0-RC1, <6.1.1
M
Insufficient Granularity of Access Control
CVE-2026-23494
Affects
pimcore/pimcore
| Versions
<11.5.14
>=12.0.0-RC1, <12.3.1
H
Insertion of Sensitive Information into Log File
CVE-2026-23493
Affects
pimcore/pimcore
| Versions
<11.5.14
>=12.0.0-RC1, <12.3.1
M
Cross-site Scripting (XSS)
CVE-2025-63644
Affects
ph7software/ph7builder
| Versions
>=12.9.8
M
SQL Injection
CVE-2026-23492
Affects
pimcore/pimcore
| Versions
<11.5.14
>=12.0.0-RC1, <12.3.1
H
Arbitrary Code Injection
CVE-2026-23498
Affects
shopware/platform
| Versions
>=6.7.0.0, <6.7.6.1
H
Arbitrary Code Injection
CVE-2026-23498
Affects
shopware/core
| Versions
>=6.7.0.0, <6.7.6.1
H
Arbitrary Code Injection
Affects
algolia/algoliasearch-magento-2
| Versions
<3.16.2
>=3.17.0-beta.1, <3.17.2
H
Allocation of Resources Without Limits or Throttling
Affects
google/protobuf
| Versions
<5.34.0RC1
M
Missing Authorization
CVE-2025-59021
Affects
typo3/cms-redirects
| Versions
<12.4.41
>=13.0.0, <13.4.23
>=14.0.0, <14.0.2
H
Missing Authorization
CVE-2025-59022
Affects
typo3/cms-core
| Versions
<12.4.41
>=13.0.0, <13.4.23
>=14.0.0, <14.0.2
H
Missing Authorization
CVE-2025-59022
Affects
typo3/cms-recycler
| Versions
<12.4.41
>=13.0.0, <13.4.23
>=14.0.0, <14.0.2
M
Deserialization of Untrusted Data
CVE-2026-0859
Affects
typo3/cms-core
| Versions
<12.4.41
>=13.0.0, <13.4.23
>=14.0.0, <14.0.2
H
Cross-site Scripting (XSS)
CVE-2025-61676
Affects
october/system
| Versions
<3.7.13
>=4.0.0, <4.0.12
H
Cross-site Scripting (XSS)
CVE-2025-61676
Affects
october/backend
| Versions
>=0.0.0
H
Cross-site Scripting (XSS)
CVE-2025-61674
Affects
october/backend
| Versions
>=0.0.0
H
Cross-site Scripting (XSS)
CVE-2025-61674
Affects
october/october
| Versions
<3.7.13
>=4.0.0, <4.0.12
M
Incorrect Authorization
CVE-2025-59020
Affects
typo3/cms-core
| Versions
<12.4.41
>=13.0.0, <13.4.23
>=14.0.0, <14.0.2
M
Incorrect Authorization
CVE-2025-59020
Affects
typo3/cms-backend
| Versions
<12.4.41
>=13.0.0, <13.4.23
>=14.0.0, <14.0.2
M
PHP Remote File Inclusion
CVE-2022-50897
Affects
mpdf/mpdf
| Versions
>=5.5.1
M
Directory Traversal
CVE-2026-21857
Affects
redaxo/source
| Versions
<5.20.2
H
Allocation of Resources Without Limits or Throttling
CVE-2025-68456
Affects
craftcms/cms
| Versions
>=3.0.0, <4.16.17
>=5.0.0-RC1, <5.8.21
H
Unsafe Reflection
CVE-2025-68455
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.16.17
>=5.0.0-RC1, <5.8.21