Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Directory Traversal
CVE-2026-21857
Affects
redaxo/source
| Versions
<5.20.2
H
Allocation of Resources Without Limits or Throttling
CVE-2025-68456
Affects
craftcms/cms
| Versions
>=3.0.0, <4.16.17
>=5.0.0-RC1, <5.8.21
H
Unsafe Reflection
CVE-2025-68455
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.16.17
>=5.0.0-RC1, <5.8.21
M
Server-side Request Forgery (SSRF)
CVE-2025-68437
Affects
craftcms/cms
| Versions
>=3.5.0, <4.16.17
>=5.0.0-RC1, <5.8.21
H
Template Injection
CVE-2025-68454
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.16.17
>=5.0.0-RC1, <5.8.21
M
Incorrect Authorization
CVE-2025-68436
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.16.17
>=5.0.0-RC1, <5.8.21
M
Insufficient Session Expiration
CVE-2025-68954
Affects
pterodactyl/panel
| Versions
<1.12.0
M
Incorrect Authorization
CVE-2026-21896
Affects
getkirby/cms
| Versions
>=5.0.0, <5.2.2
M
SQL Injection: Hibernate
CVE-2026-22242
Affects
coreshop/core-bundle
| Versions
<4.1.8
M
Insufficient Session Expiration
CVE-2025-69197
Affects
pterodactyl/panel
| Versions
<1.12.0
H
Improper Validation of Specified Quantity in Input
CVE-2023-7332
Affects
pocketmine/pocketmine-mp
| Versions
<4.18.1
L
Improper Encoding or Escaping of Output
CVE-2025-67746
Affects
composer/composer
| Versions
>=2.0.0, <2.2.26
>=2.3.0, <2.9.3
M
Cross-site Scripting (XSS)
Affects
yourls/yourls
| Versions
<1.10.3
M
Server-side Request Forgery (SSRF)
CVE-2025-15264
Affects
feehi/cms
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2025-69210
Affects
facturascripts/facturascripts
| Versions
<2025.7
H
Information Exposure
CVE-2025-69200
Affects
thorsten/phpmyfaq
| Versions
<4.0.16
>=4.1.0-alpha, <4.1.0-rc
M
Cross-site Scripting (XSS)
Affects
pterodactyl/panel
| Versions
<1.12.0
M
Cross-site Scripting (XSS)
CVE-2025-60796
Affects
phppgadmin/phppgadmin
| Versions
>=0.0.0
M
SQL Injection
CVE-2025-60798
Affects
phppgadmin/phppgadmin
| Versions
>=0.0.0
M
Access Control Bypass
CVE-2025-60799
Affects
phppgadmin/phppgadmin
| Versions
>=0.0.0
M
SQL Injection
CVE-2025-60797
Affects
phppgadmin/phppgadmin
| Versions
>=0.0.0
M
Race Condition
CVE-2025-15116
Affects
opencart/opencart
| Versions
>=0.0.0
H
Directory Traversal
CVE-2024-42718
Affects
croogo/croogo
| Versions
>=0.0.0
H
Command Injection
CVE-2025-13700
Affects
dreamfactory/df-core
| Versions
<1.0.10
H
Arbitrary File Upload
CVE-2025-51511
Affects
cadmium-org/cadmium-cms
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2025-67163
Affects
simplemachines/smf
| Versions
>=0.0.0
M
CSV Injection
CVE-2023-53929
Affects
thorsten/phpmyfaq
| Versions
<3.1.16
M
Cross-site Scripting (XSS)
CVE-2025-68461
Affects
roundcube/roundcubemail
| Versions
<1.5.12
>=1.6.0, <1.6.12
M
Improper Encoding or Escaping of Output
CVE-2025-68460
Affects
roundcube/roundcubemail
| Versions
<1.5.12
>=1.6.0, <1.6.12
M
Use of a Broken or Risky Cryptographic Algorithm
CVE-2025-14761
Affects
aws/aws-sdk-php
| Versions
<3.368.0