Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
amphp/http-server affected by HTTP/2 DDoS vulnerability
CVE-2026-25892
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
CVE-2026-25878
FroshAdminer Adminer UI is accessible without admin session
CVE-2026-25498
Craft CMS Vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
CVE-2026-25497
Craft CMS: GraphQL Asset Mutation Privilege Escalation
CVE-2026-25496
Craft CMS Vulnerable to Stored XSS in Number Prefix & Suffix Fields
CVE-2026-25495
Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`
CVE-2026-25494
Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via Alternative IP Notation
CVE-2026-25493
Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via HTTP Redirect
CVE-2026-25492
Craft CMS: save_images_Asset graphql mutation can be abused to exfiltrate AWS credentials of underlying host
CVE-2026-25491
Craft CMS Vulnerable to Stored XSS in Entry Types Name
CVE-2026-24419
OpenSTAManager has a SQL Injection in the Prima Nota module
CVE-2026-24418
OpenSTAManager has a SQL Injection vulnerability in the Scadenzario bulk operations module
CVE-2026-24417
OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service
CVE-2026-24416
OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module
CVE-2025-69216
OpenSTAManager has a SQL Injection in Scadenzario Print Template
CVE-2025-69214
OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)
CVE-2025-69212
OpenSTAManager has an OS Command Injection in P7M File Processing
CVE-2025-70791
Microweber has a Cross-site Scripting vulnerability
CVE-2025-70792
Microweber Cross-site Scripting vulnerability
Showing 1 - 20 of 1,000+ results