An open API service providing security vulnerability metadata for many open source software ecosystems.

Browse Security Advisories

Moderate
8 months ago

Drupal core Access bypass GSA_kwCzR0hTQS03Y3djLWZqcW0tOHZoOM4ABCNe

packagist drupal/drupal, drupal/core-recommended, drupal/core
High
8 months ago

Drupal core contains a potential PHP Object Injection vulnerability GSA_kwCzR0hTQS1ndmYyLTJmNGctanFmNM4ABCNl

packagist drupal/drupal, drupal/core-recommended, drupal/core
High
8 months ago

Drupal core contains a potential PHP Object Injection vulnerability GSA_kwCzR0hTQS13NnJ4LTlnMngtbWc1Z84ABCNg

packagist drupal/drupal, drupal/core-recommended, drupal/core
Low
8 months ago

Drupal core contains a potential PHP Object Injection vulnerability GSA_kwCzR0hTQS05MzhmLTVyNGYtaDY1ds4ABCNm

packagist drupal/drupal, drupal/core-recommended, drupal/core
Moderate
8 months ago

Drupal Core Cross-Site Scripting (XSS) GSA_kwCzR0hTQS04bXZxLThoMnYtajl2Zs4ABCNk

packagist drupal/drupal, drupal/core-recommended, drupal/core
Moderate
11 months ago

Drupal Full Path Disclosure GSA_kwCzR0hTQS1tZzhqLXc5M3cteGpnY84AA_BD

packagist drupal/core, drupal/core-recommended, drupal/drupal
Moderate
about 1 year ago

Drupal core Denial of Service GSA_kwCzR0hTQS13MzMzLTVmOTYtbWpycs4AA8HU

packagist drupal/drupal
Moderate
about 1 year ago

Drupal Anonymous Open Redirect GSA_kwCzR0hTQS14NnYyLXhtcnEtNTc0as4AA8HQ

packagist drupal/drupal
Critical
over 1 year ago

Drupal Core Remote Code Execution Vulnerability GSA_kwCzR0hTQS0yOTd4LWo5cG0teGpnZ84AA7QY

packagist drupal/drupal, drupal/core
Critical
over 1 year ago

Drupal Improper Access Control GSA_kwCzR0hTQS14cTYyLTYyYzktMjJtZ84AA4Y2

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Drupal Core Access bypass vulnerability GSA_kwCzR0hTQS14MnE5LXI4Z20tZjY1N84AAohb

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Drupal Core Cross-site scripting vulnerability GSA_kwCzR0hTQS04amoyLXgyZ2MtZ2dtN84AAoX_

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Drupal Core Open Redirect vulnerability GSA_kwCzR0hTQS1nanFnLTlyaHYtcWo2N84AAoX9

packagist drupal/drupal, drupal/core
Critical
about 3 years ago

Drupal Core Access bypass vulnerability GSA_kwCzR0hTQS13eHFwLWp3YzktZzM5eM4AAoYB

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Drupal Cross Site Scripting (XSS) vulnerability GSA_kwCzR0hTQS1jbW1oLThtd3AtZ3E1cM4AAiGR

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Drupal Open Redirect GSA_kwCzR0hTQS13d3JtLTg5NDctNG02Y84AAe25

packagist drupal/drupal
High
about 3 years ago

Drupal Open Redirect GSA_kwCzR0hTQS04MzZwLTZwNGotMzVjZ84AAdZS

packagist drupal/core, drupal/drupal
Moderate
about 3 years ago

Drupal Reflected file download vulnerability GSA_kwCzR0hTQS1xcXhjLWNwcGctNHhwOM4AAdYz

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Drupal sensitive information disclosure GSA_kwCzR0hTQS1wcXY0LXhncWgtajh2aM4AAdYs

packagist drupal/drupal, drupal/core
High
about 3 years ago

Drupal arbitrary code execution GSA_kwCzR0hTQS02OWc4LWc5anEtNzR2N84AAdW6

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Drupal Cross-site scripting (XSS) vulnerability GSA_kwCzR0hTQS12aGc4LXg4NTgtN3dxNs4AAdKN

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Drupal Unprivileged access to config export GSA_kwCzR0hTQS1mbXFoLTJqMngtdmdwM84AAdKO

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Drupal Denial of service via transliterate mechanism GSA_kwCzR0hTQS1qcGo4LTQ5aHItd2N3ds4AAc7N

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Drupal sensitive information disclosure GSA_kwCzR0hTQS1wNzQ1LTM0N2gtaGpmd84AAcG_

packagist drupal/drupal, drupal/core
High
about 3 years ago

Drupal Cross-Site Request Forgery (CSRF) GSA_kwCzR0hTQS1neHhxLWZoYzctM2p2Oc4AAbOV

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Drupal cross site scripting vulnerability GSA_kwCzR0hTQS01dnByLXYyNHctbW1qas4AAXNU

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Drupal external link injection vulnerability GSA_kwCzR0hTQS13bTg2LXczY2YtaDZ2bc4AAXNG

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Drupal cross-site scripting vulnerability GSA_kwCzR0hTQS01ODVqLTU0NDktbWY1bc4AAXMs

packagist drupal/drupal, drupal/core
Critical
about 3 years ago

Drupal PECL YAML parser unsafe object handling GSA_kwCzR0hTQS05YzI0LWczMmctMzVyas4AAWPD

packagist drupal/drupal, drupal/core
Critical
about 3 years ago

Drupal Core Remote Code Execution Vulnerability GSA_kwCzR0hTQS03Zmg5LTkzM2ctODg1cM4AAUGf

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS) GSA_kwCzR0hTQS1nNzhoLXBmNjUtNDZyds4AATTf

packagist, npm drupal/drupal, ckeditor-dev, drupal/core
Moderate
about 3 years ago

Drupal Settings Tray access bypass GSA_kwCzR0hTQS03ZmZoLWNqdmctZnByNM4AASZT

packagist drupal/drupal, drupal/core
High
about 3 years ago

Drupal access control bypass vulnerability GSA_kwCzR0hTQS02aHBqLTl4ajctMmp4eM4AASZo

packagist drupal/drupal, drupal/core
High
about 3 years ago

Drupal access bypass vulnerability GSA_kwCzR0hTQS0zMzI3LWpyOTMtN2hxM84AASZL

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Drupal access bypass vulnerability GSA_kwCzR0hTQS02Nm12LXE4cjItaGo4d84AASZx

packagist drupal/drupal, drupal/core
High
about 3 years ago

Drupal Remote code execution GSA_kwCzR0hTQS1yaHg5LTNxZjctcjNqN84AASYD

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Drupal core access bypass vulnerability GSA_kwCzR0hTQS01OGYzLWN4OHAtaDhqZ84AARYs

packagist drupal/drupal, drupal/core
Moderate
about 3 years ago

Drupal file REST resource does not properly validate GSA_kwCzR0hTQS1oMzc3LTI4N20tdzJyOc4AARY1

packagist drupal/drupal, drupal/core
High
about 3 years ago

Drupal REST API can bypass comment approval GSA_kwCzR0hTQS1wOGc2LTVtZzctOXI1cc4AARZN

packagist drupal/drupal, drupal/core
High
about 3 years ago

Drupal Core Remote Code Execution Vulnerability GSA_kwCzR0hTQS0zZ3g2LWg1N2gtcm0yN84AAQKY

packagist drupal/drupal, drupal/core
High
over 3 years ago

HTTP Proxy header vulnerability GSA_kwCzR0hTQS1tNmNoLWdnNWYtd3h4M805QQ

packagist typo3/cms, drupal/drupal, bugsnag/bugsnag-laravel, amphp/artax, padraic/humbug_get_contents, drupal/core, guzzlehttp/guzzle
Moderate
over 3 years ago

Cross-site Scripting in Drupal Core GSA_kwCzR0hTQS1tNnE1LXd2NHgtZnY2aM0rRw

packagist drupal/drupal, drupal/core
Moderate
over 3 years ago

Drupal core Cross-site Scripting (XSS) vulnerability GSA_kwCzR0hTQS0zbTM2LW1qd2otMzUyY80rQQ

packagist drupal/drupal, drupal/core
Critical
over 3 years ago

Arbitrary PHP code execution in Drupal GSA_kwCzR0hTQS04Y3c1LXJ2OTgtNWM0Ns0g-A

packagist drupal/core, drupal/drupal
Critical
almost 4 years ago

Directory Traversal in typo3/phar-stream-wrapper GSA_kwCzR0hTQS14djd2LXJmNmcteHdyY80WEA

packagist drupal/drupal, drupal/core, typo3/phar-stream-wrapper
Moderate
about 4 years ago

ckeditor4 vulnerable to cross-site scripting MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJneDYtcmpqNC1jMzg4

packagist, npm drupal/drupal, drupal/core, ckeditor4
Moderate
over 5 years ago

Symfony Cross-site Scripting (XSS) vulnerability MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc5OTYtcTVyOC13N2cy

packagist drupal/drupal, drupal/core, symfony/symfony, symfony/framework-bundle
Moderate
almost 6 years ago

Missing Authorization in Drupal MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXYzZjYtZjI5Zi1yZ3Zw

packagist drupal/drupal, drupal/core

Filter by Severity

Filter by Ecosystem

Filter by Package

tensorflow 433 tensorflow-gpu 427 tensorflow-cpu 423 moodle/moodle 418 magento/community-edition 300 Microsoft.ChakraCore 247 org.jenkins-ci.main:jenkins-core 239 typo3/cms 190 org.apache.tomcat:tomcat 138 pimcore/pimcore 120 dolibarr/dolibarr 116 github.com/mattermost/mattermost/server/v8 115 typo3/cms-core 111 phpmyadmin/phpmyadmin 107 Django 107 drupal/core 103 com.liferay.portal:release.portal.bom 100 magento/project-community-edition 100 microweber/microweber 99 silverstripe/framework 92 com.liferay.portal:release.dxp.bom 91 apache-airflow 85 drupal/drupal 83 librenms/librenms 82 thorsten/phpmyfaq 73 Plone 72 com.fasterxml.jackson.core:jackson-databind 69 symfony/symfony 69 concrete5/concrete5 65 github.com/usememos/memos 65 salt 65 ansible 63 actionpack 61 apache-superset 57 shopware/platform 57 org.apache.struts:struts2-core 57 github.com/grafana/grafana 56 mlflow 53 craftcms/cms 51 org.keycloak:keycloak-core 50 nova 48 baserproject/basercms 47 django 46 org.apache.tomcat.embed:tomcat-embed-core 46 nokogiri 46 shopware/core 45 gradio 44 github.com/rancher/rancher 44 mautic/core 44 vyper 44 matrix-synapse 42 rdiffweb 42 nilsteampassnet/teampass 42 mantisbt/mantisbt 41 org.keycloak:keycloak-services 41 k8s.io/kubernetes 41 org.xwiki.platform:xwiki-platform-oldcore 41 plone 41 showdoc/showdoc 41 org.elasticsearch:elasticsearch 41 github.com/hashicorp/vault 40 froxlor/froxlor 40 intelliants/subrion 39 github.com/mattermost/mattermost-server/v6 39 directus 38 com.thoughtworks.xstream:xstream 37 snipe/snipe-it 36 net.mingsoft:ms-mcms 36 com.jfinal:jfinal 36 moin 35 io.undertow:undertow-core 34 github.com/answerdev/answer 34 org.jenkins-ci.plugins:script-security 34 zendframework/zendframework1 34 parse-server 33 keystone 32 gogs.io/gogs 32 github.com/cilium/cilium 31 github.com/argoproj/argo-cd/v2 31 github.com/argoproj/argo-cd 31 opencv-python 31 Pillow 31 github.com/hashicorp/nomad 31 opencv-contrib-python 31 getgrav/grav 30 shopware/shopware 30 rack 29 github.com/docker/docker 29 github.com/hashicorp/consul 29 github.com/mattermost/mattermost-server 29 org.apache.solr:solr-core 28 mediawiki/core 28 electron 28 org.opencms:opencms-core 27 centreon/centreon 27 pillow 26 openssl-src 26 org.springframework.security:spring-security-core 26 next 26 prestashop/prestashop 26 rubygems-update 25 contao/core-bundle 25 org.eclipse.jetty:jetty-server 25 open-webui 25 github.com/traefik/traefik/v2 24 surrealdb 24 getkirby/cms 24 pocketmine/pocketmine-mp 24 magento/core 24 org.keycloak:keycloak-parent 24 laravel/framework 23 simplesamlphp/simplesamlphp 23 puppet 23 vllm 23 grumpydictator/firefly-iii 23 phpoffice/phpexcel 23 remdex/livehelperchat 23 zendframework/zendframework 23 org.bouncycastle:bcprov-jdk14 22 tribalsystems/zenario 22 Microsoft.AspNetCore.App.Runtime.win-x86 22 Microsoft.AspNetCore.App.Runtime.win-x64 22 org.apache.openmeetings:openmeetings-parent 22 DotNetNuke.Core 22 @openzeppelin/contracts-upgradeable 22 ckb 22 org.apache.nifi:nifi 21 github.com/ethereum/go-ethereum 21 org.apache.tomcat:tomcat-catalina 21 @openzeppelin/contracts 21 phpoffice/phpspreadsheet 21 glance 21 github.com/goharbor/harbor 21 activerecord 21 Microsoft.AspNetCore.App.Runtime.win-arm 21 golang.org/x/net 20 funadmin/funadmin 20 aim 20 code.gitea.io/gitea 20 wasmtime 20 cockpit-hq/cockpit 20 org.cloudfoundry.identity:cloudfoundry-identity-server 20 langchain 20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 19 neutron 19 github.com/zitadel/zitadel 19 helm.sh/helm/v3 19 deno 19 Microsoft.AspNetCore.App.Runtime.linux-arm 19 Microsoft.AspNetCore.App.Runtime.linux-arm64 19 Microsoft.AspNetCore.App.Runtime.linux-x64 19 Microsoft.AspNetCore.App.Runtime.osx-x64 19 Microsoft.AspNetCore.App.Runtime.win-arm64 19 pyload-ng 19 org.apache.tomcat:tomcat-coyote 19 org.xwiki.platform:xwiki-platform-web-templates 19 genix/cms 18 contao/contao 18 topthink/framework 18 forkcms/forkcms 18 cobbler 18 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 18 mercurial 18 mindsdb 18 com.vaadin:vaadin-bom 18 symfony/security 17 cakephp/cakephp 17 notebook 17 calibreweb 17 opencart/opencart 17 org.apache.geode:geode-core 17 openmage/magento-lts 17 OctoPrint 17 org.apache.inlong:manager-pojo 17 org.springframework:spring-core 17 cryptography 17 francoisjacquet/rosariosis 17 typo3/cms-backend 17 yetiforce/yetiforce-crm 17 ezsystems/ezpublish-kernel 17 phpbb/phpbb 16 org.apache.ranger:ranger 16 github.com/traefik/traefik/v3 16 paddlepaddle 16 PaddlePaddle 16 org.apache.activemq:activemq-client 16 lollms 16 org.apache.jspwiki:jspwiki-main 16 rusqlite 16 sequelize 16 org.apache.dubbo:dubbo 16 Microsoft.NetCore.App.Runtime.win-arm 16 github.com/openfga/openfga 16 Microsoft.NetCore.App.Runtime.win-arm64 16 Microsoft.NetCore.App.Runtime.win-x64 16 Microsoft.NetCore.App.Runtime.win-x86 16 org.bouncycastle:bcprov-jdk15 16 october/system 16 tinymce 16 ethyca-fides 16

Filter by Repository