Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
596046
AlmaLinux
4544
Alpaquita
8493
Alpine
3988
Android
3260
BellSoft Hardened Containers
380
Bitnami
6681
Chainguard
5186
CleanStart
428
CRAN
13
crates.io
2116
Debian
53236
Echo
3045
GHC
3
GIT
79664
GitHub Actions
46
Go
6151
Hackage
27
Hex
51
Julia
342
Linux
15364
Mageia
5836
Maven
6220
MinimOS
18081
npm
216276
NuGet
1614
opam
11
openEuler
6137
openSUSE
12157
OSS-Fuzz
3804
Packagist
5835
Pub
10
PyPI
18218
Red Hat
18912
Rocky Linux
2811
Root
10849
RubyGems
1891
SUSE
19815
SwiftURL
48
Ubuntu
51260
VSCode
15
Wolfi
3228
ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-28809
Hex/esaml
github.com/arekinath/esaml.git
github.com/dropbox/esaml.git
github.com/handnot2/esaml.git
XXE in esaml SAML library allows local file read and potential SSRF
yesterday
No fix available
Severity - 6.3 (Medium)
GHSA-4w98-xf39-23gp
Hex/ewe
Loop with Unreachable Exit Condition ('Infinite Loop') in ewe
16 Mar
Fix available
Severity - 7.5 (High)
GHSA-9w88-79f8-m3vp
Hex/ewe
Permissive List of Allowed Inputs in ewe
16 Mar
Fix available
Severity - 5.3 (Medium)
GHSA-h7cj-j2vv-qw8r
Hex/wisp
Wisp Vulnerable to Path Traversal
11 Mar
Fix available
Severity - 8.7 (High)
EEF-CVE-2026-28807
Hex/wisp
github.com/gleam-wisp/wisp.git
Path Traversal in wisp.serve_static allows arbitrary file read
10 Mar
Fix available
Severity - 8.7 (High)
GHSA-hx9w-f2w9-9g96
Hex/hex_core
hex_core has Unsafe Deserialization of Erlang Terms
01 Mar
Fix available
Severity - 2.0 (Low)
EEF-CVE-2026-21619
Hex/hex_core
github.com/erlang/rebar3
github.com/hexpm/hex
github.com/hexpm/hex_core
Unsafe Deserialization of Erlang Terms in hex_core
27 Feb
Fix available
Severity - 2.0 (Low)
GHSA-6gvq-jcmp-8959
Go/github.com/altcha-org/altcha-lib-go
Hex/altcha
Maven/org.altcha:altcha
Packagist/altcha-org/altcha
PyPI/altcha
... 2 more
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
16 Dec 2025
Fix available
Severity - 6.5 (Medium)
GHSA-pcxq-fjp3-r752
Hex/ash
Ash has authorization bypass when bypass policy condition evaluates to true
17 Oct 2025
Fix available
Severity - 8.6 (High)
EEF-CVE-2025-48044
Hex/ash
github.com/ash-project/ash
Authorization bypass when bypass policy condition evaluates to true
17 Oct 2025
Fix available
Severity - 8.6 (High)
GHSA-7r7f-9xpj-jmr7
Hex/ash
Ash Framework: Filter authorization misapplies impossible bypass/runtime policies
13 Oct 2025
Fix available
Severity - 8.6 (High)
EEF-CVE-2025-48043
Hex/ash
github.com/ash-project/ash
Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization
10 Oct 2025
Fix available
Severity - 8.6 (High)
GHSA-jj4j-x5ww-cwh9
Hex/ash
Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden
15 Sep 2025
Fix available
Severity - 7.1 (High)
EEF-CVE-2025-48042
Hex/ash
github.com/ash-project/ash
Before action hooks may execute in certain scenarios despite a request being forbidden
07 Sep 2025
Fix available
Severity - 7.1 (High)
EEF-CVE-2025-4754
Hex/ash_authentication_phoenix
github.com/team-alembic/ash_authentication_phoenix
Missing Session Revocation on Logout in ash_authentication_phoenix
17 Jun 2025
Fix available
Severity - 2.3 (Low)
GHSA-f7gq-h8jv-h3cq
Hex/ash_authentication_phoenix
ash_authentication_phoenix has Insufficient Session Expiration
17 Jun 2025
Fix available
Severity - 2.3 (Low)
Load more...
(3 pages left)
Hex - OSV