Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
C
Arbitrary Code Injection
CVE-2026-33873
Affects
langflow-base
| Versions
[0,]
M
Arbitrary Code Injection
CVE-2026-4963
Affects
smolagents
| Versions
[1.21.0,]
H
Missing Authorization
CVE-2026-34046
Affects
langflow-base
| Versions
[,0.5.0.post1)
H
Arbitrary Code Injection
CVE-2026-33744
Affects
bentoml
| Versions
[1.4.8,1.4.37)
H
Directory Traversal
CVE-2026-34070
Affects
langchain-core
| Versions
[,1.2.22)
M
Improper Certificate Validation
CVE-2026-34073
Affects
cryptography
| Versions
[,46.0.6)
C
Command Injection
Affects
zen-ai-pentest
| Versions
[0,]
M
Improper Handling of Length Parameter Inconsistency
CVE-2026-33936
Affects
ecdsa
| Versions
[,0.19.2)
H
Unsafe Dependency Resolution
CVE-2026-27893
Affects
vllm
| Versions
[0.10.1,0.18.0)
C
Embedded Malicious Code
Affects
telnyx
| Versions
[4.87.1]
[4.87.2]
L
Server-side Request Forgery (SSRF)
CVE-2026-33682
Affects
streamlit
| Versions
[,1.54.0)
H
Command Injection
CVE-2026-27602
Affects
modoboa
| Versions
[,2.7.1)
H
Infinite loop
CVE-2026-33699
Affects
pypdf
| Versions
[,6.9.2)
M
Cross-site Scripting (XSS)
CVE-2026-33140
Affects
pyspector
| Versions
[,0.1.7)
H
Incomplete List of Disallowed Inputs
CVE-2026-33139
Affects
pyspector
| Versions
[,0.1.7)
M
SQL Injection
CVE-2026-33545
Affects
mobsf
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2026-32722
Affects
memray
| Versions
[,1.19.2)
H
Infinite loop
CVE-2026-32889
Affects
tinytag
| Versions
[2.2.0,2.2.1)
H
Cross-site Scripting (XSS)
Affects
justhtml
| Versions
[,1.13.0)
H
Command Injection
CVE-2026-33310
Affects
intake
| Versions
[,2.0.9)
M
Insecure Temporary File
CVE-2026-25645
Affects
requests
| Versions
[,2.33.0)
M
Improper Protection of Alternate Path
CVE-2026-4270
Affects
awslabs.aws-api-mcp-server
| Versions
[0.2.14,1.3.9)
H
Missing Authorization
CVE-2026-33125
Affects
frigate
| Versions
[0,]
C
Unsafe Dependency Resolution
CVE-2026-0848
Affects
nltk
| Versions
[,3.9.3)
C
Arbitrary Command Injection
CVE-2025-69902
Affects
kubectl-mcp-tool
| Versions
[,1.2.0)
C
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-33475
Affects
langflow
| Versions
[0,]
C
Embedded Malicious Code
Affects
litellm
| Versions
[1.82.7]
[1.82.8]
H
Allocation of Resources Without Limits or Throttling
CVE-2026-26209
Affects
cbor2
| Versions
[,5.9.0)
L
Cross-site Scripting (XSS)
Affects
justhtml
| Versions
[,1.12.0)
M
Cross-site Scripting (XSS)
Affects
justhtml
| Versions
[,1.12.0)