Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Sensitive Cookie Without "HttpOnly" Flag
CVE-2026-25733
Affects
rucio-webui
| Versions
[,35.8.3)
[36.0.0rc1,38.5.4)
[39.0.0rc1,39.3.1)
M
Information Exposure
CVE-2026-25138
Affects
rucio-webui
| Versions
[,35.8.3)
[36.0.0rc1,38.5.4)
[39.0.0rc1,39.3.1)
H
Eval Injection
CVE-2026-27702
Affects
@budibase/server
| Versions
<3.30.4
H
Server-side Request Forgery (SSRF)
CVE-2026-27732
Affects
wwbn/avideo
| Versions
<22.0.0
H
Weak Password Recovery Mechanism for Forgotten Password
CVE-2026-27593
Affects
statamic/cms
| Versions
<5.73.10
>=6.0.0-alpha.1, <6.3.3
C
Missing Authorization
CVE-2026-27608
Affects
parse-dashboard
| Versions
>=7.3.0-alpha.42 <9.0.0-alpha.8
H
Missing Authentication for Critical Function
CVE-2026-27595
Affects
parse-dashboard
| Versions
>=7.3.0-alpha.42 <9.0.0-alpha.8
H
Cross-site Request Forgery (CSRF)
CVE-2026-27609
Affects
parse-dashboard
| Versions
>=7.3.0-alpha.42 <9.0.0-alpha.8
H
Improper Validation of Unsafe Equivalence in Input
CVE-2026-27610
Affects
parse-dashboard
| Versions
>=7.3.0-alpha.42 <9.0.0-alpha.8
M
Cross-site Scripting (XSS)
CVE-2026-27612
Affects
repostat
| Versions
<1.0.1
M
Cross-site Scripting (XSS)
CVE-2026-27621
Affects
typicms/core
| Versions
<16.1.7
H
Allocation of Resources Without Limits or Throttling
CVE-2026-26047
Affects
moodle/moodle
| Versions
<4.5.9
>=5.0.0-beta, <5.0.5
>=5.1.0-beta, <5.1.2
H
Arbitrary Code Injection
CVE-2026-26045
Affects
moodle/moodle
| Versions
<4.5.9
>=5.0.0-beta, <5.0.5
>=5.1.0-beta, <5.1.2
M
Multiple Releases of Same Resource or Handle
Affects
openclaw
| Versions
<2026.2.21
M
Incorrect Authorization
Affects
openclaw
| Versions
<2026.2.23-beta.1
M
Out-of-bounds Write
CVE-2026-3394
Affects
jarikomppa/soloud
| Versions
[0,]
M
Heap-based Buffer Overflow
CVE-2026-3393
Affects
jarikomppa/soloud
| Versions
[0,]
L
Cross-site Scripting (XSS)
CVE-2026-28338
Affects
net.sourceforge.pmd:pmd-core
| Versions
[,7.22.0)
H
Server-side Request Forgery (SSRF)
CVE-2026-27730
Affects
github.com/esm-dev/esm.sh/server
| Versions
<136_1
H
Server-side Request Forgery (SSRF)
CVE-2026-27730
Affects
github.com/esm-dev/esm.sh/internal/fetch
| Versions
<136_1
M
Division by zero
CVE-2026-3383
Affects
chaiscript
| Versions
[0,]
M
Division by zero
CVE-2026-3383
Affects
ChaiScript/ChaiScript
| Versions
[0,]
M
Uncontrolled Recursion
CVE-2026-3384
Affects
chaiscript
| Versions
[0,]
M
Uncontrolled Recursion
CVE-2026-3384
Affects
ChaiScript/ChaiScript
| Versions
[0,]
M
Allocation of Resources Without Limits or Throttling
CVE-2026-28351
Affects
pypdf
| Versions
[,6.7.4)
M
Use After Free
CVE-2026-3382
Affects
chaiscript
| Versions
[0,]
M
Use After Free
CVE-2026-3382
Affects
ChaiScript/ChaiScript
| Versions
[0,]
H
Incorrect Authorization
CVE-2026-2293
Affects
@nestjs/core
| Versions
>=11.1.13 <11.1.14
C
Server-side Request Forgery (SSRF)
CVE-2026-27696
Affects
changedetection.io
| Versions
[,0.54.1)
M
Cross-site Scripting (XSS)
CVE-2026-27645
Affects
changedetection.io
| Versions
[,0.54.1)