Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Incorrect Resource Transfer Between Spheres
CVE-2026-49853
Affects
tornado
| Versions
[,6.5.6)
M
Cross-site Scripting (XSS)
Affects
html5lib
| Versions
[0,]
M
Cross-site Scripting (XSS)
Affects
bleach
| Versions
[,6.4.0)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-5497
Affects
vllm
| Versions
[, 0.19.1)
M
HTTP Request Smuggling
CVE-2026-48746
Affects
vllm
| Versions
[0.3.0, 0.22.0)
H
Reachable Assertion
CVE-2026-41523
Affects
vllm
| Versions
[,0.22.0)
H
Relative Path Traversal
CVE-2026-50203
Affects
apache-airflow-providers-sftp
| Versions
[,5.8.1)
H
Command Injection
Affects
yt-dlp
| Versions
[2021.4.11, 2026.6.9)
H
Uncontrolled Recursion
CVE-2026-48712
Affects
org.webjars.npm:protobufjs
| Versions
[0,]
H
Regular Expression Denial of Service (ReDoS)
CVE-2026-48125
Affects
org.webjars.npm:ua-parser-js
| Versions
[2.0.1,]
M
Unintended Proxy or Intermediary ('Confused Deputy')
CVE-2026-9595
Affects
org.webjars.npm:webpack-dev-server
| Versions
[0,]
C
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-50574
Affects
yt-dlp
| Versions
[,2026.6.9)
H
Directory Traversal
CVE-2026-53571
Affects
org.webjars.npm:vite
| Versions
[0,]
M
Inefficient Algorithmic Complexity
CVE-2026-48988
Affects
org.webjars.npm:markdown-it
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2026-56317
Affects
org.webjars.npm:nuxt
| Versions
[0,]
C
Open Redirect
CVE-2026-56326
Affects
org.webjars.npm:nuxt
| Versions
[0,]
C
Embedded Malicious Code
Affects
@mastra/node-speaker
| Versions
=0.1.1
H
Improper Restriction of Names for Files and Other Resources
CVE-2026-50023
Affects
yt-dlp
| Versions
[,2026.6.9)
M
Inefficient Algorithmic Complexity
CVE-2026-48988
Affects
markdown-it
| Versions
<14.2.0
M
Reliance on Cookies without Validation and Integrity Checking
CVE-2026-50019
Affects
yt-dlp
| Versions
[2023.9.24, 2026.6.9)
M
Exposure of Sensitive System Information to an Unauthorized Control Sphere
Affects
nuxt
| Versions
>=4.0.0-alpha.1 <4.4.7
H
Directory Traversal
CVE-2026-53571
Affects
vite
| Versions
<6.4.3
>=7.0.0-beta.0 <7.3.5
>=8.0.0-beta.0 <8.0.16
H
Directory Traversal
CVE-2026-53571
Affects
vite-plus
| Versions
<0.1.24
M
Cross-site Scripting (XSS)
CVE-2026-56317
Affects
nuxt
| Versions
<3.21.7
>=4.0.0-alpha.1 <4.4.7
M
Incorrect Default Permissions
Affects
nuxt
| Versions
>=3.18.0 <3.21.7
>=4.0.0-alpha.1 <4.4.7
C
Open Redirect
CVE-2026-56326
Affects
nuxt
| Versions
<3.21.7
>=4.0.0-alpha.1 <4.4.7
M
Cross-site Scripting (XSS)
CVE-2026-52725
Affects
@angular/core
| Versions
<19.2.23
>=20.0.0-next.0 <20.3.22
>=21.0.0-next.0 <21.2.15
>=22.0.0-next.0 <22.0.0-rc.2
M
Unintended Proxy or Intermediary ('Confused Deputy')
CVE-2026-9595
Affects
webpack-dev-server
| Versions
<5.2.5
H
Regular Expression Denial of Service (ReDoS)
CVE-2026-48125
Affects
ua-parser-js
| Versions
>=2.0.1 <2.0.10
H
Uncontrolled Recursion
CVE-2026-48712
Affects
protobufjs
| Versions
<7.6.1
>=8.0.0 <8.4.1