Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Incorrect Authorization
CVE-2026-40574
Affects
github.com/oauth2-proxy/oauth2-proxy/v7
| Versions
<7.15.2
H
Incorrect Authorization
CVE-2026-40574
Affects
github.com/oauth2-proxy/oauth2-proxy
| Versions
<7.15.2
M
Information Exposure
CVE-2026-22746
Affects
org.springframework.security:spring-security-core
| Versions
[,6.5.10)
[7.0.0-M1,7.0.5)
L
Incorrect Authorization
CVE-2026-29179
Affects
october/october
| Versions
>=0.0.0
H
User Impersonation
CVE-2026-22747
Affects
org.springframework.security:spring-security-web
| Versions
[7.0.0-M1,7.0.5)
M
Incorrect Authorization
CVE-2026-26067
Affects
october/october
| Versions
>=0.0.0
H
Incomplete List of Disallowed Inputs
CVE-2026-26274
Affects
october/october
| Versions
>=0.0.0
L
Cross-site Scripting (XSS)
CVE-2026-27937
Affects
october/october
| Versions
>=0.0.0
H
Access Control Bypass
CVE-2026-22754
Affects
org.springframework.security:spring-security-config
| Versions
[7.0.0-M1,7.0.5)
H
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-41059
Affects
github.com/oauth2-proxy/oauth2-proxy/pkg/requests/util
| Versions
<7.15.2
H
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-41059
Affects
github.com/oauth2-proxy/oauth2-proxy/v7/pkg/requests/util
| Versions
<7.15.2
H
Missing Authorization
CVE-2026-41266
Affects
flowise
| Versions
<3.1.0
M
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-22751
Affects
org.springframework.security:spring-security-core
| Versions
[6.4.0,6.5.10)
[7.0.0-M1,7.0.5)
H
Improper Verification of Cryptographic Signature
CVE-2026-40372
Affects
microsoft.aspnetcore.dataprotection
| Versions
[10.0.0,10.0.7)
C
Embedded Malicious Code
Affects
kube-health-tools
| Versions
*
C
Embedded Malicious Code
Affects
kube-node-health
| Versions
[0,]
C
Embedded Malicious Code
Affects
xinference
| Versions
[2.6.0]
[2.6.1]
[2.6.2]
H
Arbitrary File Upload
CVE-2026-41269
Affects
flowise-components
| Versions
<3.1.0
H
Arbitrary File Upload
CVE-2026-41269
Affects
flowise
| Versions
<3.1.0
H
Missing Authentication for Critical Function
CVE-2026-41273
Affects
flowise
| Versions
<3.1.0
L
Incorrect Authorization
CVE-2026-41131
Affects
github.com/openfga/openfga/pkg/storage
| Versions
<1.14.1
L
Incorrect Authorization
CVE-2026-41131
Affects
github.com/openfga/openfga/pkg/server/commands
| Versions
<1.14.1
L
Incorrect Authorization
CVE-2026-41131
Affects
github.com/openfga/openfga/pkg/server
| Versions
<1.14.1
L
Incorrect Authorization
CVE-2026-41131
Affects
github.com/openfga/openfga/internal/validation
| Versions
<1.14.1
L
Incorrect Authorization
CVE-2026-41131
Affects
github.com/openfga/openfga/internal/utils
| Versions
<1.14.1
M
Use of Hard-coded Credentials
Affects
flowise
| Versions
<3.1.0
M
Use of Hard-coded Credentials
Affects
flowise
| Versions
<3.1.0
M
Deserialization of Untrusted Data
CVE-2026-25917
Affects
apache-airflow-core
| Versions
[,3.2.0)
H
Missing Authorization
CVE-2026-40870
Affects
decidim-comments
| Versions
<0.30.5
>=0.30.0.rc1, <0.31.1
H
Missing Authorization
CVE-2026-40870
Affects
decidim-api
| Versions
<0.30.5
>=0.30.0.rc1, <0.31.1