Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
L
Uncontrolled Recursion
CVE-2026-39396
Affects
github.com/openbao/openbao/helper/pluginutil
| Versions
<2.5.3
L
Uncontrolled Recursion
CVE-2026-39396
Affects
github.com/openbao/openbao/command/server
| Versions
<2.5.3
L
Improper Certificate Validation
CVE-2026-39388
Affects
github.com/openbao/openbao/builtin/credential/cert
| Versions
<2.5.3
L
Improper Restriction of Security Token Assignment
CVE-2026-40264
Affects
github.com/openbao/openbao/vault
| Versions
<2.5.3
H
Access Control Bypass
CVE-2026-33031
Affects
github.com/0xjacky/nginx-ui/internal/user
| Versions
<2.3.4
H
Access Control Bypass
CVE-2026-33031
Affects
github.com/0xjacky/nginx-ui/api/user
| Versions
<2.3.4
M
Missing Origin Validation in WebSockets
CVE-2026-34403
Affects
github.com/0xjacky/nginx-ui/mcp
| Versions
<2.3.4
M
Missing Origin Validation in WebSockets
CVE-2026-34403
Affects
github.com/0xjacky/nginx-ui/internal/middleware
| Versions
<2.3.4
M
Missing Origin Validation in WebSockets
CVE-2026-34403
Affects
github.com/0xjacky/nginx-ui/api
| Versions
<2.3.4
H
Allocation of Resources Without Limits or Throttling
CVE-2026-40481
Affects
github.com/monetr/monetr/server/controller
| Versions
<1.12.4
M
Cross-site Scripting (XSS)
CVE-2026-40302
Affects
github.com/openziti/zrok/v2/endpoints/publicproxy
| Versions
<2.0.1
M
Cross-site Scripting (XSS)
CVE-2026-40302
Affects
github.com/openziti/zrok/v2/endpoints/dynamicproxy
| Versions
<2.0.1
M
Cross-site Scripting (XSS)
CVE-2026-40302
Affects
github.com/openziti/zrok/endpoints/proxyui
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2026-40302
Affects
github.com/openziti/zrok/v2/endpoints/proxyui
| Versions
<2.0.1
M
Cross-site Scripting (XSS)
CVE-2026-40302
Affects
github.com/openziti/zrok/endpoints/publicproxy
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2026-40302
Affects
github.com/openziti/zrok/endpoints/dynamicproxy
| Versions
>=0.0.0
H
Memory Allocation with Excessive Size Value
CVE-2026-40303
Affects
github.com/openziti/zrok/v2/endpoints/publicproxy
| Versions
<2.0.1
H
Memory Allocation with Excessive Size Value
CVE-2026-40303
Affects
github.com/openziti/zrok/v2/endpoints/dynamicproxy
| Versions
<2.0.1
H
Memory Allocation with Excessive Size Value
CVE-2026-40303
Affects
github.com/openziti/zrok/endpoints/dynamicproxy
| Versions
>=0.0.0
H
Memory Allocation with Excessive Size Value
CVE-2026-40303
Affects
github.com/openziti/zrok/endpoints/publicproxy
| Versions
>=0.0.0
H
Incorrect Ownership Assignment
CVE-2026-40196
Affects
github.com/sysadminsmedia/homebox/backend/app/api
| Versions
<0.25.0
H
Incorrect Ownership Assignment
CVE-2026-40196
Affects
github.com/sysadminsmedia/homebox/backend/internal/core/services
| Versions
<0.25.0
M
Cross-site Scripting (XSS)
CVE-2026-40922
Affects
github.com/siyuan-note/siyuan/kernel/bazaar
| Versions
>=3.6.1 <3.6.4
H
Improper Authorization
CVE-2026-40248
Affects
github.com/free5gc/udr/internal/sbi/processor
| Versions
>=0.0.0
H
Improper Authorization
CVE-2026-40247
Affects
github.com/free5gc/udr/internal/sbi/processor
| Versions
>=0.0.0
H
Use of Externally-Controlled Format String
CVE-2026-3008
Affects
notepad-plus-plus/notepad-plus-plus
| Versions
[,8.9.4)
M
Improper Resource Shutdown or Release
CVE-2026-34317
Affects
mysql/mysql-shell
| Versions
[8.0.0,8.0.46)
[8.4.0,8.4.9)
[9.0.0,]
M
Information Exposure
CVE-2026-34319
Affects
mysql/mysql-shell
| Versions
[8.0.0,8.0.46)
[8.4.0,8.4.9)
[9.0.0,]
M
Information Exposure
CVE-2026-34318
Affects
mysql/mysql-shell
| Versions
[8.0.0,8.0.46)
[8.4.0,8.4.9)
[9.0.0,]
H
Use of Weak Hash
CVE-2026-40164
Affects
stedolan/jq
| Versions
[,1.8.2-rc1)