Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Improper Neutralization of Special Elements in Data Query Logic
CVE-2026-54019
Affects
open-webui
| Versions
[,0.9.6)
H
Protection Mechanism Failure
CVE-2026-54013
Affects
open-webui
| Versions
[,0.9.6)
M
Authorization Bypass Through User-Controlled Key
CVE-2026-54006
Affects
open-webui
| Versions
[,0.9.6)
H
UNIX Symbolic Link (Symlink) Following
CVE-2026-55447
Affects
lfx
| Versions
[,0.4.2)
M
Directory Traversal
CVE-2026-54014
Affects
open-webui
| Versions
[,0.9.6)
M
Authorization Bypass Through User-Controlled Key
CVE-2026-54015
Affects
open-webui
| Versions
[,0.9.6)
H
Authorization Bypass Through User-Controlled Key
CVE-2026-54009
Affects
open-webui
| Versions
[,0.9.6)
H
Origin Validation Error
CVE-2026-54007
Affects
open-webui
| Versions
[,0.9.6)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-55446
Affects
langflow-base
| Versions
[, 0.0.97)
H
Missing Authorization
CVE-2026-54012
Affects
open-webui
| Versions
[,0.9.6)
H
Cross-site Scripting (XSS)
CVE-2026-54011
Affects
open-webui
| Versions
[,0.9.6)
M
Missing Authorization
CVE-2026-54016
Affects
open-webui
| Versions
[,0.9.6)
M
Insufficient Session Expiration
CVE-2026-55423
Affects
lfx
| Versions
[,0.2.1)
M
Insufficient Session Expiration
CVE-2026-55423
Affects
langflow-base
| Versions
[,0.6.7)
H
Missing Authorization
CVE-2026-54010
Affects
open-webui
| Versions
[,0.9.6)
H
Server-side Request Forgery (SSRF)
CVE-2026-54008
Affects
open-webui
| Versions
[,0.9.6)
H
Uncontrolled Recursion
CVE-2026-54297
Affects
faraday
| Versions
<2.14.3
L
Missing Release of Resource after Effective Lifetime
CVE-2026-54786
Affects
wasmtime-wasi
| Versions
<24.0.10
>=25.0.0 <36.0.11
>=37.0.0 <44.0.3
>=45.0.0 <45.0.2
M
Cross-site Scripting (XSS)
CVE-2026-55847
Affects
io.qameta.allure:allure-generator
| Versions
[,2.39.0)
H
Missing Authentication for Critical Function
CVE-2026-55450
Affects
lfx
| Versions
[,0.4.2)
H
Missing Authentication for Critical Function
CVE-2026-55450
Affects
langflow-base
| Versions
[,0.9.2)
H
Command Injection
CVE-2026-48723
Affects
browserstack-cypress-cli
| Versions
>=1.22.0 <1.36.6
M
Directory Traversal
CVE-2026-42867
Affects
langflow-base
| Versions
[,0.9.2)
H
Authorization Bypass Through User-Controlled Key
CVE-2026-33760
Affects
langflow-base
| Versions
[,0.9.2)
H
Arbitrary Code Injection
CVE-2026-48519
Affects
langflow
| Versions
[,1.9.2)
H
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-54777
Affects
corewcf.netnamedpipe
| Versions
[1.4.0-preview1,1.8.1)
[1.9.0, 1.9.1)
M
External Control of File Name or Path
CVE-2026-48520
Affects
lfx
| Versions
[,1.10.0)
M
Expired Pointer Dereference
CVE-2026-54778
Affects
corewcf.unixdomainsocket
| Versions
[1.5.0-preview1,1.8.1)
[1.9.0,1.9.1)
M
Incorrect Authorization
CVE-2026-32967
Affects
org.apache.dolphinscheduler:dolphinscheduler-api
| Versions
[,3.4.2)
M
Incorrect Authorization
CVE-2026-41280
Affects
org.apache.dolphinscheduler:dolphinscheduler-api
| Versions
[,3.4.2)