Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Prototype Pollution
CVE-2026-30226
Affects
devalue
| Versions
>=4.0.0 <5.6.4
M
Parameter Injection
Affects
tornado
| Versions
[,6.5.5)
H
Directory Traversal
CVE-2026-24457
Affects
org.glassfish.mq:mqbroker-comm
| Versions
[0,]
H
Allocation of Resources Without Limits or Throttling
CVE-2026-31958
Affects
tornado
| Versions
[,6.5.5)
M
Off-by-one Error
CVE-2026-31988
Affects
yauzl
| Versions
>=3.2.0 <3.2.1
H
Command Injection
CVE-2026-29783
Affects
@github/copilot
| Versions
<0.0.423
M
CRLF Injection
CVE-2026-30227
Affects
mimekitlite
| Versions
[,4.15.1)
M
CRLF Injection
CVE-2026-30227
Affects
mimekit
| Versions
[,4.15.1)
H
Incorrect Authorization
CVE-2026-31892
Affects
github.com/argoproj/argo-workflows/v4/workflow/controller
| Versions
>=4.0.0 <4.0.2
H
Incorrect Authorization
CVE-2026-31892
Affects
github.com/argoproj/argo-workflows/workflow/controller
| Versions
>=2.9.0 <3.7.11
>=4.0.0 <4.0.2
H
Cross-site Scripting (XSS)
CVE-2026-29192
Affects
github.com/zitadel/zitadel/internal/notification/types
| Versions
>=4.0.0 <4.12.0
H
Cross-site Scripting (XSS)
CVE-2026-29192
Affects
github.com/zitadel/zitadel/cmd/start
| Versions
>=4.0.0 <4.12.0
H
Cross-site Scripting (XSS)
CVE-2026-29192
Affects
github.com/zitadel/zitadel/internal/notification/handlers
| Versions
>=4.0.0 <4.12.0
H
Cross-site Scripting (XSS)
CVE-2026-29192
Affects
github.com/zitadel/zitadel/internal/command
| Versions
>=4.0.0 <4.12.0
H
Cross-site Scripting (XSS)
CVE-2026-29192
Affects
github.com/zitadel/zitadel/internal/api/ui/login
| Versions
>=4.0.0 <4.12.0
H
Cross-site Scripting (XSS)
CVE-2026-29192
Affects
github.com/zitadel/zitadel/internal/api/http
| Versions
>=4.0.0 <4.12.0
H
Cross-site Scripting (XSS)
CVE-2026-29192
Affects
github.com/zitadel/zitadel/cmd/setup
| Versions
>=4.0.0 <4.12.0
H
Cross-site Scripting (XSS)
CVE-2026-29192
Affects
github.com/zitadel/zitadel/cmd/mirror
| Versions
>=4.0.0 <4.12.0
M
Incorrect Authorization
CVE-2026-3940
Affects
chromium
| Versions
[,146.0.7680.71)
H
User Interface (UI) Misrepresentation of Critical Information
CVE-2026-3935
Affects
chromium
| Versions
[,146.0.7680.71)
M
Use After Free
CVE-2026-3936
Affects
chromium
| Versions
[,146.0.7680.71)
M
Origin Validation Error
CVE-2025-68467
Affects
org.webjars.npm:darkreader
| Versions
[0,]
M
User Interface (UI) Misrepresentation of Critical Information
CVE-2026-3937
Affects
chromium
| Versions
[,146.0.7680.71)
M
Incorrect Authorization
CVE-2026-3939
Affects
chromium
| Versions
[,146.0.7680.71)
M
Incorrect Authorization
CVE-2026-3941
Affects
chrome-devtools-frontend
| Versions
<1.0.1575174
M
Incorrect Authorization
CVE-2026-3941
Affects
chromium
| Versions
[,146.0.7680.71)
C
Malicious Package
Affects
chrono_anchor
| Versions
*
C
Malicious Package
Affects
@kinggupong/libsignal-node
| Versions
*
C
Malicious Package
Affects
mezukabil
| Versions
*
C
Malicious Package
Affects
kinggupong
| Versions
*