Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
C
Arbitrary Command Injection
CVE-2026-41501
Affects
electerm
| Versions
<3.3.8
M
Cross-site Request Forgery (CSRF)
CVE-2026-42190
Affects
rwsdk
| Versions
>=1.0.0-beta.50 <1.2.3
M
Origin Validation Error
CVE-2026-40594
Affects
pyload-ng
| Versions
[,0.5.0b3.dev98)
H
Incorrect Authorization
Affects
@saltcorn/server
| Versions
<1.4.4
>=1.5.0-beta.0 <1.5.2
>=1.6.0-alpha.0 <1.6.0-beta.1
H
Incorrect Authorization
Affects
@saltcorn/data
| Versions
<1.4.4
>=1.5.0-beta.0 <1.5.2
>=1.6.0-alpha.0 <1.6.0-beta.1
M
Insertion of Sensitive Information into Log File
CVE-2026-42282
Affects
n8n-mcp
| Versions
<2.47.13
H
Sensitive Cookie Without "HttpOnly" Flag
CVE-2026-42239
Affects
@budibase/backend-core
| Versions
<3.35.10
M
Insertion of Sensitive Information into Log File
CVE-2026-41495
Affects
n8n-mcp
| Versions
<2.47.11
H
Infinite loop
Affects
justhtml
| Versions
[,1.17.0)
M
Server-side Request Forgery (SSRF)
CVE-2026-6606
Affects
agentscope
| Versions
[0,]
M
Server-side Request Forgery (SSRF)
CVE-2026-6605
Affects
agentscope
| Versions
[0,]
M
Arbitrary Code Injection
CVE-2026-6603
Affects
agentscope
| Versions
[0,]
M
Server-side Request Forgery (SSRF)
CVE-2026-6604
Affects
agentscope
| Versions
[0,]
H
Arbitrary Code Injection
CVE-2026-39846
Affects
github.com/siyuan-note/siyuan/kernel/sql
| Versions
<3.6.4-dev2
H
Allocation of Resources Without Limits or Throttling
Affects
meridian.mapping
| Versions
[,2.1.1)
H
Allocation of Resources Without Limits or Throttling
Affects
meridian.mediator
| Versions
[,2.1.1)
M
Incorrect Authorization
CVE-2026-35596
Affects
github.com/go-vikunja/vikunja/pkg/models
| Versions
<2.3.0
M
Cross-site Scripting (XSS)
CVE-2026-35600
Affects
github.com/go-vikunja/vikunja/pkg/notifications
| Versions
<2.3.0
M
Cross-site Scripting (XSS)
CVE-2026-35600
Affects
github.com/go-vikunja/vikunja/pkg/modules/migration/handler
| Versions
<2.3.0
M
Cross-site Scripting (XSS)
CVE-2026-35600
Affects
github.com/go-vikunja/vikunja/pkg/models
| Versions
<2.3.0
H
Inefficient Algorithmic Complexity
CVE-2026-35599
Affects
github.com/go-vikunja/vikunja/pkg/models
| Versions
<2.3.0
M
Incorrect Authorization
CVE-2026-40103
Affects
github.com/go-vikunja/vikunja/pkg/models
| Versions
<2.3.0
M
CRLF Injection
CVE-2026-35601
Affects
github.com/go-vikunja/vikunja/pkg/caldav
| Versions
<2.3.0
H
Allocation of Resources Without Limits or Throttling
CVE-2026-40980
Affects
org.springframework.ai:spring-ai-pdf-document-reader
| Versions
[,1.0.6)
[1.1.0-M1, 1.1.5)
M
Insufficiently Protected Credentials
CVE-2026-40979
Affects
org.springframework.ai:spring-ai-autoconfigure-model-transformers
| Versions
[,1.0.6)
[1.1.0-M1, 1.1.5)
H
SQL Injection
CVE-2026-40978
Affects
org.springframework.ai:spring-ai-azure-cosmos-db-store
| Versions
[,1.0.6)
[1.1.0-M1, 1.1.5)
H
Improper Certificate Validation
CVE-2026-4740
Affects
github.com/open-cluster-management-io/ocm/pkg/registration/register
| Versions
<1.2.1
H
Arbitrary Code Injection
CVE-2026-6357
Affects
pip
| Versions
[22.1b1, 26.1)
H
Allocation of Resources Without Limits or Throttling
Affects
github.com/platform-mesh/kubernetes-graphql-gateway/gateway/gateway/endpoint
| Versions
<1.2.9
M
Insertion of Sensitive Information into Log File
Affects
github.com/cloudnativelabs/kube-router/v2/pkg/controllers/routing
| Versions
>=2.7.0 <2.9.0