Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Deserialization of Untrusted Data
CVE-2026-1323
Affects
cpsit/typo3-mailqueue
| Versions
<0.4.5
>=0.5.0, <0.5.2
M
Prototype Pollution
CVE-2026-31865
Affects
elysia
| Versions
<1.4.27
L
Missing Authorization
CVE-2026-4202
Affects
ayacoo/redirect-tab
| Versions
<2.1.2
>=3.0.0, <3.1.7
>=4.0.0, <4.0.5
M
Cross-site Scripting (XSS)
CVE-2026-4175
Affects
aureuserp/aureuserp
| Versions
<1.3.0-BETA1
H
Authorization Bypass Through User-Controlled Key
CVE-2026-4208
Affects
ralffreit/mfa-email
| Versions
<2.0.1
H
Authorization Bypass Through User-Controlled Key
CVE-2026-26004
Affects
sentry
| Versions
[0,]
M
Missing Authorization
CVE-2026-32265
Affects
craftcms/aws-s3
| Versions
>=2.0.2, <2.2.5
H
Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-32261
Affects
craftcms/webhooks
| Versions
>=3.0.0-beta.1, <3.2.0
M
Missing Authentication for Critical Function
CVE-2026-32266
Affects
craftcms/google-cloud
| Versions
>=2.0.0-beta.1, <2.2.1
H
Missing Authorization
CVE-2026-32268
Affects
craftcms/azure-blob
| Versions
>=2.0.0-beta.1, <2.1.1
M
Cross-site Scripting (XSS)
CVE-2026-32757
Affects
admidio/admidio
| Versions
<5.0.7
M
Cross-site Request Forgery (CSRF)
CVE-2026-32755
Affects
admidio/admidio
| Versions
<5.0.7
H
Command Injection
CVE-2026-22169
Affects
openclaw
| Versions
<2026.2.22
H
Missing Authorization
CVE-2026-32818
Affects
admidio/admidio
| Versions
>=5.0-Beta.1, <5.0.7
H
Missing Authorization
CVE-2026-32817
Affects
admidio/admidio
| Versions
>=5.0-Beta.1, <5.0.7
M
Server-side Request Forgery (SSRF)
CVE-2026-32812
Affects
admidio/admidio
| Versions
>=5.0-Beta.1, <5.0.7
H
Arbitrary File Upload
CVE-2026-32756
Affects
admidio/admidio
| Versions
<5.0.7
H
Improperly Controlled Sequential Memory Allocation
CVE-2026-32886
Affects
parse-server
| Versions
<8.6.47
>=9.0.0-alpha.1 <9.6.0-alpha.24
H
SQL Injection
CVE-2026-32813
Affects
admidio/admidio
| Versions
<5.0.7
M
Cross-site Request Forgery (CSRF)
CVE-2026-32816
Affects
admidio/admidio
| Versions
>=5.0-Beta.1, <5.0.7
M
Weak Authentication
CVE-2026-33042
Affects
parse-server
| Versions
<8.6.49
>=9.0.0-alpha.1 <9.6.0-alpha.29
H
SQL Injection
CVE-2026-31891
Affects
cockpit-hq/cockpit
| Versions
<2.13.5
M
Cross-site Scripting (XSS)
CVE-2026-33035
Affects
wwbn/avideo
| Versions
>=0.0.0
H
Permissive Cross-domain Policy with Untrusted Domains
CVE-2026-33043
Affects
wwbn/avideo
| Versions
>=0.0.0
L
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-32943
Affects
parse-server
| Versions
<8.6.48
>=9.0.0-alpha.1 <9.6.0-alpha.28
M
Prototype Pollution
CVE-2026-32878
Affects
parse-server
| Versions
<8.6.44
>=9.0.0-alpha.1 <9.6.0-alpha.20
H
Improper Validation of Syntactic Correctness of Input
CVE-2026-32770
Affects
parse-server
| Versions
<8.6.43
>=9.0.0-alpha.1 <9.6.0-alpha.19
M
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-32742
Affects
parse-server
| Versions
<8.6.42
>=9.0.0-alpha.1 <9.6.0-alpha.17
C
Missing Authentication for Critical Function
CVE-2026-33038
Affects
wwbn/avideo
| Versions
>=0.0.0
H
Uncontrolled Recursion
CVE-2026-32944
Affects
parse-server
| Versions
<8.6.45
>=9.0.0-alpha.1 <9.6.0-alpha.21