Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
C
Malicious Package
Affects
new-mjs-eslint
| Versions
*
C
Malicious Package
Affects
local-ip-helper
| Versions
*
C
Malicious Package
Affects
new-ecro-helper
| Versions
*
C
Malicious Package
Affects
new-eslint-1
| Versions
*
C
Malicious Package
Affects
poly-utils
| Versions
*
C
Malicious Package
Affects
ts-numbering
| Versions
*
C
Malicious Package
Affects
new-solt-1
| Versions
*
C
Malicious Package
Affects
new-ts-helper
| Versions
*
C
Malicious Package
Affects
eslint-helper-1
| Versions
*
M
HTTP Response Splitting
CVE-2026-50188
Affects
getkirby/cms
| Versions
<4.9.4
>=5.0.0-alpha.1, <5.4.4
H
Cross-site Scripting (XSS)
CVE-2026-54002
Affects
getkirby/cms
| Versions
<4.9.4
>=5.0.0-alpha.1, <5.4.4
C
External Initialization of Trusted Variables or Data Stores
CVE-2026-54003
Affects
getkirby/cms
| Versions
<4.9.4
>=5.0.0-alpha.1, <5.4.4
H
Cross-site Scripting (XSS)
CVE-2026-49276
Affects
getkirby/cms
| Versions
<4.9.4
>=5.0.0-alpha.1, <5.4.4
M
Missing Authorization
CVE-2026-54004
Affects
getkirby/cms
| Versions
<4.9.4
>=5.0.0-alpha.1, <5.4.4
H
Missing Authorization
CVE-2026-54005
Affects
getkirby/cms
| Versions
<4.9.4
>=5.0.0-alpha.1, <5.4.4
M
Missing Authorization
CVE-2026-49274
Affects
getkirby/cms
| Versions
<4.9.4
>=5.0.0-alpha.1, <5.4.4
H
Improper Handling of Length Parameter Inconsistency
CVE-2026-48487
Affects
zeroconf
| Versions
[,0.149.16)
C
Deserialization of Untrusted Data
CVE-2026-46495
Affects
org.openidentityplatform.opendj:opendj-server-legacy
| Versions
[,5.1.1)
H
Missing Authorization
CVE-2026-56104
Affects
chainlit
| Versions
[,2.10.1)
H
Deserialization of Untrusted Data
CVE-2025-71344
Affects
picklescan
| Versions
[,0.0.30)
C
Malicious Package
Affects
chai-as-uphelded
| Versions
*
C
Malicious Package
Affects
chai-as-attested
| Versions
*
C
Malicious Package
Affects
libsignal-node-travatiger
| Versions
*
H
Deserialization of Untrusted Data
CVE-2025-71358
Affects
picklescan
| Versions
[,0.0.29)
C
Malicious Package
Affects
datacamp-light
| Versions
*
H
Deserialization of Untrusted Data
CVE-2025-71378
Affects
picklescan
| Versions
[,0.0.30)
H
Deserialization of Untrusted Data
CVE-2025-71357
Affects
picklescan
| Versions
[,0.0.30)
H
Incomplete List of Disallowed Inputs
CVE-2025-71320
Affects
picklescan
| Versions
[,0.0.33)
H
Deserialization of Untrusted Data
CVE-2025-71321
Affects
picklescan
| Versions
[,0.0.33)
H
Deserialization of Untrusted Data
CVE-2025-71322
Affects
picklescan
| Versions
[,0.0.33)