Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Timing Attack
CVE-2026-5598
Affects
org.bouncycastle:bcprov-debug-jdk14
| Versions
[1.71,1.84)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-3505
Affects
org.bouncycastle:bcpg-jdk18on
| Versions
[,1.84)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-3505
Affects
org.bouncycastle:bcpg-jdk15to18
| Versions
[,1.84)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-3505
Affects
org.bouncycastle:bcpg-jdk14
| Versions
[,1.84)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-3505
Affects
org.bouncycastle:bcpg-debug-jdk18on
| Versions
[,1.84)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-3505
Affects
org.bouncycastle:bcpg-debug-jdk15to18
| Versions
[,1.84)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-3505
Affects
org.bouncycastle:bcpg-debug-jdk14
| Versions
[,1.84)
M
Missing Authorization
CVE-2026-40869
Affects
decidim-budgets
| Versions
>=0.19.0, <0.30.5
>=0.31.0.rc1, <0.31.1
H
Infinite loop
Affects
boazsegev/facil.io
| Versions
[0,]
H
Infinite loop
Affects
iodine
| Versions
>=0.0.1.pre
M
Incorrect Authorization
CVE-2026-6290
Affects
www.velocidex.com/golang/velociraptor/vql/server
| Versions
>=0.2.1
M
Incorrect Authorization
CVE-2026-6290
Affects
www.velocidex.com/golang/velociraptor/vql/tools
| Versions
>=0.2.1
M
Incorrect Authorization
CVE-2026-6290
Affects
www.velocidex.com/golang/velociraptor/paths/artifacts
| Versions
>=0.2.1
M
Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2026-32631
Affects
git-for-windows/git
| Versions
[,2.53.0-3)
M
Incorrect Authorization
CVE-2026-6290
Affects
github.com/velocidex/velociraptor/vql/tools
| Versions
>=0.2.1
M
Incorrect Authorization
CVE-2026-6290
Affects
github.com/velocidex/velociraptor/vql/server
| Versions
>=0.2.1
M
Incorrect Authorization
CVE-2026-6290
Affects
github.com/velocidex/velociraptor/paths/artifacts
| Versions
>=0.2.1
M
Information Exposure
CVE-2025-12141
Affects
github.com/grafana/grafana/pkg/services/sqlstore/migrations
| Versions
<12.4.0
M
Information Exposure
CVE-2025-12141
Affects
github.com/grafana/grafana/pkg/services/ngalert/accesscontrol
| Versions
<12.4.0
H
Arbitrary Code Injection
CVE-2026-30625
Affects
upsonic
| Versions
[,0.72.0)
H
Arbitrary Code Injection
CVE-2026-30617
Affects
langchain-chatchat
| Versions
[0,]
M
Information Exposure
CVE-2026-30778
Affects
org.apache.skywalking:server-core
| Versions
[9.7.0,10.4.0)
H
Out-of-Bounds
Affects
rand
| Versions
>=0.7.0-pre.0 <0.9.3
>=0.10.0-rc.0 <0.10.1
M
Server-side Request Forgery (SSRF)
Affects
github.com/kyverno/kyverno/pkg/engine/apicall
| Versions
>=0.1.0
H
Server-side Request Forgery (SSRF)
CVE-2026-35036
Affects
github.com/lin-snow/ech0/internal/service
| Versions
<4.2.8
H
Server-side Request Forgery (SSRF)
CVE-2026-35036
Affects
github.com/lin-snow/ech0/internal/router
| Versions
<4.2.8
M
Server-side Request Forgery (SSRF)
CVE-2026-5470
Affects
google-search-mcp
| Versions
*
H
Arbitrary Command Injection
CVE-2026-5463
Affects
pymetasploit3
| Versions
[0,]
H
Out-of-bounds Write
Affects
scaly
| Versions
*
H
Out-of-bounds Write
CVE-2026-28815
Affects
apple/swift-crypto
| Versions
>=4.0.0, <4.3.1