Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
SQL Injection
CVE-2026-23969
Affects
apache-superset
| Versions
[,4.1.2)
H
Out-of-bounds Read
CVE-2026-21863
Affects
valkey-io/valkey
| Versions
[,7.2.12)
[8.0.0-rc1,8.0.7)
[8.1.0-rc1,8.1.6)
[9.0.0-rc1,9.0.2)
M
Modification of Assumed-Immutable Data (MAID)
CVE-2025-67733
Affects
valkey-io/valkey
| Versions
[,7.2.12)
[8.0.0-rc1,8.0.7)
[8.1.0-rc1,8.1.6)
[9.0.0-rc1,9.0.2)
H
Command Injection
CVE-2026-27965
Affects
vitess.io/vitess/go/vt/mysqlctl
| Versions
<22.0.4
>=23.0.0-rc1 <23.0.3
H
Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-27809
Affects
psd-tools
| Versions
[,1.12.2)
C
Use of a Broken or Risky Cryptographic Algorithm
CVE-2026-27804
Affects
parse-server
| Versions
<8.6.3
>=9.0.0-alpha.1 <9.3.1-alpha.4
H
Command Injection
CVE-2026-27965
Affects
github.com/vitessio/vitess/go/vt/mysqlctl
| Versions
<22.0.4
>=23.0.0-rc1 <23.0.3
C
Directory Traversal
CVE-2026-27969
Affects
vitess.io/vitess/go/vt
| Versions
>=0.0.0
C
Directory Traversal
CVE-2026-27969
Affects
github.com/vitessio/vitess/go/vt
| Versions
>=0.0.0
H
Reachable Assertion
CVE-2026-27623
Affects
valkey-io/valkey
| Versions
[9.0.0,9.0.3)
C
Arbitrary Code Injection
CVE-2026-27966
Affects
lfx
| Versions
[0,]
M
Server-side Request Forgery (SSRF)
CVE-2026-27829
Affects
astro
| Versions
<5.17.3
L
Reusing a Nonce, Key Pair in Encryption
CVE-2026-3099
Affects
libsoup
| Versions
[0,]
M
Open Redirect
CVE-2026-27738
Affects
@angular/ssr
| Versions
>=19.0.0-next.0 <19.2.21
>=20.0.0-next.0 <20.3.17
>=21.0.0-next.0 <21.1.5
>=21.2.0-next.0 <21.2.0-rc.0
C
Server-side Request Forgery (SSRF)
CVE-2026-27739
Affects
@angular-devkit/build-angular
| Versions
<19.2.21
>=20.0.0-next.0 <20.3.17
>=21.0.0-next.0 <21.1.5
>=21.2.0-next.0 <21.2.0-rc.0
C
Server-side Request Forgery (SSRF)
CVE-2026-27739
Affects
@angular/ssr
| Versions
<19.2.21
>=20.0.0-next.0 <20.3.17
>=21.0.0-next.0 <21.1.5
>=21.2.0-next.0 <21.2.0-rc.0
C
Server-side Request Forgery (SSRF)
CVE-2026-27739
Affects
@schematics/angular
| Versions
<19.2.21
>=20.0.0-next.0 <20.3.17
>=21.0.0-next.0 <21.1.5
>=21.2.0-next.0 <21.2.0-rc.0
C
Server-side Request Forgery (SSRF)
CVE-2026-27739
Affects
@angular/build
| Versions
<19.2.21
>=20.0.0-next.0 <20.3.17
>=21.0.0-next.0 <21.1.5
>=21.2.0-next.0 <21.2.0-rc.0
M
Server-side Request Forgery (SSRF)
CVE-2026-27795
Affects
@langchain/community
| Versions
<1.1.18
M
NULL Pointer Dereference
CVE-2025-61143
Affects
libtiff
| Versions
[,4.7.1)
M
NULL Pointer Dereference
CVE-2025-61143
Affects
libtiff
| Versions
[,4.7.1-rc1)
M
Cross-site Scripting (XSS)
CVE-2026-27901
Affects
org.webjars.npm:svelte
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2026-27901
Affects
svelte
| Versions
<5.53.5
M
Double Free
CVE-2025-61145
Affects
libtiff
| Versions
[,4.7.1)
M
Double Free
CVE-2025-61145
Affects
libtiff
| Versions
[,4.7.1-rc1)
M
Cross-site Scripting (XSS)
CVE-2026-27902
Affects
svelte
| Versions
>=5.53.0 <5.53.5
H
User Impersonation
CVE-2026-27700
Affects
hono
| Versions
>=4.12.0 <4.12.2
H
Deserialization of Untrusted Data
CVE-2026-27794
Affects
langgraph-checkpoint
| Versions
[,4.0.0)
H
Arbitrary Code Injection
CVE-2026-27148
Affects
storybook
| Versions
<7.6.23
>=8.0.0-alpha.0 <8.6.17
>=9.0.0-alpha.0 <9.1.19
>=10.0.0-beta.0 <10.2.10
H
Use After Free
CVE-2021-37977
Affects
v8/v8
| Versions
[,9.6.155)