Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Arbitrary Command Injection
CVE-2026-5973
Affects
metagpt
| Versions
[0,]
C
SQL Injection
CVE-2026-23696
Affects
wmill
| Versions
>=1.276.0 <1.603.3
H
Missing Authorization
CVE-2026-22683
Affects
wmill
| Versions
>=1.56.0 <1.615.0
H
Missing Authorization
CVE-2026-33318
Affects
@actual-app/sync-server
| Versions
<26.4.0
M
Incorrect Behavior Order: Early Validation
CVE-2026-40923
Affects
github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1
| Versions
<1.11.1
M
Incorrect Behavior Order: Early Validation
CVE-2026-40923
Affects
github.com/tektoncd/pipeline/pkg/apis/pipeline/v1
| Versions
<1.11.1
H
Arbitrary File Upload
CVE-2026-40488
Affects
openmage/magento-lts
| Versions
<20.17.0
C
Not Failing Securely ('Failing Open')
CVE-2026-40525
Affects
openviking
| Versions
[,0.3.9)
M
Use of Incorrectly-Resolved Name or Reference
Affects
astral-tokio-tar
| Versions
<0.6.1
M
Symlink Attack
Affects
astral-tokio-tar
| Versions
<0.6.1
H
SQL Injection
CVE-2026-41496
Affects
praisonai
| Versions
[,4.5.149)
H
SQL Injection
CVE-2026-41496
Affects
praisonaiagents
| Versions
[,1.6.9)
C
Arbitrary Command Injection
CVE-2026-41501
Affects
electerm
| Versions
<3.3.8
M
Cross-site Request Forgery (CSRF)
CVE-2026-42190
Affects
rwsdk
| Versions
>=1.0.0-beta.50 <1.2.3
M
Origin Validation Error
CVE-2026-40594
Affects
pyload-ng
| Versions
[,0.5.0b3.dev98)
H
Incorrect Authorization
Affects
@saltcorn/server
| Versions
<1.4.4
>=1.5.0-beta.0 <1.5.2
>=1.6.0-alpha.0 <1.6.0-beta.1
H
Incorrect Authorization
Affects
@saltcorn/data
| Versions
<1.4.4
>=1.5.0-beta.0 <1.5.2
>=1.6.0-alpha.0 <1.6.0-beta.1
M
Insertion of Sensitive Information into Log File
CVE-2026-42282
Affects
n8n-mcp
| Versions
<2.47.13
H
Sensitive Cookie Without "HttpOnly" Flag
CVE-2026-42239
Affects
@budibase/backend-core
| Versions
<3.35.10
M
Insertion of Sensitive Information into Log File
CVE-2026-41495
Affects
n8n-mcp
| Versions
<2.47.11
H
Infinite loop
Affects
justhtml
| Versions
[,1.17.0)
M
Server-side Request Forgery (SSRF)
CVE-2026-6606
Affects
agentscope
| Versions
[0,]
M
Server-side Request Forgery (SSRF)
CVE-2026-6605
Affects
agentscope
| Versions
[0,]
M
Arbitrary Code Injection
CVE-2026-6603
Affects
agentscope
| Versions
[0,]
M
Server-side Request Forgery (SSRF)
CVE-2026-6604
Affects
agentscope
| Versions
[0,]
H
Arbitrary Code Injection
CVE-2026-39846
Affects
github.com/siyuan-note/siyuan/kernel/sql
| Versions
<3.6.4-dev2
H
Allocation of Resources Without Limits or Throttling
Affects
meridian.mapping
| Versions
[,2.1.1)
H
Allocation of Resources Without Limits or Throttling
Affects
meridian.mediator
| Versions
[,2.1.1)
M
Incorrect Authorization
CVE-2026-35596
Affects
github.com/go-vikunja/vikunja/pkg/models
| Versions
<2.3.0
M
Cross-site Scripting (XSS)
CVE-2026-35600
Affects
github.com/go-vikunja/vikunja/pkg/notifications
| Versions
<2.3.0