Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Cross-site Request Forgery (CSRF)
CVE-2026-6109
Affects
metagpt
| Versions
[0,]
M
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-6110
Affects
metagpt
| Versions
[0,]
C
Command Injection
CVE-2026-41113
Affects
sagredo-dev/qmail
| Versions
[,2026.04.07)
M
Access Control Bypass
CVE-2025-56015
Affects
genieacs
| Versions
>=0.0.0
M
Arbitrary Code Injection
CVE-2026-5971
Affects
metagpt
| Versions
[0,]
M
Server-side Request Forgery (SSRF)
CVE-2026-40242
Affects
github.com/getarcaneapp/arcane/backend/internal/services
| Versions
<1.17.3
M
Arbitrary Command Injection
CVE-2026-5972
Affects
metagpt
| Versions
[0,]
M
Arbitrary Command Injection
CVE-2026-5974
Affects
metagpt
| Versions
[0,]
H
Improper Handling of Case Sensitivity
Affects
github.com/gotenberg/gotenberg/v8/pkg/modules/exiftool
| Versions
<8.30.0
M
Arbitrary Command Injection
CVE-2026-5973
Affects
metagpt
| Versions
[0,]
C
SQL Injection
CVE-2026-23696
Affects
wmill
| Versions
>=1.276.0 <1.603.3
H
Missing Authorization
CVE-2026-22683
Affects
wmill
| Versions
>=1.56.0 <1.615.0
H
Missing Authorization
CVE-2026-33318
Affects
@actual-app/sync-server
| Versions
<26.4.0
M
Incorrect Behavior Order: Early Validation
CVE-2026-40923
Affects
github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1
| Versions
<1.11.1
M
Incorrect Behavior Order: Early Validation
CVE-2026-40923
Affects
github.com/tektoncd/pipeline/pkg/apis/pipeline/v1
| Versions
<1.11.1
H
Arbitrary File Upload
CVE-2026-40488
Affects
openmage/magento-lts
| Versions
<20.17.0
C
Not Failing Securely ('Failing Open')
CVE-2026-40525
Affects
openviking
| Versions
[,0.3.9)
M
Use of Incorrectly-Resolved Name or Reference
Affects
astral-tokio-tar
| Versions
<0.6.1
M
Symlink Attack
Affects
astral-tokio-tar
| Versions
<0.6.1
H
SQL Injection
CVE-2026-41496
Affects
praisonai
| Versions
[,4.5.149)
H
SQL Injection
CVE-2026-41496
Affects
praisonaiagents
| Versions
[,1.6.9)
C
Arbitrary Command Injection
CVE-2026-41501
Affects
electerm
| Versions
<3.3.8
M
Cross-site Request Forgery (CSRF)
CVE-2026-42190
Affects
rwsdk
| Versions
>=1.0.0-beta.50 <1.2.3
M
Origin Validation Error
CVE-2026-40594
Affects
pyload-ng
| Versions
[,0.5.0b3.dev98)
H
Incorrect Authorization
Affects
@saltcorn/server
| Versions
<1.4.4
>=1.5.0-beta.0 <1.5.2
>=1.6.0-alpha.0 <1.6.0-beta.1
H
Incorrect Authorization
Affects
@saltcorn/data
| Versions
<1.4.4
>=1.5.0-beta.0 <1.5.2
>=1.6.0-alpha.0 <1.6.0-beta.1
M
Insertion of Sensitive Information into Log File
CVE-2026-42282
Affects
n8n-mcp
| Versions
<2.47.13
H
Sensitive Cookie Without "HttpOnly" Flag
CVE-2026-42239
Affects
@budibase/backend-core
| Versions
<3.35.10
M
Insertion of Sensitive Information into Log File
CVE-2026-41495
Affects
n8n-mcp
| Versions
<2.47.11
H
Infinite loop
Affects
justhtml
| Versions
[,1.17.0)