Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Out-of-bounds Read
CVE-2025-54070
Affects
@openzeppelin/contracts
| Versions
>=5.2.0 <5.4.0
M
Out-of-bounds Read
CVE-2024-27094
Affects
@openzeppelin/contracts
| Versions
>=4.5.0 <4.9.6
>=5.0.0-rc.0 <5.0.2
M
Always-Incorrect Control Flow Implementation
CVE-2023-49798
Affects
@openzeppelin/contracts
| Versions
>=4.9.4 <4.9.5
M
Improper Encoding or Escaping of Output
CVE-2023-40014
Affects
@openzeppelin/contracts
| Versions
>=4.0.0 <4.9.3
M
Improper Input Validation
CVE-2023-34459
Affects
@openzeppelin/contracts
| Versions
>=4.7.0 <4.9.2
L
Missing Authorization
CVE-2023-34234
Affects
@openzeppelin/contracts
| Versions
>=4.3.0 <4.9.1
L
Denial of Service (DoS)
CVE-2023-30541
Affects
@openzeppelin/contracts
| Versions
>=3.2.0 <4.8.3
M
Improper Input Validation
CVE-2023-30542
Affects
@openzeppelin/contracts
| Versions
>=4.3.0 <4.8.3
M
Incorrect Calculation
CVE-2023-26488
Affects
@openzeppelin/contracts
| Versions
>=4.8.0 <4.8.2
M
Incorrect Calculation
CVE-2023-26488
Affects
@openzeppelin/contracts
| Versions
>=4.8.0 <4.8.2
H
Improper Verification of Cryptographic Signature
CVE-2022-35961
Affects
@openzeppelin/contracts
| Versions
<4.7.3
M
Denial of Service (DoS)
CVE-2022-35915
Affects
@openzeppelin/contracts
| Versions
>=2.3.0 <4.7.2
L
Incorrect Resource Transfer Between Spheres
CVE-2022-35916
Affects
@openzeppelin/contracts
| Versions
>=4.6.0 <4.7.2
H
Incorrect Calculation
CVE-2022-31198
Affects
@openzeppelin/contracts
| Versions
>=4.3.0 <4.7.2
H
Information Exposure
CVE-2022-31172
Affects
@openzeppelin/contracts
| Versions
>=4.1.0 <4.7.1
H
Information Exposure
CVE-2022-31170
Affects
@openzeppelin/contracts
| Versions
>=4.0.0 <4.7.1
M
Function Call With Incorrect Argument
Affects
@openzeppelin/contracts
| Versions
>=4.3.0 <4.4.2
H
Deserialization of Untrusted Data
CVE-2021-46320
Affects
@openzeppelin/contracts
| Versions
>=3.2.0 <4.4.1
H
Deserialization of Untrusted Data
CVE-2022-39384
Affects
@openzeppelin/contracts
| Versions
>=3.2.0 <4.4.1
M
Numeric Errors
Affects
@openzeppelin/contracts
| Versions
>=4.2.0 <4.3.3
C
Improper Initialization
CVE-2021-41264
Affects
@openzeppelin/contracts
| Versions
>=4.1.0 <4.3.2
H
Improper Input Validation
Affects
@openzeppelin/contracts
| Versions
>=4.1.0 <4.3.2
C
Privilege Escalation
CVE-2021-39167
Affects
@openzeppelin/contracts
| Versions
>=4.0.0-beta.0 <4.3.1
<3.4.2
M
Improper Synchronization
Affects
@openzeppelin/contracts
| Versions
<3.4.0-rc.0
M
Out-of-bounds Read
CVE-2025-54070
Affects
@openzeppelin/contracts-upgradeable
| Versions
>=5.2.0 <5.4.0
M
Out-of-bounds Read
CVE-2024-27094
Affects
@openzeppelin/contracts-upgradeable
| Versions
>=4.5.0 <4.9.6
>=5.0.0-rc.0 <5.0.2
M
Always-Incorrect Control Flow Implementation
CVE-2023-49798
Affects
@openzeppelin/contracts-upgradeable
| Versions
>=4.9.4 <4.9.5
M
Improper Encoding or Escaping of Output
CVE-2023-40014
Affects
@openzeppelin/contracts-upgradeable
| Versions
>=4.0.0 <4.9.3
M
Improper Input Validation
CVE-2023-34459
Affects
@openzeppelin/contracts-upgradeable
| Versions
>=4.7.0 <4.9.2
L
Missing Authorization
CVE-2023-34234
Affects
@openzeppelin/contracts-upgradeable
| Versions
>=4.3.0 <4.9.1