Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Out-of-bounds Read
CVE-2025-54070
Affects
@openzeppelin/contracts
| Versions
>=5.2.0 <5.4.0
M
Out-of-bounds Read
CVE-2024-27094
Affects
@openzeppelin/contracts
| Versions
>=4.5.0 <4.9.6
>=5.0.0-rc.0 <5.0.2
M
Always-Incorrect Control Flow Implementation
CVE-2023-49798
Affects
@openzeppelin/contracts
| Versions
>=4.9.4 <4.9.5
M
Improper Encoding or Escaping of Output
CVE-2023-40014
Affects
@openzeppelin/contracts
| Versions
>=4.0.0 <4.9.3
M
Improper Input Validation
CVE-2023-34459
Affects
@openzeppelin/contracts
| Versions
>=4.7.0 <4.9.2
L
Missing Authorization
CVE-2023-34234
Affects
@openzeppelin/contracts
| Versions
>=4.3.0 <4.9.1
L
Denial of Service (DoS)
CVE-2023-30541
Affects
@openzeppelin/contracts
| Versions
>=3.2.0 <4.8.3
M
Improper Input Validation
CVE-2023-30542
Affects
@openzeppelin/contracts
| Versions
>=4.3.0 <4.8.3
M
Incorrect Calculation
CVE-2023-26488
Affects
@openzeppelin/contracts
| Versions
>=4.8.0 <4.8.2
M
Incorrect Calculation
CVE-2023-26488
Affects
@openzeppelin/contracts
| Versions
>=4.8.0 <4.8.2
H
Improper Verification of Cryptographic Signature
CVE-2022-35961
Affects
@openzeppelin/contracts
| Versions
<4.7.3
M
Denial of Service (DoS)
CVE-2022-35915
Affects
@openzeppelin/contracts
| Versions
>=2.3.0 <4.7.2
L
Incorrect Resource Transfer Between Spheres
CVE-2022-35916
Affects
@openzeppelin/contracts
| Versions
>=4.6.0 <4.7.2
H
Incorrect Calculation
CVE-2022-31198
Affects
@openzeppelin/contracts
| Versions
>=4.3.0 <4.7.2
H
Information Exposure
CVE-2022-31172
Affects
@openzeppelin/contracts
| Versions
>=4.1.0 <4.7.1
H
Information Exposure
CVE-2022-31170
Affects
@openzeppelin/contracts
| Versions
>=4.0.0 <4.7.1
M
Function Call With Incorrect Argument
Affects
@openzeppelin/contracts
| Versions
>=4.3.0 <4.4.2
H
Deserialization of Untrusted Data
CVE-2022-39384
Affects
@openzeppelin/contracts
| Versions
>=3.2.0 <4.4.1
H
Deserialization of Untrusted Data
CVE-2021-46320
Affects
@openzeppelin/contracts
| Versions
>=3.2.0 <4.4.1
M
Numeric Errors
Affects
@openzeppelin/contracts
| Versions
>=4.2.0 <4.3.3
C
Improper Initialization
CVE-2021-41264
Affects
@openzeppelin/contracts
| Versions
>=4.1.0 <4.3.2
H
Improper Input Validation
Affects
@openzeppelin/contracts
| Versions
>=4.1.0 <4.3.2
C
Privilege Escalation
CVE-2021-39167
Affects
@openzeppelin/contracts
| Versions
>=4.0.0-beta.0 <4.3.1
<3.4.2
M
Improper Synchronization
Affects
@openzeppelin/contracts
| Versions
<3.4.0-rc.0
M
Out-of-bounds Read
CVE-2025-54070
Affects
@openzeppelin/contracts-upgradeable
| Versions
>=5.2.0 <5.4.0
M
Out-of-bounds Read
CVE-2024-27094
Affects
@openzeppelin/contracts-upgradeable
| Versions
>=4.5.0 <4.9.6
>=5.0.0-rc.0 <5.0.2
M
Always-Incorrect Control Flow Implementation
CVE-2023-49798
Affects
@openzeppelin/contracts-upgradeable
| Versions
>=4.9.4 <4.9.5
M
Improper Encoding or Escaping of Output
CVE-2023-40014
Affects
@openzeppelin/contracts-upgradeable
| Versions
>=4.0.0 <4.9.3
M
Improper Input Validation
CVE-2023-34459
Affects
@openzeppelin/contracts-upgradeable
| Versions
>=4.7.0 <4.9.2
L
Missing Authorization
CVE-2023-34234
Affects
@openzeppelin/contracts-upgradeable
| Versions
>=4.3.0 <4.9.1