Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Improper Check for Certificate Revocation
Affects
rustls-webpki
| Versions
>=0.101.0 <0.103.10
>=0.104.0-alpha.1 <0.104.0-alpha.5
M
UNIX Symbolic Link (Symlink) Following
CVE-2026-33056
Affects
tar
| Versions
<0.4.45
M
Access of Resource Using Incompatible Type ('Type Confusion')
CVE-2026-33055
Affects
tar
| Versions
<0.4.45
L
Interpretation Conflict
CVE-2026-32766
Affects
astral-tokio-tar
| Versions
<0.6.0
H
Use of Out-of-range Pointer Offset
CVE-2026-32829
Affects
lz4_flex
| Versions
<0.11.6
>=0.12.0 <0.12.1
M
Improper Check for Unusual or Exceptional Conditions
Affects
kora-lib
| Versions
<2.0.5
M
Improper Validation of Specified Quantity in Input
Affects
kora-lib
| Versions
<2.0.5
H
Missing Authentication for Critical Function
Affects
zeptoclaw
| Versions
<0.7.6
C
Malicious Package
Affects
tracing-ethers
| Versions
*
H
Uncaught Exception
CVE-2026-32314
Affects
yamux
| Versions
>=0.13.9
H
Integer Overflow or Wraparound
CVE-2026-31814
Affects
yamux
| Versions
>=0.13.0 <0.13.9
M
Missing Cryptographic Step
CVE-2026-32322
Affects
soroban-sdk
| Versions
<22.0.11
>=23.0.0-rc.1 <23.5.3
>=25.0.0-rc.1 <25.3.0
C
Command Injection
CVE-2026-32260
Affects
deno
| Versions
>=2.7.0 <2.7.2
H
Use of Weak Hash
CVE-2026-32129
Affects
soroban-poseidon
| Versions
<25.0.1
H
Missing Authentication for Critical Function
CVE-2026-32231
Affects
zeptoclaw
| Versions
<0.7.6
C
Directory Traversal
CVE-2026-32232
Affects
zeptoclaw
| Versions
<0.7.6
M
Open Redirect
Affects
actix-web-lab
| Versions
<0.26.0
C
Malicious Package
Affects
chrono_anchor
| Versions
*
H
Uncaught Exception
CVE-2026-31812
Affects
quinn-proto
| Versions
>=0.5.0 <0.11.14
C
Use of Low-Level Functionality
CVE-2026-30960
Affects
rssn
| Versions
<0.2.9
M
Allocation of Resources Without Limits or Throttling
CVE-2026-29795
Affects
stellar-xdr
| Versions
<25.0.1
H
Server-side Request Forgery (SSRF)
CVE-2026-29178
Affects
lemmy_routes
| Versions
<0.19.16-beta.1
M
Incorrect Calculation of Buffer Size
Affects
aws-kms-tls-auth
| Versions
<0.0.3
M
Incorrect Conversion between Numeric Types
Affects
soroban-env-host
| Versions
>=0.0.0
H
Command Injection
Affects
zeptoclaw
| Versions
<0.6.2
H
Incorrect Authorization
CVE-2026-27802
Affects
vaultwarden
| Versions
<1.35.4
M
Brute Force
CVE-2026-27801
Affects
vaultwarden
| Versions
<1.35.0
M
Authorization Bypass Through User-Controlled Key
CVE-2026-27898
Affects
vaultwarden
| Versions
<1.35.4
H
Incorrect Authorization
CVE-2026-27803
Affects
vaultwarden
| Versions
<1.35.4
C
Arbitrary Command Injection
Affects
zeptoclaw
| Versions
<0.6.2