Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
UNIX Symbolic Link (Symlink) Following
CVE-2026-5223
Affects
cargo
| Versions
>=0.0.0
L
Use of Non-Canonical URL Paths for Authorization Decisions
CVE-2026-5222
Affects
cargo
| Versions
>=0.0.0
H
Access Control Bypass
CVE-2026-47261
Affects
wasmtime-wasi
| Versions
<24.0.9
>=25.0.0 <36.0.10
>=37.0.0 <44.0.2
H
Allocation of Resources Without Limits or Throttling
CVE-2026-46673
Affects
russh-cryptovec
| Versions
<0.60.3
H
Allocation of Resources Without Limits or Throttling
CVE-2026-46673
Affects
russh
| Versions
<0.60.3
M
Reachable Assertion
CVE-2026-46542
Affects
nimiq-keys
| Versions
<1.4.0
M
Directory Traversal
CVE-2026-46671
Affects
onenote_parser
| Versions
<1.1.1
H
Use of a Cryptographic Primitive with a Risky Implementation
CVE-2026-46654
Affects
p3-challenger
| Versions
<0.4.3
>=0.5.0 <0.5.3
H
Unchecked Return Value
CVE-2026-40092
Affects
nimiq-keys
| Versions
<1.4.0
H
Improper Verification of Cryptographic Signature
Affects
libcrux-ml-dsa
| Versions
<0.0.9
M
Symlink Attack
CVE-2026-46703
Affects
boxlite-cli
| Versions
<0.9.0
M
Symlink Attack
CVE-2026-46703
Affects
boxlite
| Versions
<0.9.0
H
Improper Isolation or Compartmentalization
CVE-2026-46695
Affects
boxlite-cli
| Versions
<0.9.0
H
Improper Isolation or Compartmentalization
CVE-2026-46695
Affects
boxlite
| Versions
<0.9.0
M
Reliance on Data/Memory Layout
Affects
diesel
| Versions
<2.3.8
M
Heap-based Buffer Overflow
CVE-2026-45784
Affects
openssl
| Versions
>=0.10.50 <0.10.80
H
Directory Traversal
CVE-2026-22810
Affects
one2html
| Versions
<1.3.1
H
Incorrect Authorization
Affects
anchor-lang
| Versions
>=1.0.0-rc.1 <1.0.0-rc.2
H
Incorrect Authorization
CVE-2026-45137
Affects
anchor-lang
| Versions
>=1.0.0-rc.1 <1.0.2
M
Access of Resource Using Incompatible Type ('Type Confusion')
Affects
astral-tokio-tar
| Versions
<0.6.2
M
Directory Traversal
CVE-2026-7645
Affects
sublinear
| Versions
<0.2.0
M
Improper Validation of Specified Quantity in Input
Affects
oxidize-pdf
| Versions
<2.6.0
H
Arbitrary Code Injection
CVE-2026-45374
Affects
deepseek-tui
| Versions
<0.8.26
H
Server-side Request Forgery (SSRF)
CVE-2026-45373
Affects
deepseek-tui
| Versions
<0.8.26
H
Arbitrary Code Injection
CVE-2026-45311
Affects
deepseek-tui
| Versions
>=0.3.0 <0.8.23
H
Server-side Request Forgery (SSRF)
CVE-2026-45310
Affects
deepseek-tui
| Versions
<0.8.22
H
Incorrect Authorization
CVE-2026-43913
Affects
vaultwarden
| Versions
<1.35.5
H
Improper Protection Against Voltage and Clock Glitches
Affects
anchor-lang
| Versions
<1.0.0-rc.3
H
Uncaught Exception
Affects
libcrux-chacha20poly1305
| Versions
<0.0.8
H
Insufficient Session Expiration
CVE-2026-43911
Affects
vaultwarden
| Versions
<1.35.5