Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Allocation of Resources Without Limits or Throttling
CVE-2026-61609
Affects
pterodactyl/panel
| Versions
>=1.7.0, <1.13.0
H
Improper Restriction of Security Token Assignment
CVE-2026-54593
Affects
pterodactyl/panel
| Versions
<1.12.3
M
Server-side Request Forgery (SSRF)
CVE-2026-63107
Affects
limesurvey/limesurvey
| Versions
>=0.0.0
M
Missing Authorization
CVE-2026-63092
Affects
medienbaecker/kirby-modules
| Versions
<5.5.8
M
Cross-site Scripting (XSS)
CVE-2026-26483
Affects
mettle/sendportal
| Versions
>=0.0.0
M
Directory Traversal
CVE-2026-16767
Affects
nelexa/zip
| Versions
>=0.0.0
H
Incorrect Permission Assignment for Critical Resource
CVE-2026-63358
Affects
filegator/filegator
| Versions
<7.14.3
H
Arbitrary Code Injection
CVE-2026-65693
Affects
microweber/microweber
| Versions
>=0.0.0
H
Arbitrary Argument Injection
Affects
pheditor/pheditor
| Versions
<2.0.7
C
Authentication Bypass by Assumed-Immutable Data
Affects
pheditor/pheditor
| Versions
<2.0.8
H
Authorization Bypass Through User-Controlled Key
Affects
poweradmin/poweradmin
| Versions
>=3.0.0, <3.9.11
>=4.0.0, <4.2.5
>=4.3.0, <4.3.4
H
Missing Authorization
Affects
poweradmin/poweradmin
| Versions
>=4.0.0, <4.2.5
>=4.3.0, <4.3.4
H
Improper Authentication
Affects
poweradmin/poweradmin
| Versions
>=4.1.0, <4.2.5
>=4.3.0, <4.3.4
H
Infinite loop
CVE-2026-59933
Affects
phpoffice/phpspreadsheet
| Versions
<1.30.6
>=2.0.0, <2.1.18
>=2.2.0, <2.4.7
>=3.3.0, <3.10.7
>=4.0.0, <5.8.1
H
Server-side Request Forgery (SSRF)
CVE-2026-59931
Affects
phpoffice/phpspreadsheet
| Versions
<1.30.6
>=2.0.0, <2.1.18
>=2.2.0, <2.4.7
>=3.3.0, <3.10.7
>=4.0.0, <5.8.1
H
Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-59932
Affects
phpoffice/phpspreadsheet
| Versions
<1.30.6
>=2.0.0, <2.1.18
>=2.2.0, <2.4.7
>=3.3.0, <3.10.7
>=4.0.0, <5.8.1
M
Denial of Service (DoS)
CVE-2026-59941
Affects
dompdf/dompdf
| Versions
<3.1.6
M
Allocation of Resources Without Limits or Throttling
CVE-2026-59942
Affects
dompdf/dompdf
| Versions
<3.1.6
M
Information Exposure
CVE-2026-59943
Affects
dompdf/dompdf
| Versions
<3.1.6
M
Directory Traversal
CVE-2026-56722
Affects
dompdf/dompdf
| Versions
<3.1.6
L
Directory Traversal
CVE-2026-55554
Affects
dompdf/dompdf
| Versions
<3.1.6
L
Information Exposure
CVE-2026-55555
Affects
dompdf/dompdf
| Versions
<3.1.6
H
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
CVE-2026-65608
Affects
getgrav/grav
| Versions
>=1.7.0, <2.0.9
C
Arbitrary Code Injection
CVE-2026-65008
Affects
getgrav/grav
| Versions
<2.0.7
M
Incorrect Implementation of Authentication Algorithm
CVE-2026-57852
Affects
getgrav/grav
| Versions
<2.0.9
M
Improperly Controlled Sequential Memory Allocation
Affects
guzzlehttp/guzzle
| Versions
<7.15.1
H
Incorrectly Specified Destination in a Communication Channel
Affects
guzzlehttp/guzzle
| Versions
<7.15.1
H
Improper Removal of Sensitive Information Before Storage or Transfer
Affects
guzzlehttp/guzzle
| Versions
<7.15.1
M
Insufficiently Protected Credentials
Affects
guzzlehttp/guzzle
| Versions
<7.14.2
H
Directory Traversal
CVE-2026-65694
Affects
microweber/microweber
| Versions
>=0.0.0