Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-27128
Affects
craftcms/cms
| Versions
>=4.5.0-RC1, <4.16.19
>=5.0.0-RC1, <5.8.23
M
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-27127
Affects
craftcms/cms
| Versions
>=3.5.0, <4.16.19
>=5.0.0-RC1, <5.8.23
H
Server-side Request Forgery (SSRF)
CVE-2026-27129
Affects
craftcms/cms
| Versions
>=3.5.0, <4.16.19
>=5.0.0-RC1, <5.8.23
M
Cross-site Scripting (XSS)
CVE-2026-27126
Affects
craftcms/cms
| Versions
<4.16.19
>=5.0.0-RC1, <5.8.23
H
Incorrect Privilege Assignment
CVE-2026-27198
Affects
getformwork/formwork
| Versions
>=2.0.0, <2.3.4
M
Cross-site Scripting (XSS)
CVE-2026-27196
Affects
statamic/cms
| Versions
<5.73.9
>=6.0.0-alpha.1, <6.3.2
M
Cross-site Scripting (XSS)
CVE-2026-27568
Affects
wwbn/avideo
| Versions
<21.0
C
Deserialization of Untrusted Data
CVE-2026-27206
Affects
zumba/json-serializer
| Versions
<3.2.3
H
SQL Injection
CVE-2026-26988
Affects
librenms/librenms
| Versions
<26.2.0
M
Cross-site Scripting (XSS)
CVE-2026-26992
Affects
librenms/librenms
| Versions
<26.2.0
M
Cross-site Scripting (XSS)
CVE-2026-26989
Affects
librenms/librenms
| Versions
<26.2.0
M
Improper Encoding or Escaping of Output
CVE-2026-27016
Affects
librenms/librenms
| Versions
>=24.10.0, <26.2.0
H
SQL Injection
CVE-2026-26990
Affects
librenms/librenms
| Versions
<26.2.0
M
Cross-site Scripting (XSS)
CVE-2026-26987
Affects
librenms/librenms
| Versions
<26.2.0
M
Cross-site Scripting (XSS)
CVE-2026-26991
Affects
librenms/librenms
| Versions
<26.2.0
H
Authorization Bypass Through User-Controlled Key
CVE-2026-26016
Affects
pterodactyl/panel
| Versions
<1.12.1
H
Insufficient Session Expiration
Affects
pterodactyl/panel
| Versions
<1.12.1
C
Weak Password Recovery Mechanism for Forgotten Password
CVE-2026-26273
Affects
idno/known
| Versions
<1.6.3
M
Missing Authorization
CVE-2025-70866
Affects
lavalite/cms
| Versions
>=10.1.0
M
Cross-site Scripting (XSS)
CVE-2018-25157
Affects
phraseanet/phraseanet
| Versions
<4.0.7
H
Deserialization of Untrusted Data
Affects
cesargb/laravel-magiclink
| Versions
>=2.0.0, <2.25.1
H
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-2469
Affects
directorytree/imapengine
| Versions
<1.22.3
C
Cross-site Scripting (XSS)
CVE-2026-25759
Affects
statamic/cms
| Versions
>=6.0.0, <6.2.3
M
Missing Authorization
CVE-2026-25633
Affects
statamic/cms
| Versions
<5.73.6
>=6.0.0-alpha.1, <6.2.5
H
Authorization Bypass Through User-Controlled Key
CVE-2026-25497
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.16.18
>=5.0.0-RC1, <5.8.22
H
Server-side Request Forgery (SSRF)
CVE-2026-25493
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.16.18
>=5.0.0-RC1, <5.8.22
M
Server-side Request Forgery (SSRF)
CVE-2026-25494
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.16.18
>=5.0.0-RC1, <5.8.22
L
Cross-site Scripting (XSS)
CVE-2026-25491
Affects
craftcms/cms
| Versions
>=5.0.0-RC1, <5.8.22
H
SQL Injection
CVE-2026-25495
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.16.18
>=5.0.0-RC1, <5.8.22
M
Server-side Request Forgery (SSRF)
CVE-2026-25492
Affects
craftcms/cms
| Versions
>=3.5.0, <4.16.18
>=5.0.0-RC1, <5.8.22