Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Eval Injection
CVE-2026-22666
Affects
dolibarr/dolibarr
| Versions
<23.0.2
H
Logging of Excessive Data
Affects
pocketmine/pocketmine-mp
| Versions
<5.41.1
M
Improper Control of a Resource Through its Lifetime
Affects
pocketmine/pocketmine-mp
| Versions
<5.39.2
H
Allocation of Resources Without Limits or Throttling
Affects
pocketmine/pocketmine-mp
| Versions
<5.39.2
M
Insufficient Control of Network Message Volume (Network Amplification)
Affects
pocketmine/pocketmine-mp
| Versions
<5.39.2
H
Cross-site Scripting (XSS)
CVE-2026-35035
Affects
ci4-cms-erp/ci4ms
| Versions
<0.31.2.0
H
Arbitrary Code Injection
CVE-2026-26026
Affects
glpi/glpi
| Versions
>=11.0.0, <11.0.6
C
SQL Injection
CVE-2026-26263
Affects
glpi/glpi
| Versions
>=11.0.0-alpha, <11.0.6
H
Improper Encoding or Escaping of Output
CVE-2026-25932
Affects
glpi/glpi
| Versions
>=0.60, <10.0.24
>=11.0.0-alpha, <11.0.6
H
SQL Injection
CVE-2026-29047
Affects
glpi/glpi
| Versions
>=10.0.0-beta, <10.0.24
>=11.0.0-alpha, <11.0.6
H
Cross-site Scripting (XSS)
CVE-2026-26027
Affects
glpi/glpi
| Versions
>=11.0.0-alpha, <11.0.6
M
Cross-site Scripting (XSS)
CVE-2026-31350
Affects
feehi/cms
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2026-31352
Affects
feehi/cms
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2026-31353
Affects
feehi/cms
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2026-31354
Affects
feehi/cms
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2026-31313
Affects
feehi/cms
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2026-31351
Affects
feehi/cms
| Versions
>=0.0.0
H
Arbitrary File Upload
CVE-2019-25673
Affects
unisharp/laravel-filemanager
| Versions
>=2.0.0-alpha7
H
Directory Traversal
CVE-2019-25685
Affects
phpbb/phpbb
| Versions
>=3.2.3
M
Deserialization of Untrusted Data
CVE-2026-35537
Affects
roundcube/roundcubemail
| Versions
<1.5.14
>=1.6-beta, <1.6.14
>=1.7-beta, <1.7-rc5
L
Arbitrary Argument Injection
CVE-2026-35538
Affects
roundcube/roundcubemail
| Versions
<1.5.14
>=1.6-beta, <1.6.14
>=1.7-beta, <1.7-rc5
M
Cross-site Scripting (XSS)
CVE-2026-35539
Affects
roundcube/roundcubemail
| Versions
<1.5.14
>=1.6-beta, <1.6.14
>=1.7-beta, <1.7-rc5
L
Access of Resource Using Incompatible Type ('Type Confusion')
CVE-2026-35541
Affects
roundcube/roundcubemail
| Versions
<1.5.14
>=1.6-beta, <1.6.14
>=1.7-beta, <1.7-rc5
M
Incorrect Resource Transfer Between Spheres
CVE-2026-35544
Affects
roundcube/roundcubemail
| Versions
<1.5.14
>=1.6-beta, <1.6.14
>=1.7-beta, <1.7-rc5
M
Incorrect Resource Transfer Between Spheres
CVE-2026-35545
Affects
roundcube/roundcubemail
| Versions
<1.5.15
>=1.6-beta, <1.6.15
>=1.7-beta, <1.7-rc5
M
Incorrect Resource Transfer Between Spheres
CVE-2026-35542
Affects
roundcube/roundcubemail
| Versions
<1.5.14
>=1.6-beta, <1.6.14
>=1.7-beta, <1.7-rc5
M
Server-side Request Forgery (SSRF)
CVE-2026-35540
Affects
roundcube/roundcubemail
| Versions
<1.6.14
>=1.7-beta, <1.7-rc5
M
Incorrect Resource Transfer Between Spheres
CVE-2026-35543
Affects
roundcube/roundcubemail
| Versions
<1.5.14
>=1.6-beta, <1.6.14
>=1.7-beta, <1.7-rc5
M
Cross-site Scripting (XSS)
CVE-2026-5370
Affects
krayin/laravel-crm
| Versions
>=0.0.0
H
SQL Injection
CVE-2026-35470
Affects
devcode-it/openstamanager
| Versions
<2.10.2