Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Incorrect Authorization
CVE-2026-46636
Affects
twig/twig
| Versions
<3.27.0
L
Incorrect Authorization
CVE-2026-48806
Affects
twig/twig
| Versions
<3.27.0
M
Incorrect Authorization
CVE-2026-48808
Affects
twig/twig
| Versions
<3.27.0
L
Incorrect Authorization
CVE-2026-48805
Affects
twig/twig
| Versions
<3.27.0
M
Missing Authorization
CVE-2026-31266
Affects
craftcms/cms
| Versions
>=0.0.0
M
Improper Validation of Specified Index, Position, or Offset in Input
CVE-2026-48807
Affects
twig/twig
| Versions
<3.27.0
M
Cross-site Scripting (XSS)
CVE-2026-47759
Affects
tinymce/tinymce
| Versions
<7.9.3
>=8.0.0, <8.5.1
M
Cross-site Scripting (XSS)
CVE-2026-47760
Affects
tinymce/tinymce
| Versions
>=6.8.0, <7.1.0
M
Cross-site Scripting (XSS)
CVE-2026-47762
Affects
tinymce/tinymce
| Versions
<7.9.3
>=8.0.0, <8.5.1
M
Cross-site Scripting (XSS)
CVE-2026-47761
Affects
tinymce/tinymce
| Versions
<7.9.3
>=8.0.0, <8.5.1
M
Improper Verification of Cryptographic Signature
CVE-2026-48747
Affects
symfony/symfony
| Versions
<7.4.13
>=8.0.0-BETA1, <8.0.13
M
Improper Encoding or Escaping of Output
CVE-2026-48784
Affects
symfony/symfony
| Versions
<5.4.53
>=6.0.0-BETA1, <6.4.41
>=7.0.0-BETA1, <7.4.13
>=8.0.0-BETA1, <8.0.13
M
Improper Encoding or Escaping of Output
CVE-2026-48760
Affects
symfony/symfony
| Versions
<6.4.41
>=7.0.0-BETA1, <7.4.13
>=8.0.0-BETA1, <8.0.13
M
Cross-site Scripting (XSS)
CVE-2026-48761
Affects
symfony/symfony
| Versions
<6.4.41
>=7.0.0-BETA1, <7.4.13
>=8.0.0-BETA1, <8.0.13
H
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-48489
Affects
symfony/symfony
| Versions
<5.4.53
>=6.0.0-BETA1, <6.4.41
>=7.0.0-BETA1, <7.4.13
>=8.0.0-BETA1, <8.0.13
H
Server-side Request Forgery (SSRF)
CVE-2026-48736
Affects
symfony/symfony
| Versions
<5.4.53
>=6.0.0-BETA1, <6.4.41
>=7.0.0-BETA1, <7.4.13
>=8.0.0-BETA1, <8.0.13
M
Incorrect Comparison
CVE-2026-46644
Affects
symfony/polyfill-intl-idn
| Versions
>=1.17.1, <1.38.1
H
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-6366
Affects
drupal/core
| Versions
<10.5.9
>=10.6.0-beta1, <10.6.7
>=11.0.0-alpha1, <11.2.11
>=11.3.0-alpha1, <11.3.7
H
Deserialization of Untrusted Data
CVE-2026-8727
Affects
tomasnorre/crawler
| Versions
<11.0.13
>=12.0.0, <12.0.11
H
SQL Injection
CVE-2026-8827
Affects
friendsoftypo3/tt-address
| Versions
<8.1.2
>=9.0.0, <9.1.1
>=10.0.0, <10.0.1
C
Deserialization of Untrusted Data
CVE-2026-46725
Affects
mmc/ceselector
| Versions
<3.0.3
>=4.0.0, <4.0.2
>=5.0.0, <5.0.1
>=6.0.0, <6.0.1
M
Authorization Bypass Through User-Controlled Key
CVE-2026-46721
Affects
evoweb/sf-register
| Versions
<13.2.4
>=14.0.0, <14.0.2
H
SQL Injection
CVE-2026-8726
Affects
georgringer/news
| Versions
<9.4.1
>=10.0.0, <10.0.4
>=11.0.0, <11.4.4
>=12.0.0, <12.3.2
>=13.0.0, <13.0.2
>=14.0.0, <14.0.3
M
Directory Traversal
CVE-2026-46724
Affects
tpwd/ke_search
| Versions
<5.6.2
>=6.0.0, <6.6.1
>=7.0.0, <7.0.1
M
XML External Entity (XXE) Injection
CVE-2026-46722
Affects
tpwd/ke_search
| Versions
<5.6.2
>=6.0.0, <6.6.1
>=7.0.0, <7.0.1
M
XML External Entity (XXE) Injection
CVE-2026-46723
Affects
tpwd/ke_search
| Versions
<5.6.2
>=6.0.0, <6.6.1
>=7.0.0, <7.0.1
M
Allocation of Resources Without Limits or Throttling
CVE-2026-46629
Affects
twig/intl-extra
| Versions
<3.26.0
M
Improper Encoding or Escaping of Output
CVE-2026-46637
Affects
twig/markdown-extra
| Versions
<3.26.0
M
Improper Encoding or Escaping of Output
CVE-2026-46637
Affects
twig/cssinliner-extra
| Versions
<3.26.0
M
Authorization Bypass Through User-Controlled Key
CVE-2026-8337
Affects
concrete5/concrete5
| Versions
<9.5.1