Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Improper Neutralization of Special Elements in Data Query Logic
CVE-2026-81525
Affects
mongodb/mongodb
| Versions
<1.21.4
>=2.0.0, <2.4.1
L
Deserialization of Untrusted Data
CVE-2026-49400
Affects
october/system
| Versions
<3.7.17
>=4.0.0, <4.2.23
C
Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-59989
Affects
phalcon/cphalcon
| Versions
<5.16.0
H
SQL Injection
CVE-2026-56738
Affects
phpmyfaq/phpmyfaq
| Versions
<4.1.6
H
SQL Injection
CVE-2026-56738
Affects
thorsten/phpmyfaq
| Versions
<4.1.6
C
Improper Authentication
CVE-2026-56737
Affects
thorsten/phpmyfaq
| Versions
>=3.2.0, <4.1.6
C
Improper Authentication
CVE-2026-56737
Affects
phpmyfaq/phpmyfaq
| Versions
>=3.2.0, <4.1.6
H
User Impersonation
CVE-2026-55584
Affects
phpsysinfo/phpsysinfo
| Versions
<3.4.6
M
Cross-site Scripting (XSS)
CVE-2026-55696
Affects
privatebin/privatebin
| Versions
<2.0.5
H
Infinite loop
CVE-2026-84997
Affects
react/http
| Versions
>=0.6.0, <1.11.1
M
Cross-site Scripting (XSS)
CVE-2026-63001
Affects
redaxo/source
| Versions
<5.21.2
M
Cross-site Scripting (XSS)
CVE-2026-63002
Affects
redaxo/source
| Versions
<5.21.2
M
Information Exposure
CVE-2026-62998
Affects
redaxo/source
| Versions
<5.21.2
M
Cross-site Request Forgery (CSRF)
CVE-2026-63000
Affects
redaxo/source
| Versions
<5.21.2
C
Server-side Request Forgery (SSRF)
CVE-2026-50887
Affects
shlinkio/shlink
| Versions
>=0.0.0
H
Missing Authorization
CVE-2026-56827
Affects
shopper/framework
| Versions
<2.9.2
H
Missing Authorization
CVE-2026-56828
Affects
shopper/framework
| Versions
>=2.8.0, <2.9.2
M
Missing Authorization
CVE-2026-56826
Affects
shopper/framework
| Versions
>=2.0.0, <2.9.2
H
Improper Input Validation
CVE-2026-56831
Affects
shopper/framework
| Versions
<2.9.0
H
Missing Authorization
CVE-2026-56830
Affects
shopper/framework
| Versions
<2.9.2
H
Missing Authorization
CVE-2026-56829
Affects
shopper/framework
| Versions
<2.9.2
H
Missing Authorization
CVE-2026-56825
Affects
shopper/framework
| Versions
<2.9.2
H
Arbitrary Code Injection
CVE-2026-54721
Affects
silverstripe/userforms
| Versions
<6.4.9
>=7.0.0, <7.0.7
>=7.1.0, <7.1.1
M
Cross-site Scripting (XSS)
CVE-2026-55779
Affects
silverstripe/versioned
| Versions
<3.2.1
M
Server-side Request Forgery (SSRF)
CVE-2026-62993
Affects
smarty/smarty
| Versions
<4.5.7
>=5.0.0, <5.8.2
M
Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-73858
Affects
solspace/craft-freeform
| Versions
>=5.0.0, <5.10.14
H
Authorization Bypass Through User-Controlled Key
CVE-2026-53673
Affects
buddypress/buddypress
| Versions
<14.5.0
M
Authorization Bypass Through User-Controlled Key
CVE-2026-53675
Affects
buddypress/buddypress
| Versions
>=0.0.0
C
SQL Injection
CVE-2026-79752
Affects
cakephp/database
| Versions
<4.5.12
>=4.6.0, <4.6.5
>=5.0.0, <5.1.9
>=5.2.0, <5.2.14
>=5.3.0, <5.3.7
C
SQL Injection
CVE-2026-79752
Affects
cakephp/cakephp
| Versions
<4.5.12
>=4.6.0, <4.6.5
>=5.0.0, <5.1.9
>=5.2.0, <5.2.14
>=5.3.0, <5.3.7