Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Cross-site Scripting (XSS)
CVE-2026-29177
Affects
craftcms/commerce
| Versions
>=4.0.0-beta.1, <4.10.2
>=5.0.0-beta.1, <5.5.3
M
Authorization Bypass Through User-Controlled Key
CVE-2026-31867
Affects
craftcms/commerce
| Versions
>=4.0.0-beta.1, <4.11.0
>=5.0.0, <5.6.0
M
Cross-site Scripting (XSS)
CVE-2026-29176
Affects
craftcms/commerce
| Versions
>=5.0.0-beta.1, <5.5.3
M
Cross-site Scripting (XSS)
CVE-2026-29173
Affects
craftcms/commerce
| Versions
>=5.0.0-beta.1, <5.5.3
>=4.0.0-beta.1, <4.10.2
H
Incorrect Authorization
Affects
ec-cube/ec-cube
| Versions
>=4.1-beta3, <4.3.1-p1
M
Cross-site Scripting (XSS)
Affects
leantime/leantime
| Versions
<3.3.0
H
Missing Authorization
CVE-2026-28685
Affects
kimai/kimai
| Versions
<2.51.0
H
Authorization Bypass Through User-Controlled Key
CVE-2026-29069
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.17.0-beta.2
>=5.0.0-RC1, <5.9.0-beta.2
H
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-28781
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.17.0-beta.1
>=5.0.0-RC1, <5.9.0-beta.2
H
Authorization Bypass Through User-Controlled Key
CVE-2026-28782
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.17.0-beta.1
>=5.0.0-RC1, <5.9.0-beta.1
H
Template Injection
CVE-2026-28783
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.17.0-beta.1
>=5.0.0-RC1, <5.9.0-beta.1
H
Template Injection
CVE-2026-28784
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.17.0-beta.1
>=5.0.0-RC1, <5.9.0-beta.1
H
Template Injection
CVE-2026-28695
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.17.0-beta.1
>=5.8.7, <5.9.0-beta.1
M
Template Injection
CVE-2026-28697
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.17.0-beta.1
>=5.0.0-RC1, <5.9.0-beta.1
M
Missing Authorization
CVE-2026-28696
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.17.0-beta.1
>=5.0.0-RC1, <5.9.0-beta.1
M
Cross-site Scripting (XSS)
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.17.0-beta.1
>=5.0.0-RC1, <5.9.0-beta.1
M
Cross-site Scripting (XSS)
CVE-2026-24415
Affects
devcode-it/openstamanager
| Versions
<2.10.1
C
Missing Authentication for Critical Function
CVE-2026-27012
Affects
devcode-it/openstamanager
| Versions
<2.10.1
M
Cross-site Scripting (XSS)
CVE-2026-30838
Affects
league/commonmark
| Versions
<2.8.1
H
Deserialization of Untrusted Data
CVE-2026-3452
Affects
concrete5/core
| Versions
<9.4.8
M
Cross-site Scripting (XSS)
CVE-2026-3242
Affects
concrete5/core
| Versions
<9.4.8
M
Cross-site Request Forgery (CSRF)
CVE-2026-2994
Affects
concrete5/core
| Versions
<9.4.8
M
Cross-site Scripting (XSS)
CVE-2026-3244
Affects
concrete5/core
| Versions
<9.4.8
M
Cross-site Scripting (XSS)
CVE-2026-3241
Affects
concrete5/core
| Versions
<9.4.8
M
Cross-site Scripting (XSS)
CVE-2026-3240
Affects
concrete5/core
| Versions
<9.4.8
H
Comparing instead of Assigning
CVE-2026-26279
Affects
froxlor/froxlor
| Versions
<2.3.4
C
SQL Injection
CVE-2026-28501
Affects
wwbn/avideo
| Versions
<24.0
H
Arbitrary File Upload
CVE-2026-28502
Affects
wwbn/avideo
| Versions
<24.0
H
Command Injection
CVE-2026-28507
Affects
idno/known
| Versions
<1.6.4
C
Server-side Request Forgery (SSRF)
CVE-2026-28508
Affects
idno/known
| Versions
>=0.0.0, <1.6.4