Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Directory Traversal
CVE-2026-33681
Affects
wwbn/avideo
| Versions
>=0.0.0
M
Missing Authorization
CVE-2026-33685
Affects
wwbn/avideo
| Versions
>=0.0.0
M
Use of Less Trusted Source
CVE-2026-33690
Affects
wwbn/avideo
| Versions
>=0.0.0
M
Information Exposure
CVE-2026-33688
Affects
wwbn/avideo
| Versions
>=0.0.0
H
Arbitrary File Upload
CVE-2026-33647
Affects
wwbn/avideo
| Versions
>=0.0.0
H
Cross-site Request Forgery (CSRF)
CVE-2026-33649
Affects
wwbn/avideo
| Versions
>=0.0.0
H
Command Injection
CVE-2026-33648
Affects
wwbn/avideo
| Versions
>=0.0.0
H
Incorrect Authorization
CVE-2026-33650
Affects
wwbn/avideo
| Versions
>=0.0.0
M
SQL Injection
CVE-2026-33651
Affects
wwbn/avideo
| Versions
>=0.0.0
H
Cross-site Scripting (XSS)
CVE-2026-33548
Affects
mantisbt/mantisbt
| Versions
>=2.28.0, <2.28.1
H
Cross-site Scripting (XSS)
CVE-2026-33517
Affects
mantisbt/mantisbt
| Versions
>=2.28.0, <2.28.1
M
Cross-site Scripting (XSS)
CVE-2026-4267
Affects
johnbillion/query-monitor
| Versions
<3.20.4
M
Server-side Request Forgery (SSRF)
CVE-2026-33347
Affects
league/commonmark
| Versions
>=2.3.0, <2.8.2
C
Access Control Bypass
CVE-2026-33478
Affects
wwbn/avideo
| Versions
>=0.0.0
C
Authentication Bypass by Primary Weakness
CVE-2026-30849
Affects
mantisbt/mantisbt
| Versions
<2.28.1
M
Server-side Request Forgery (SSRF)
CVE-2026-33486
Affects
roadiz/documents
| Versions
<2.3.42
>=2.4.0, <2.5.44
>=2.6.0, <2.6.28
>=2.7.0, <2.7.9
M
Missing Authorization
CVE-2026-33160
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.17.8
>=5.0.0-RC1, <5.9.14
H
Authorization Bypass Through User-Controlled Key
CVE-2026-33158
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.17.8
>=5.0.0-RC1, <5.9.14
M
Missing Authorization
CVE-2026-33159
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.17.8
>=5.0.0-RC1, <5.9.14
H
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
CVE-2026-33157
Affects
craftcms/cms
| Versions
>=5.6.0, <5.9.13
H
Arbitrary Code Injection
CVE-2026-30932
Affects
froxlor/froxlor
| Versions
<2.3.5
M
Missing Authorization
CVE-2026-33161
Affects
craftcms/cms
| Versions
>=4.0.0-RC1, <4.17.8
>=5.0.0-RC1, <5.9.14
H
Missing Authorization
CVE-2026-33162
Affects
craftcms/cms
| Versions
>=5.3.0, <5.9.14
M
Missing Authorization
CVE-2026-1217
Affects
yoast/duplicate-post
| Versions
<4.6
H
Excessive Iteration
CVE-2026-33204
Affects
kelvinmo/simplejwt
| Versions
<1.1.1
H
Arbitrary Code Injection
CVE-2026-32276
Affects
opensource-workshop/connect-cms
| Versions
<1.41.1
>=2.0.0, <2.41.1
M
Missing Authorization
CVE-2026-32299
Affects
opensource-workshop/connect-cms
| Versions
<1.41.1
>=2.0.0, <2.41.1
M
Cross-site Scripting (XSS)
CVE-2026-32277
Affects
opensource-workshop/connect-cms
| Versions
>=1.35.0, <1.41.1
>=2.35.0, <2.41.1
M
Authorization Bypass Through User-Controlled Key
CVE-2026-32300
Affects
opensource-workshop/connect-cms
| Versions
<1.41.1
>=2.0.0, <2.41.1
H
Arbitrary File Upload
CVE-2026-32278
Affects
opensource-workshop/connect-cms
| Versions
<1.41.1
>=2.0.0, <2.41.1