Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Server-side Request Forgery (SSRF)
CVE-2026-28423
Affects
statamic/cms
| Versions
<5.73.11
>=6.0.0-alpha.1, <6.4.0
H
Arbitrary Code Injection
CVE-2026-28425
Affects
statamic/cms
| Versions
<5.73.11
>=6.0.0-alpha.1, <6.4.0
M
Incorrect Privilege Assignment
CVE-2026-2896
Affects
funadmin/funadmin
| Versions
>=0.0.0
M
Information Exposure
CVE-2026-2894
Affects
funadmin/funadmin
| Versions
>=0.0.0
M
Deserialization of Untrusted Data
CVE-2026-2898
Affects
funadmin/funadmin
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2026-2897
Affects
funadmin/funadmin
| Versions
>=0.0.0
M
Weak Password Recovery Mechanism for Forgotten Password
CVE-2026-2895
Affects
funadmin/funadmin
| Versions
>=0.0.0
H
SQL Injection
CVE-2026-3105
Affects
mautic/core-lib
| Versions
>=2.10.0, <5.2.10
>=6.0.0-alpha, <6.0.8
>=7.0.0-alpha, <7.0.1
L
Cross-site Scripting (XSS)
Affects
craftcms/cms
| Versions
>=5.0.0-RC1, <5.8.23
>=4.5.0-beta.1, <4.16.19
H
Server-side Request Forgery (SSRF)
CVE-2026-27732
Affects
wwbn/avideo
| Versions
<22.0.0
H
Weak Password Recovery Mechanism for Forgotten Password
CVE-2026-27593
Affects
statamic/cms
| Versions
<5.73.10
>=6.0.0-alpha.1, <6.3.3
M
Cross-site Scripting (XSS)
CVE-2026-27621
Affects
typicms/core
| Versions
<16.1.7
H
Allocation of Resources Without Limits or Throttling
CVE-2026-26047
Affects
moodle/moodle
| Versions
<4.5.9
>=5.0.0-beta, <5.0.5
>=5.1.0-beta, <5.1.2
H
Arbitrary Code Injection
CVE-2026-26045
Affects
moodle/moodle
| Versions
<4.5.9
>=5.0.0-beta, <5.0.5
>=5.1.0-beta, <5.1.2
C
Arbitrary Code Injection
Affects
unisharp/laravel-filemanager
| Versions
>=0.1.0
M
SQL Injection
CVE-2026-27461
Affects
pimcore/pimcore
| Versions
<12.3.3
M
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-27128
Affects
craftcms/cms
| Versions
>=4.5.0-RC1, <4.16.19
>=5.0.0-RC1, <5.8.23
M
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-27127
Affects
craftcms/cms
| Versions
>=3.5.0, <4.16.19
>=5.0.0-RC1, <5.8.23
H
Server-side Request Forgery (SSRF)
CVE-2026-27129
Affects
craftcms/cms
| Versions
>=3.5.0, <4.16.19
>=5.0.0-RC1, <5.8.23
M
Cross-site Scripting (XSS)
CVE-2026-27126
Affects
craftcms/cms
| Versions
<4.16.19
>=5.0.0-RC1, <5.8.23
H
Incorrect Privilege Assignment
CVE-2026-27198
Affects
getformwork/formwork
| Versions
>=2.0.0, <2.3.4
M
Cross-site Scripting (XSS)
CVE-2026-27196
Affects
statamic/cms
| Versions
<5.73.9
>=6.0.0-alpha.1, <6.3.2
M
Cross-site Scripting (XSS)
CVE-2026-27568
Affects
wwbn/avideo
| Versions
<21.0
C
Deserialization of Untrusted Data
CVE-2026-27206
Affects
zumba/json-serializer
| Versions
<3.2.3
H
SQL Injection
CVE-2026-26988
Affects
librenms/librenms
| Versions
<26.2.0
M
Cross-site Scripting (XSS)
CVE-2026-26992
Affects
librenms/librenms
| Versions
<26.2.0
M
Cross-site Scripting (XSS)
CVE-2026-26989
Affects
librenms/librenms
| Versions
<26.2.0
M
Improper Encoding or Escaping of Output
CVE-2026-27016
Affects
librenms/librenms
| Versions
>=24.10.0, <26.2.0
H
SQL Injection
CVE-2026-26990
Affects
librenms/librenms
| Versions
<26.2.0
M
Cross-site Scripting (XSS)
CVE-2026-26987
Affects
librenms/librenms
| Versions
<26.2.0