Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
C
Malicious Package
CVE-2026-67595
Affects
webreinvent/vaahcms
| Versions
>=2.0.0
H
Authorization Bypass Through User-Controlled Key
CVE-2026-66412
Affects
leantime/leantime
| Versions
>=0.0.0
H
Cross-site Request Forgery (CSRF)
CVE-2026-66416
Affects
leantime/leantime
| Versions
>=0.0.0
H
Server-side Request Forgery (SSRF)
CVE-2026-66415
Affects
leantime/leantime
| Versions
>=0.0.0
M
Open Redirect
CVE-2026-66414
Affects
leantime/leantime
| Versions
>=0.0.0
H
Directory Traversal
CVE-2026-63222
Affects
codeigniter4/framework
| Versions
<4.7.4
H
SQL Injection
CVE-2026-63221
Affects
codeigniter4/framework
| Versions
>=4.3.0, <4.7.4
C
Arbitrary File Upload
CVE-2026-63223
Affects
codeigniter4/framework
| Versions
<4.7.4
M
Authorization Bypass Through User-Controlled Key
CVE-2026-68501
Affects
sylius/mollie-plugin
| Versions
<2.2.8
>=3.0.0, <3.2.4
>=3.3.0, <3.3.1
H
Authorization Bypass Through User-Controlled Key
CVE-2026-68500
Affects
sylius/mollie-plugin
| Versions
<2.2.8
>=3.0.0, <3.2.4
>=3.3.0, <3.3.1
H
Arbitrary File Upload
CVE-2026-53599
Affects
redaxo/source
| Versions
>=5.18.2, <5.21.1
H
Improper Authentication
CVE-2026-51953
Affects
feehi/cms
| Versions
>=0.0.0
H
Allocation of Resources Without Limits or Throttling
CVE-2026-61609
Affects
pterodactyl/panel
| Versions
>=1.7.0, <1.13.0
H
Improper Restriction of Security Token Assignment
CVE-2026-54593
Affects
pterodactyl/panel
| Versions
<1.12.3
M
Server-side Request Forgery (SSRF)
CVE-2026-63107
Affects
limesurvey/limesurvey
| Versions
>=0.0.0
M
Missing Authorization
CVE-2026-63092
Affects
medienbaecker/kirby-modules
| Versions
<5.5.8
M
Cross-site Scripting (XSS)
CVE-2026-26483
Affects
mettle/sendportal
| Versions
>=0.0.0
M
Directory Traversal
CVE-2026-16767
Affects
nelexa/zip
| Versions
>=0.0.0
H
Incorrect Permission Assignment for Critical Resource
CVE-2026-63358
Affects
filegator/filegator
| Versions
<7.14.3
H
Arbitrary Code Injection
CVE-2026-65693
Affects
microweber/microweber
| Versions
>=0.0.0
H
Arbitrary Argument Injection
Affects
pheditor/pheditor
| Versions
<2.0.7
C
Authentication Bypass by Assumed-Immutable Data
Affects
pheditor/pheditor
| Versions
<2.0.8
H
Authorization Bypass Through User-Controlled Key
Affects
poweradmin/poweradmin
| Versions
>=3.0.0, <3.9.11
>=4.0.0, <4.2.5
>=4.3.0, <4.3.4
H
Missing Authorization
Affects
poweradmin/poweradmin
| Versions
>=4.0.0, <4.2.5
>=4.3.0, <4.3.4
H
Improper Authentication
Affects
poweradmin/poweradmin
| Versions
>=4.1.0, <4.2.5
>=4.3.0, <4.3.4
H
Infinite loop
CVE-2026-59933
Affects
phpoffice/phpspreadsheet
| Versions
<1.30.6
>=2.0.0, <2.1.18
>=2.2.0, <2.4.7
>=3.3.0, <3.10.7
>=4.0.0, <5.8.1
H
Server-side Request Forgery (SSRF)
CVE-2026-59931
Affects
phpoffice/phpspreadsheet
| Versions
<1.30.6
>=2.0.0, <2.1.18
>=2.2.0, <2.4.7
>=3.3.0, <3.10.7
>=4.0.0, <5.8.1
H
Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-59932
Affects
phpoffice/phpspreadsheet
| Versions
<1.30.6
>=2.0.0, <2.1.18
>=2.2.0, <2.4.7
>=3.3.0, <3.10.7
>=4.0.0, <5.8.1
M
Denial of Service (DoS)
CVE-2026-59941
Affects
dompdf/dompdf
| Versions
<3.1.6
H
Allocation of Resources Without Limits or Throttling
CVE-2026-59942
Affects
dompdf/dompdf
| Versions
<3.1.6