Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Cross-site Scripting (XSS)
CVE-2026-40607
Affects
mantisbt/mantisbt
| Versions
>=2.1.0, <2.28.2
H
Cross-site Scripting (XSS)
CVE-2026-44657
Affects
mantisbt/mantisbt
| Versions
<2.28.2
H
Improperly Implemented Security Check for Standard
CVE-2026-40597
Affects
mantisbt/mantisbt
| Versions
<2.28.2
H
Cross-site Scripting (XSS)
CVE-2026-40596
Affects
mantisbt/mantisbt
| Versions
>=2.11.0, <2.28.2
M
Authorization Bypass Through User-Controlled Key
CVE-2026-33052
Affects
mantisbt/mantisbt
| Versions
>=2.28.0, <2.28.2
C
Deserialization of Untrusted Data
Affects
torrentpier/torrentpier
| Versions
<2.4.4
C
PHP Remote File Inclusion
CVE-2026-39850
Affects
yiisoft/yii2
| Versions
<2.0.55
L
Open Redirect
CVE-2026-34094
Affects
mediawiki/core
| Versions
>=1.0.0, <1.43.7
>=1.44.0-rc.0, <1.44.4
>=1.45.0-rc.0, <1.45.2
L
Information Exposure
CVE-2026-34092
Affects
mediawiki/core
| Versions
<1.43.7
>=1.44.0-rc.0, <1.44.4
>=1.45.0-rc.0, <1.45.2
H
Arbitrary Code Injection
CVE-2026-44738
Affects
getgrav/grav
| Versions
<2.0.0-rc.2
H
SQL Injection
CVE-2026-44521
Affects
studio-42/elfinder
| Versions
<2.1.68
H
Arbitrary Code Injection
CVE-2021-47939
Affects
evolutioncms/evolution
| Versions
>=3.1.6
C
User Impersonation
CVE-2021-47923
Affects
opencart/opencart
| Versions
>=3.0.3.8
M
Cross-site Request Forgery (CSRF)
CVE-2021-47946
Affects
opencart/opencart
| Versions
>=3.0.3.6
M
Cross-site Request Forgery (CSRF)
CVE-2021-47953
Affects
opencart/opencart
| Versions
>=3.0.3.7
L
Cross-site Scripting (XSS)
CVE-2026-27964
Affects
facturascripts/facturascripts
| Versions
>=0.0.0
H
Arbitrary File Upload
CVE-2026-27891
Affects
facturascripts/facturascripts
| Versions
<2026.0
H
Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2026-27892
Affects
facturascripts/facturascripts
| Versions
<2026.1
M
Cross-site Scripting (XSS)
CVE-2026-42877
Affects
facturascripts/facturascripts
| Versions
<2026.1
M
Active Debug Code
CVE-2026-42878
Affects
facturascripts/facturascripts
| Versions
>=2026.0
M
Arbitrary File Upload
CVE-2026-42879
Affects
facturascripts/facturascripts
| Versions
<2026.1
C
Access Control Bypass
CVE-2026-37709
Affects
snipe/snipe-it
| Versions
<8.4.1
H
Incorrect Authorization
CVE-2026-44832
Affects
snipe/snipe-it
| Versions
<8.4.1
L
Cross-site Scripting (XSS)
CVE-2026-44831
Affects
snipe/snipe-it
| Versions
<8.4.1
M
Cross-site Scripting (XSS)
CVE-2026-44737
Affects
getgrav/grav
| Versions
<1.7.49.5
>1.8.0-beta.1, <1.8.0-beta.5
M
Directory Traversal
CVE-2026-44298
Affects
kimai/kimai
| Versions
>=2.32.0, <2.56.0
H
Cross-site Scripting (XSS)
CVE-2026-44212
Affects
prestashop/prestashop
| Versions
<8.2.6
>=9.0.0-alpha.1, <9.1.1
L
Incorrect Authorization
Affects
web-auth/webauthn-framework
| Versions
>=5.3.0, <5.3.1
M
Cross-site Scripting (XSS)
CVE-2026-36341
Affects
krayin/laravel-crm
| Versions
>=2.1.5, <2.1.6
M
Cross-site Request Forgery (CSRF)
CVE-2025-68604
Affects
wp-graphql/wp-graphql
| Versions
<2.5.4