Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Arbitrary File Upload
CVE-2026-40488
Affects
openmage/magento-lts
| Versions
<20.17.0
M
SQL Injection
CVE-2026-6982
Affects
showdoc/showdoc
| Versions
>=2.5.3, <3.8.1
M
Server-side Request Forgery (SSRF)
CVE-2026-41887
Affects
flarum/core
| Versions
<1.8.16
>=2.0.0-beta.1, <2.0.0-rc.1
C
Deserialization of Untrusted Data
CVE-2026-25524
Affects
openmage/magento-lts
| Versions
<20.17.0
H
CRLF Injection
CVE-2026-41570
Affects
phpunit/phpunit
| Versions
>=12.5.21, <12.5.22
>=13.1.5, <13.1.6
M
Missing Authorization
CVE-2026-40098
Affects
openmage/magento-lts
| Versions
<20.17.0
H
Directory Traversal
CVE-2026-25525
Affects
openmage/magento-lts
| Versions
<20.17.0
H
Incorrect Authorization
CVE-2026-41325
Affects
getkirby/cms
| Versions
<4.9.0
>=5.0.0-alpha.1, <5.4.0
M
XML Injection
CVE-2026-32870
Affects
getkirby/cms
| Versions
<4.9.0
>=5.0.0-alpha.1, <5.4.0
M
Incorrect Authorization
CVE-2026-40099
Affects
getkirby/cms
| Versions
<4.9.0
>=5.0.0-alpha.1, <5.4.0
H
Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-34587
Affects
getkirby/cms
| Versions
>=3.8.0-rc.1, <4.9.0
>=5.0.0-alpha.1, <5.4.0
M
Cross-site Scripting (XSS)
CVE-2025-10354
Affects
mediawiki/semantic-media-wiki
| Versions
<5.0.2
C
Authorization Bypass Through User-Controlled Key
CVE-2018-25270
Affects
top-think/framework
| Versions
<5.1.32
H
Cross-site Scripting (XSS)
CVE-2026-41201
Affects
ci4-cms-erp/ci4ms
| Versions
<0.31.5.0
C
Directory Traversal
CVE-2026-41202
Affects
ci4-cms-erp/ci4ms
| Versions
<0.31.5.0
C
Directory Traversal
CVE-2026-41203
Affects
ci4-cms-erp/ci4ms
| Versions
<0.31.5.0
M
Cross-site Scripting (XSS)
CVE-2025-13784
Affects
yungifez/skuul
| Versions
>=0.0.0
M
Cross-site Request Forgery (CSRF)
CVE-2026-40929
Affects
wwbn/avideo
| Versions
>=0.0.0
M
Guessable CAPTCHA
CVE-2026-40935
Affects
wwbn/avideo
| Versions
>=0.0.0
M
Active Debug Code
CVE-2026-40908
Affects
wwbn/avideo
| Versions
>=0.0.0
H
Authorization Bypass Through User-Controlled Key
CVE-2026-40907
Affects
wwbn/avideo
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2019-20921
Affects
snapappointments/bootstrap-select
| Versions
<1.13.6
L
Incorrect Authorization
CVE-2026-29179
Affects
october/october
| Versions
<4.1.17
M
Incorrect Authorization
CVE-2026-26067
Affects
october/october
| Versions
<4.1.17
H
Incomplete List of Disallowed Inputs
CVE-2026-26274
Affects
october/october
| Versions
<4.1.17
L
Cross-site Scripting (XSS)
CVE-2026-27937
Affects
october/october
| Versions
<4.1.17
H
Cleartext Storage of Sensitive Information
CVE-2026-6553
Affects
typo3/cms-core
| Versions
>14.2.0, <14.3.0
H
Cleartext Storage of Sensitive Information
CVE-2026-6553
Affects
typo3/cms-backend
| Versions
>14.2.0, <14.3.0
M
SQL Injection
CVE-2026-41143
Affects
yeswiki/yeswiki
| Versions
<4.6.1
M
Timing Attack
Affects
kimai/kimai
| Versions
<2.54.0