Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Allocation of Resources Without Limits or Throttling
CVE-2026-6948
Affects
www.velocidex.com/golang/velociraptor/file_store
| Versions
<0.76.4
M
Off-by-one Error
CVE-2026-7572
Affects
www.velocidex.com/golang/evtx
| Versions
>=0.0.1
M
Off-by-one Error
CVE-2026-7572
Affects
github.com/velocidex/evtx
| Versions
>=0.0.1
M
Authorization Bypass Through User-Controlled Key
CVE-2026-7573
Affects
www.velocidex.com/golang/velociraptor/api
| Versions
>=0.2.1
M
Authorization Bypass Through User-Controlled Key
CVE-2026-7573
Affects
github.com/velocidex/velociraptor/api
| Versions
>=0.2.1
M
Allocation of Resources Without Limits or Throttling
CVE-2026-6948
Affects
github.com/velocidex/velociraptor/file_store
| Versions
<0.76.4
M
Improper Validation of Specified Type of Input
CVE-2026-5329
Affects
www.velocidex.com/golang/velociraptor/flows
| Versions
<0.75.7
>=0.76.1-rc1
M
Memory Allocation with Excessive Size Value
CVE-2026-33812
Affects
golang.org/x/image/font/sfnt
| Versions
<0.39.0
M
Memory Allocation with Excessive Size Value
CVE-2026-33812
Affects
github.com/golang/image/font/sfnt
| Versions
<0.39.0
M
Download of Code Without Integrity Check
CVE-2026-42248
Affects
github.com/ollama/ollama/app/updater
| Versions
>=0.0.1
M
Download of Code Without Integrity Check
CVE-2026-42249
Affects
github.com/ollama/ollama/app/updater
| Versions
>=0.0.1
M
Improper Validation of Specified Type of Input
CVE-2026-5329
Affects
github.com/velocidex/velociraptor/flows
| Versions
<0.75.7
>=0.76
H
Incorrect Type Conversion or Cast
CVE-2026-42576
Affects
chainguard.dev/apko/pkg/apk/apk
| Versions
<1.2.7
H
Resources Downloaded over Insecure Protocol
CVE-2026-42575
Affects
chainguard.dev/apko/pkg/apk/apk
| Versions
<1.2.7
M
Missing Authorization
CVE-2026-42541
Affects
github.com/kubewarden/adm-controller/api/policies/v1
| Versions
<1.35.0
M
Missing Authorization
CVE-2026-42541
Affects
github.com/kubewarden/adm-controller/internal/controller
| Versions
<1.35.0
H
Symlink Attack
CVE-2026-42574
Affects
chainguard.dev/apko/pkg/apk/fs
| Versions
>=0.14.8 <1.2.5
H
Out-of-bounds Read
CVE-2026-40251
Affects
github.com/lxc/incus/v7/cmd/incusd
| Versions
<7.0.0
H
Out-of-bounds Read
CVE-2026-40251
Affects
github.com/lxc/incus/v7/internal/server/storage
| Versions
<7.0.0
H
Cross-site Request Forgery (CSRF)
CVE-2026-42091
Affects
goshs.de/goshs/v2/httpserver
| Versions
<2.0.2
H
Directory Traversal
CVE-2026-41589
Affects
charm.land/wish/v2/scp
| Versions
<2.0.1
M
Symlink Attack
CVE-2026-41433
Affects
go.opentelemetry.io/obi/pkg/internal/java
| Versions
>=0.4.0 <0.8.0
H
Placement of User into Incorrect Group
CVE-2026-6970
Affects
github.com/canonical/authd/internal/users
| Versions
>=0.6.0 <0.6.4
M
Integer Overflow or Wraparound
CVE-2026-32759
Affects
github.com/filebrowser/filebrowser/http
| Versions
>=1.0.0
M
Server-side Request Forgery (SSRF)
CVE-2026-39383
Affects
github.com/gotenberg/gotenberg/v8/pkg/modules/webhook
| Versions
>=8.29.1 <8.31.0
M
Server-side Request Forgery (SSRF)
CVE-2026-39383
Affects
github.com/gotenberg/gotenberg/v8/pkg/modules/chromium
| Versions
>=8.29.1 <8.31.0
M
Server-side Request Forgery (SSRF)
CVE-2026-39383
Affects
github.com/gotenberg/gotenberg/v8/pkg/modules/api
| Versions
>=8.29.1 <8.31.0
C
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-42300
Affects
github.com/l3montree-dev/devguard/middlewares
| Versions
<1.2.2
C
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-42300
Affects
github.com/l3montree-dev/devguard/integrations/gitlabint
| Versions
<1.2.2
C
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-42300
Affects
github.com/l3montree-dev/devguard/accesscontrol
| Versions
<1.2.2