Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-32282
Affects
std/internal/syscall/unix
| Versions
<1.25.9
>=1.26.0-0 <1.26.2
M
Insufficient Session Expiration
CVE-2026-34454
Affects
github.com/oauth2-proxy/oauth2-proxy/v7
| Versions
>=7.11.0 <7.15.2
C
LDAP Injection
CVE-2026-40193
Affects
github.com/foxcpp/maddy/internal/auth/ldap
| Versions
>=0.5.0 <0.9.3
C
User Impersonation
CVE-2026-34457
Affects
github.com/oauth2-proxy/oauth2-proxy/pkg/middleware
| Versions
>=6.0.0 <7.15.2
C
User Impersonation
CVE-2026-34457
Affects
github.com/oauth2-proxy/oauth2-proxy/v7/pkg/middleware
| Versions
<7.15.2
H
Improper Neutralization
CVE-2026-39350
Affects
istio.io/istio/pilot/pkg/security/authz/model
| Versions
>=1.25.0-rc.0 <1.27.9
>=1.28.0-alpha.0 <1.28.6
>=1.29.0-alpha.0 <1.29.2
M
Server-side Request Forgery (SSRF)
CVE-2026-5530
Affects
github.com/ollama/ollama/server
| Versions
>=0.0.1
H
Directory Traversal
CVE-2026-35454
Affects
github.com/coder/code-marketplace/storage
| Versions
<2.4.2
M
Incorrect Authorization
CVE-2026-6290
Affects
www.velocidex.com/golang/velociraptor/vql/server
| Versions
>=0.2.1
M
Incorrect Authorization
CVE-2026-6290
Affects
www.velocidex.com/golang/velociraptor/vql/tools
| Versions
>=0.2.1
M
Incorrect Authorization
CVE-2026-6290
Affects
www.velocidex.com/golang/velociraptor/paths/artifacts
| Versions
>=0.2.1
M
Incorrect Authorization
CVE-2026-6290
Affects
github.com/velocidex/velociraptor/vql/tools
| Versions
>=0.2.1
M
Incorrect Authorization
CVE-2026-6290
Affects
github.com/velocidex/velociraptor/vql/server
| Versions
>=0.2.1
M
Incorrect Authorization
CVE-2026-6290
Affects
github.com/velocidex/velociraptor/paths/artifacts
| Versions
>=0.2.1
M
Information Exposure
CVE-2025-12141
Affects
github.com/grafana/grafana/pkg/services/sqlstore/migrations
| Versions
<12.4.0
M
Information Exposure
CVE-2025-12141
Affects
github.com/grafana/grafana/pkg/services/ngalert/accesscontrol
| Versions
<12.4.0
M
Server-side Request Forgery (SSRF)
Affects
github.com/kyverno/kyverno/pkg/engine/apicall
| Versions
>=0.1.0
H
Server-side Request Forgery (SSRF)
CVE-2026-35036
Affects
github.com/lin-snow/ech0/internal/service
| Versions
<4.2.8
H
Server-side Request Forgery (SSRF)
CVE-2026-35036
Affects
github.com/lin-snow/ech0/internal/router
| Versions
<4.2.8
M
Authorization Bypass Through User-Controlled Key
CVE-2026-28736
Affects
github.com/mattermost/focalboard/server
| Versions
>=0.6.0
H
SQL Injection
CVE-2026-25773
Affects
github.com/mattermost/focalboard/server
| Versions
>=0.6.0
M
Server-side Request Forgery (SSRF)
Affects
github.com/kyverno/kyverno/pkg/engine/context/loaders
| Versions
<1.16.2
M
Server-side Request Forgery (SSRF)
Affects
github.com/kyverno/kyverno/pkg/engine/factories
| Versions
<1.16.2
M
Server-side Request Forgery (SSRF)
Affects
github.com/kyverno/kyverno/pkg/engine/apicall
| Versions
<1.16.2
H
Unintended Proxy or Intermediary ('Confused Deputy')
Affects
github.com/kyverno/kyverno/pkg/background/mpol
| Versions
<1.17.0
H
Unintended Proxy or Intermediary ('Confused Deputy')
Affects
github.com/kyverno/kyverno/pkg/engine/apicall
| Versions
<1.17.0
H
Unintended Proxy or Intermediary ('Confused Deputy')
Affects
github.com/kyverno/kyverno/pkg/cel/policies/vpol/compiler
| Versions
<1.17.0
H
Unintended Proxy or Intermediary ('Confused Deputy')
Affects
github.com/kyverno/kyverno/pkg/cel/policies/mpol/compiler
| Versions
<1.17.0
H
Unintended Proxy or Intermediary ('Confused Deputy')
Affects
github.com/kyverno/kyverno/pkg/cel/policies/gpol/compiler
| Versions
<1.17.0
H
Unintended Proxy or Intermediary ('Confused Deputy')
Affects
github.com/kyverno/kyverno/pkg/cel/policies/dpol/compiler
| Versions
<1.17.0