Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Server-side Request Forgery (SSRF)
CVE-2026-41413
Affects
github.com/istio/istio/pilot/pkg/xds
| Versions
<1.28.6
>=1.29.0-alpha.0 <1.29.2
M
Server-side Request Forgery (SSRF)
CVE-2026-41413
Affects
github.com/istio/istio/pilot/pkg/model
| Versions
<1.28.6
>=1.29.0-alpha.0 <1.29.2
M
Incorrect Authorization
CVE-2026-40304
Affects
github.com/openziti/zrok/controller
| Versions
>=0.0.0
M
Incorrect Authorization
CVE-2026-40304
Affects
github.com/openziti/zrok/v2/controller
| Versions
<2.0.1
M
Incorrect Authorization
CVE-2026-40304
Affects
github.com/openziti/zrok/controller/store
| Versions
>=0.0.0
M
Incorrect Authorization
CVE-2026-40304
Affects
github.com/openziti/zrok/v2/controller/store
| Versions
<2.0.1
H
Arbitrary Argument Injection
CVE-2026-35585
Affects
github.com/filebrowser/filebrowser/v2/runner
| Versions
>=2.0.0-rc.1
M
Directory Traversal
CVE-2026-35605
Affects
github.com/filebrowser/filebrowser/rules
| Versions
<2.63.1
H
Improper Privilege Management
CVE-2026-35607
Affects
github.com/filebrowser/filebrowser/v2/auth
| Versions
<2.63.1
H
Improper Privilege Management
CVE-2026-35607
Affects
github.com/filebrowser/filebrowser/auth
| Versions
<2.63.1
M
Missing Authorization
CVE-2026-35606
Affects
github.com/filebrowser/filebrowser/v2/http
| Versions
<2.63.1
M
Missing Authorization
CVE-2026-35606
Affects
github.com/filebrowser/filebrowser/http
| Versions
<2.63.1
H
Incorrect Authorization
CVE-2026-35604
Affects
github.com/filebrowser/filebrowser/v2/http
| Versions
<2.63.1
H
Incorrect Authorization
CVE-2026-35604
Affects
github.com/filebrowser/filebrowser/http
| Versions
<2.63.1
M
Directory Traversal
CVE-2026-35605
Affects
github.com/filebrowser/filebrowser/v2/rules
| Versions
<2.63.1
H
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-3605
Affects
github.com/hashicorp/vault/api
| Versions
>=0.10.0 <2.0.0
M
Insufficiently Protected Credentials
Affects
github.com/go-git/go-git/v5/plumbing/transport/http
| Versions
>=5.3.0 <5.18.0
M
Insufficiently Protected Credentials
Affects
github.com/go-git/go-git/v6/plumbing/transport/http
| Versions
>=6.0.0-alpha.1 <6.0.0-alpha.2
M
Insufficiently Protected Credentials
Affects
github.com/go-git/go-git/plumbing/transport/http
| Versions
>=5.3.0 <5.18.0
>=6.0.0-alpha.1 <6.0.0-alpha.2
H
Cross-site Request Forgery (CSRF)
CVE-2026-28741
Affects
github.com/mattermost/mattermost/server/channels/api4
| Versions
>=10.11.0 <10.11.13
>=11.3.0 <11.3.3
>=11.4.0 <11.4.3
>=11.5.0 <11.5.1
H
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-32282
Affects
std/internal/syscall/unix
| Versions
<1.25.9
>=1.26.0-0 <1.26.2
M
Insufficient Session Expiration
CVE-2026-34454
Affects
github.com/oauth2-proxy/oauth2-proxy/v7
| Versions
>=7.11.0 <7.15.2
C
LDAP Injection
CVE-2026-40193
Affects
github.com/foxcpp/maddy/internal/auth/ldap
| Versions
>=0.5.0 <0.9.3
C
User Impersonation
CVE-2026-34457
Affects
github.com/oauth2-proxy/oauth2-proxy/pkg/middleware
| Versions
>=6.0.0 <7.15.2
C
User Impersonation
CVE-2026-34457
Affects
github.com/oauth2-proxy/oauth2-proxy/v7/pkg/middleware
| Versions
<7.15.2
H
Improper Neutralization
CVE-2026-39350
Affects
istio.io/istio/pilot/pkg/security/authz/model
| Versions
>=1.25.0-rc.0 <1.27.9
>=1.28.0-alpha.0 <1.28.6
>=1.29.0-alpha.0 <1.29.2
M
Server-side Request Forgery (SSRF)
CVE-2026-5530
Affects
github.com/ollama/ollama/server
| Versions
>=0.0.1
H
Directory Traversal
CVE-2026-35454
Affects
github.com/coder/code-marketplace/storage
| Versions
<2.4.2
M
Incorrect Authorization
CVE-2026-6290
Affects
www.velocidex.com/golang/velociraptor/vql/server
| Versions
>=0.2.1
M
Incorrect Authorization
CVE-2026-6290
Affects
www.velocidex.com/golang/velociraptor/vql/tools
| Versions
>=0.2.1