Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Missing Authentication for Critical Function
CVE-2026-42283
Affects
github.com/loft-sh/devspace/pkg/devspace/server
| Versions
>=6.3.20 <6.3.21
M
Incorrect Authorization
CVE-2026-6863
Affects
github.com/velocidex/velociraptor/api
| Versions
<0.76.4
H
Insertion of Sensitive Information into Log File
CVE-2026-6347
Affects
github.com/mattermost/mattermost-plugin-calls/server
| Versions
<1.11.2
M
Incorrect Authorization
CVE-2026-6342
Affects
github.com/mattermost/mattermost-plugin-msteams-devsecops/server
| Versions
>=0.0.0
M
Incorrect Authorization
CVE-2026-4273
Affects
github.com/mattermost/mattermost/server/v8/platform/services/remotecluster
| Versions
>=10.11.0-rc1 <10.11.14-rc1
>=11.5.0-rc1 <11.5.2-rc1
M
Memory Allocation with Excessive Size Value
CVE-2026-6340
Affects
github.com/mattermost/mattermost/server/v8/platform/services/docextractor
| Versions
>=10.11.0-rc1 <10.11.14-rc1
>=11.4.0-rc1 <11.4.4
>=11.5.0-rc1 <11.5.2-rc3
>=11.6.0-rc1 <11.6.0-rc3
M
Missing Authentication for Critical Function
Affects
github.com/cloudnativelabs/kube-router/v2/pkg/controllers/routing
| Versions
<2.9.0
M
Missing Authentication for Critical Function
Affects
github.com/cloudnativelabs/kube-router/v2/pkg/options
| Versions
<2.9.0
M
Missing Authentication for Critical Function
Affects
github.com/cloudnativelabs/kube-router/pkg/options
| Versions
<2.9.0
M
Missing Authentication for Critical Function
Affects
github.com/cloudnativelabs/kube-router/pkg/controllers/routing
| Versions
<2.9.0
M
Incorrect Authorization
CVE-2026-6341
Affects
github.com/mattermost/mattermost-plugin-gitlab/server
| Versions
<1.12.1-rc1
M
Authorization Bypass Through User-Controlled Key
CVE-2026-42572
Affects
github.com/hatchet-dev/hatchet/api/v1/server/handlers/v1/tasks
| Versions
<0.83.39
M
Cross-site Scripting (XSS)
CVE-2026-3495
Affects
github.com/mattermost/mattermost/server/channels/utils
| Versions
>=10.11.0-rc1 <10.11.14-rc1
>=11.5.0-rc1 <11.5.2-rc1
H
Improper Certificate Validation
CVE-2025-71261
Affects
github.com/harvester/harvester/pkg/controller/master/setting
| Versions
<1.8.0
H
Improper Certificate Validation
CVE-2025-71261
Affects
github.com/harvester/harvester/pkg/settings
| Versions
<1.8.0
L
Authentication Bypass by Primary Weakness
CVE-2026-6334
Affects
github.com/mattermost/mattermost/server/channels/app
| Versions
>=10.11.0-rc1 <10.11.14-rc1
>=11.5.0-rc1 <11.5.2-rc1
L
Operation on a Resource after Expiration or Release
CVE-2026-4053
Affects
github.com/mattermost/mattermost/server/channels/api4
| Versions
>=10.11.0-rc1 <10.11.14-rc1
>=11.5.0-rc1 <11.5.2-rc2
>=11.6.0-rc1 <11.6.0-rc2
M
Directory Traversal
CVE-2026-45571
Affects
github.com/go-git/go-git/v5/storage/filesystem/dotgit
| Versions
<5.19.1
>=6.0.0-alpha.1 <6.0.0-alpha.4
M
Directory Traversal
CVE-2026-45571
Affects
github.com/go-git/go-git/v6/storage/filesystem/dotgit
| Versions
<5.19.1
>=6.0.0-alpha.1 <6.0.0-alpha.4
M
Directory Traversal
CVE-2026-45571
Affects
github.com/go-git/go-git/storage/filesystem/dotgit
| Versions
<5.19.1
>=6.0.0-alpha.1 <6.0.0-alpha.4
H
Improper Synchronization
Affects
github.com/mezo-org/mezod/x/evm/keeper
| Versions
<8.0.0
H
Improper Synchronization
Affects
github.com/mezo-org/mezod/x/evm/statedb
| Versions
<8.0.0
H
Improper Synchronization
Affects
github.com/mezo-org/mezod/x/bridge/types
| Versions
<8.0.0
H
Improper Synchronization
Affects
github.com/mezo-org/mezod/x/bridge/keeper
| Versions
<8.0.0
H
Improper Synchronization
Affects
github.com/mezo-org/mezod/precompile
| Versions
<8.0.0
H
Server-side Request Forgery (SSRF)
CVE-2026-42339
Affects
github.com/quantumnous/new-api/common
| Versions
<0.12.13
L
Improper Encoding or Escaping of Output
CVE-2026-45570
Affects
github.com/go-git/go-git/v5/plumbing/transport/ssh
| Versions
<5.19.1
>=6.0.0-alpha.1 <6.0.0-alpha.4
L
Improper Encoding or Escaping of Output
CVE-2026-45570
Affects
github.com/go-git/go-git/v6/plumbing/transport/ssh
| Versions
<5.19.1
>=6.0.0-alpha.1 <6.0.0-alpha.4
L
Improper Encoding or Escaping of Output
CVE-2026-45570
Affects
github.com/go-git/go-git/plumbing/transport/ssh
| Versions
<5.19.1
>=6.0.0-alpha.1 <6.0.0-alpha.4
C
Missing Authentication for Critical Function
CVE-2026-42222
Affects
github.com/0xjacky/nginx-ui
| Versions
<2.3.8