Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Improper Check or Handling of Exceptional Conditions
CVE-2026-28407
Affects
github.com/chainguard-dev/malcontent/pkg/archive
| Versions
<1.21.0
H
SQL Injection
CVE-2026-26186
Affects
github.com/fleetdm/fleet/v4/server/datastore/mysql
| Versions
>=4.15.0 <4.81.0
H
Improper Privilege Management
CVE-2026-27899
Affects
github.com/h44z/wg-portal/internal/domain
| Versions
<2.1.3
H
Improper Privilege Management
CVE-2026-27899
Affects
github.com/h44z/wg-portal/internal/app/users
| Versions
<2.1.3
H
Improper Privilege Management
CVE-2026-27899
Affects
github.com/h44z/wg-portal/internal/app/api/v0/backend
| Versions
<2.1.3
M
Server-side Request Forgery (SSRF)
CVE-2026-27808
Affects
github.com/axllent/mailpit/server/handlers
| Versions
<1.29.2
M
Server-side Request Forgery (SSRF)
CVE-2026-27808
Affects
github.com/axllent/mailpit/internal/linkcheck
| Versions
<1.29.2
M
Server-side Request Forgery (SSRF)
CVE-2026-27808
Affects
github.com/axllent/mailpit/config
| Versions
<1.29.2
M
Server-side Request Forgery (SSRF)
CVE-2026-27808
Affects
github.com/axllent/mailpit/cmd
| Versions
<1.29.2
L
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-21725
Affects
github.com/grafana/grafana/pkg/api
| Versions
<12.4.0
C
Weak Password Recovery Mechanism for Forgotten Password
CVE-2026-28268
Affects
code.vikunja.io/api/pkg/user
| Versions
<2.1.0
C
Weak Password Recovery Mechanism for Forgotten Password
CVE-2026-28268
Affects
github.com/go-vikunja/vikunja/pkg/user
| Versions
<2.1.0
H
Uncaught Exception
CVE-2026-27819
Affects
code.vikunja.io/api/pkg/modules/dump
| Versions
<2.0.0
H
Uncaught Exception
CVE-2026-27819
Affects
github.com/go-vikunja/vikunja/pkg/modules/dump
| Versions
<2.0.0
H
Server-side Request Forgery (SSRF)
CVE-2026-27730
Affects
github.com/esm-dev/esm.sh/server
| Versions
<136_1
H
Server-side Request Forgery (SSRF)
CVE-2026-27730
Affects
github.com/esm-dev/esm.sh/internal/fetch
| Versions
<136_1
M
Expected Behavior Violation
CVE-2025-69232
Affects
github.com/free5gc/smf/internal/util
| Versions
<1.4.1
M
Expected Behavior Violation
CVE-2025-69232
Affects
github.com/free5gc/smf/internal/context
| Versions
<1.4.1
C
Insufficient Session Expiration
CVE-2026-27575
Affects
code.vikunja.io/api/pkg/user
| Versions
<2.0.0
C
Insufficient Session Expiration
CVE-2026-27575
Affects
code.vikunja.io/api/pkg/routes/api/v1
| Versions
<2.0.0
H
Improper Handling of Highly Compressed Data (Data Amplification)
Affects
github.com/bishopfox/sliver/server/c2
| Versions
<1.7.2
H
Improper Handling of Highly Compressed Data (Data Amplification)
Affects
github.com/bishopfox/sliver/util/encoders
| Versions
<1.7.2
H
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-27611
Affects
github.com/gtsteffaniak/filebrowser/backend/http
| Versions
<1.1.3-stable
>=1.2.0-beta <1.2.6-beta
H
Server-side Request Forgery (SSRF)
CVE-2025-50180
Affects
github.com/esm-dev/esm.sh/server
| Versions
<136_1
H
Server-side Request Forgery (SSRF)
CVE-2025-50180
Affects
github.com/esm-dev/esm.sh/internal/fetch
| Versions
<136_1
C
Incorrect Behavior Order: Validate Before Canonicalize
CVE-2026-27590
Affects
github.com/caddyserver/caddy/v2/modules/caddyhttp/reverseproxy/fastcgi
| Versions
<2.11.0
C
Incorrect Behavior Order: Validate Before Canonicalize
CVE-2026-27590
Affects
github.com/caddyserver/caddy/modules/caddyhttp/reverseproxy/fastcgi
| Versions
<2.11.0
H
Cross-site Request Forgery (CSRF)
CVE-2026-27589
Affects
github.com/caddyserver/caddy/caddyconfig
| Versions
<2.11.0-beta.1
H
Cross-site Request Forgery (CSRF)
CVE-2026-27589
Affects
github.com/caddyserver/caddy/v2/caddyconfig
| Versions
<2.11.0-beta.1
H
Cross-site Request Forgery (CSRF)
CVE-2026-27589
Affects
github.com/caddyserver/caddy/cmd
| Versions
<2.11.0-beta.1