Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Permissive Cross-domain Policy with Untrusted Domains
CVE-2026-34200
Affects
github.com/nhost/nhost/cli/cmd/mcp/start
| Versions
<1.41.0
L
Incorrect Authorization
CVE-2026-34972
Affects
github.com/openfga/openfga/pkg/storage
| Versions
>=1.8.0 <1.14.0
C
Regular Expression without Anchors
CVE-2026-34940
Affects
github.com/kubeai-project/kubeai/internal/modelcontroller
| Versions
<0.23.2
M
Incorrect Authorization
CVE-2025-68152
Affects
github.com/juju/juju/apiserver
| Versions
<2.9.56
>=3.0-beta1 <3.6.20
>=4.0-beta1
H
Server-side Request Forgery (SSRF)
CVE-2026-33540
Affects
github.com/distribution/distribution/v3/registry/proxy
| Versions
<3.1.0
H
Server-side Request Forgery (SSRF)
CVE-2026-33540
Affects
github.com/distribution/distribution/v3/internal/client/auth/challenge
| Versions
<3.1.0
H
Server-side Request Forgery (SSRF)
CVE-2026-33540
Affects
github.com/distribution/distribution/registry/proxy
| Versions
<3.1.0
H
Server-side Request Forgery (SSRF)
CVE-2026-33540
Affects
github.com/distribution/distribution/internal/client/auth/challenge
| Versions
<3.1.0
H
Access Control Bypass
CVE-2026-35172
Affects
github.com/distribution/distribution/v3/registry/storage/cache/redis
| Versions
<3.1.0
H
Access Control Bypass
CVE-2026-35172
Affects
github.com/distribution/distribution/registry/storage/cache/redis
| Versions
<3.1.0
H
Incorrect Authorization
CVE-2025-68153
Affects
github.com/juju/juju/api/client/resources
| Versions
<2.9.56
>=3.0-beta1 <3.6.20
>=4.0-beta1
H
Incorrect Authorization
CVE-2025-68153
Affects
github.com/juju/juju/api
| Versions
<2.9.56
>=3.0-beta1 <3.6.20
>=4.0-beta1
H
Incorrect Authorization
CVE-2025-68153
Affects
github.com/juju/juju/apiserver
| Versions
<2.9.56
>=3.0-beta1 <3.6.20
>=4.0-beta1
M
Allocation of Resources Without Limits or Throttling
CVE-2026-33219
Affects
github.com/nats-io/nats-server/v2/server
| Versions
<2.11.15
>=2.12.0-RC.1 <2.12.6
M
Server-side Request Forgery (SSRF)
CVE-2026-33990
Affects
github.com/docker/model-runner/pkg/distribution/oci/remote
| Versions
<1.1.25
H
Missing Authorization
CVE-2026-29073
Affects
github.com/siyuan-note/siyuan/kernel/util
| Versions
<3.6.2
H
SQL Injection
CVE-2026-33643
Affects
github.com/schemahero/schemahero/plugins/mysql/lib
| Versions
*
H
SQL Injection
CVE-2026-33643
Affects
github.com/schemahero/schemahero/plugins/postgres/lib
| Versions
*
M
Unchecked Input for Loop Condition
CVE-2026-33029
Affects
github.com/0xjacky/nginx-ui/settings
| Versions
<2.3.4
M
Unchecked Input for Loop Condition
CVE-2026-33029
Affects
github.com/0xjacky/nginx-ui/internal/cron
| Versions
<2.3.4
M
Unchecked Input for Loop Condition
CVE-2026-33029
Affects
github.com/0xjacky/nginx-ui/api/settings
| Versions
<2.3.4
M
Race Condition
CVE-2026-33028
Affects
github.com/0xjacky/nginx-ui/api/settings
| Versions
<2.3.4
M
Race Condition
CVE-2026-33028
Affects
github.com/0xjacky/nginx-ui/settings
| Versions
<2.3.4
H
Authorization Bypass Through User-Controlled Key
CVE-2026-33030
Affects
github.com/0xjacky/nginx-ui/internal/migrate
| Versions
<2.3.5
H
Authorization Bypass Through User-Controlled Key
CVE-2026-33030
Affects
github.com/0xjacky/nginx-ui/model
| Versions
<2.3.5
H
Authorization Bypass Through User-Controlled Key
CVE-2026-33030
Affects
github.com/0xjacky/nginx-ui/api/certificate
| Versions
<2.3.5
H
Authorization Bypass Through User-Controlled Key
CVE-2026-33030
Affects
github.com/0xjacky/nginx-ui/api/sites
| Versions
<2.3.5
H
Improper Validation of Integrity Check Value
CVE-2026-33026
Affects
github.com/0xjacky/nginx-ui/internal/backup
| Versions
<2.3.4
M
Cross-site Scripting (XSS)
CVE-2026-35166
Affects
github.com/gohugoio/hugo/markup/goldmark
| Versions
>=0.60.0 <0.159.2
H
Missing Encryption of Sensitive Data
CVE-2026-34992
Affects
antrea.io/antrea/pkg/agent/openflow
| Versions
<2.4.5
>=2.5.0 <2.5.2