Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Inefficient Algorithmic Complexity
CVE-2026-13311
Affects
org.webjars.npm:shell-quote
| Versions
[0,]
M
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-54515
Affects
tools.jackson.core:jackson-databind
| Versions
[0,]
M
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-54515
Affects
com.fasterxml.jackson.core:jackson-databind
| Versions
[2.8.0.rc1,]
M
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-54516
Affects
com.fasterxml.jackson.core:jackson-databind
| Versions
[2.21.0,2.21.4)
M
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-54516
Affects
tools.jackson.core:jackson-databind
| Versions
[,3.1.4)
C
Deserialization of Untrusted Data
CVE-2026-54512
Affects
com.fasterxml.jackson.core:jackson-databind
| Versions
[2.10.0,2.18.8)
[2.19.0,2.21.4)
C
Deserialization of Untrusted Data
CVE-2026-54512
Affects
tools.jackson.core:jackson-databind
| Versions
[,3.1.4)
C
Incomplete List of Disallowed Inputs
CVE-2026-54513
Affects
com.fasterxml.jackson.core:jackson-databind
| Versions
[2.10.0,2.18.8)
[2.19.0,2.21.4)
C
Incomplete List of Disallowed Inputs
CVE-2026-54513
Affects
tools.jackson.core:jackson-databind
| Versions
[,3.1.4)
M
Incorrect Authorization
CVE-2026-54518
Affects
com.fasterxml.jackson.core:jackson-databind
| Versions
[2.21.0,2.21.4)
M
Incorrect Authorization
CVE-2026-54518
Affects
tools.jackson.core:jackson-databind
| Versions
[,3.1.4)
M
Allocation of Resources Without Limits or Throttling
CVE-2026-50193
Affects
com.fasterxml.jackson.core:jackson-databind
| Versions
[2.10.0,2.14.0-rc1)
M
Incorrect Authorization
CVE-2026-54517
Affects
com.fasterxml.jackson.core:jackson-databind
| Versions
[2.21.0,2.21.4)
M
Incorrect Authorization
CVE-2026-54517
Affects
tools.jackson.core:jackson-databind
| Versions
[,3.1.4)
M
Server-side Request Forgery (SSRF)
CVE-2026-54514
Affects
com.fasterxml.jackson.core:jackson-databind
| Versions
[2.0.0,2.18.8)
[2.19.0,2.21.4)
M
Server-side Request Forgery (SSRF)
CVE-2026-54514
Affects
tools.jackson.core:jackson-databind
| Versions
[,3.1.4)
L
Cross-site Scripting (XSS)
CVE-2026-44793
Affects
org.openidentityplatform.openam:openam-oauth2
| Versions
[,16.1.1)
M
Deserialization of Untrusted Data
CVE-2026-44795
Affects
io.spinnaker.keel:keel-core
| Versions
[,2025.3.3)
[2025.4.0,2025.4.4)
[2026.0.0,2026.0.3)
M
Deserialization of Untrusted Data
CVE-2026-44795
Affects
io.spinnaker.kork:kork-secrets
| Versions
[,2025.3.3)
[2025.4.0,2025.4.4)
[2026.0.0,2026.0.3)
M
Deserialization of Untrusted Data
CVE-2026-44795
Affects
io.spinnaker.orca:orca-clouddriver
| Versions
[,2025.3.3)
[2025.4.0,2025.4.4)
[2026.0.0,2026.0.3)
M
Deserialization of Untrusted Data
CVE-2026-44795
Affects
io.spinnaker.rosco:rosco-manifests
| Versions
[,2025.3.3)
[2025.4.0,2025.4.4)
[2026.0.0,2026.0.3)
C
Deserialization of Untrusted Data
CVE-2026-46495
Affects
org.openidentityplatform.opendj:opendj-server-legacy
| Versions
[,5.1.1)
M
Uncaught Exception
CVE-2026-12644
Affects
org.webjars.npm:ts-deepmerge
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2026-55847
Affects
io.qameta.allure:allure-generator
| Versions
[,2.39.0)
M
Incorrect Authorization
CVE-2026-32967
Affects
org.apache.dolphinscheduler:dolphinscheduler-api
| Versions
[,3.4.2)
M
Incorrect Authorization
CVE-2026-41280
Affects
org.apache.dolphinscheduler:dolphinscheduler-api
| Versions
[,3.4.2)
H
Incorrect Authorization
CVE-2026-32966
Affects
org.apache.dolphinscheduler:dolphinscheduler-api
| Versions
[,3.4.2)
H
Incorrect Authorization
CVE-2026-42357
Affects
org.apache.dolphinscheduler:dolphinscheduler-api
| Versions
[,3.4.2)
H
Key Exchange without Entity Authentication
CVE-2026-11745
Affects
com.linecorp.centraldogma:centraldogma-server-mirror-git
| Versions
[,0.84.0)
C
Use of Hard-coded Credentials
CVE-2026-11746
Affects
com.linecorp.centraldogma:centraldogma-server
| Versions
[,0.84.0)