Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Cross-site Scripting (XSS)
Affects
com.vaadin:vaadin-server
| Versions
[7.0.0,7.7.50)
[8.0.0,8.30.0)
M
Cross-site Scripting (XSS)
Affects
com.vaadin:vaadin-spreadsheet-flow
| Versions
[23.1.0,23.6.6)
[24.0.0,24.8.14)
[24.9.0,24.9.6)
M
Cross-site Scripting (XSS)
Affects
com.xnx3.wangmarket:wangmarket
| Versions
[0,]
M
Cross-site Scripting (XSS)
Affects
com.xnx3.wangmarket:wangmarket
| Versions
[0,]
M
Cross-site Scripting (XSS)
Affects
com.xnx3.wangmarket:wangmarket
| Versions
[0,]
H
Memory Allocation with Excessive Size Value
Affects
org.msgpack:msgpack-core
| Versions
[0.7.0-M6,0.9.11)
M
Cross-site Scripting (XSS)
Affects
org.webjars.npm:trix
| Versions
[0,]
H
Allocation of Resources Without Limits or Throttling
Affects
org.webjars.npm:qs
| Versions
[0,]
H
Prototype Pollution
Affects
org.webjars.npm:pace-js
| Versions
[0,]
H
Deserialization of Untrusted Data
Affects
org.apache.nifi:nifi-asana-processors
| Versions
[1.20.0,2.7.0)
H
Directory Traversal
Affects
org.takes:takes
| Versions
[0,)
H
Allocation of Resources Without Limits or Throttling
Affects
org.elasticsearch.plugin:x-pack-security
| Versions
[,8.19.9)
[9.0.0-beta1,9.1.9)
[9.2.0,9.2.3)
M
Allocation of Resources Without Limits or Throttling
Affects
org.elasticsearch:elasticsearch
| Versions
[7.0.0-alpha1,8.19.8)
[9.0.0-beta1,9.1.8)
[9.2.0,9.2.2)
M
Improper Validation of Certificate with Host Mismatch
Affects
org.apache.logging.log4j:log4j-core
| Versions
[,2.25.3)
M
Use of a Broken or Risky Cryptographic Algorithm
Affects
software.amazon.encryption.s3:amazon-s3-encryption-client-java
| Versions
[,3.6.0)
H
Allocation of Resources Without Limits or Throttling
Affects
org.bitbucket.b_c:jose4j
| Versions
[,0.9.6)
M
Improper Verification of Cryptographic Signature
Affects
org.altcha:altcha
| Versions
[,1.3.0)
M
Arbitrary Code Injection
Affects
com.aizuda:snail-job-common-core
| Versions
[,1.7.0-beta1)
H
Authentication Bypass by Alternate Name
Affects
org.keycloak:keycloak-services
| Versions
[0,]
M
Cross-site Scripting (XSS)
Affects
org.lucee:core
| Versions
[0,]
M
CRLF Injection
Affects
io.netty:netty-codec-http
| Versions
[,4.1.129.Final)
[4.2.0.Alpha1,4.2.8.Final)
H
Improper Certificate Validation
Affects
org.elasticsearch.plugin:x-pack-core
| Versions
[7.8.1,8.19.8)
[9.0.0-beta1,9.1.8)
[9.2.0,9.2.2)
H
Improper Certificate Validation
Affects
org.elasticsearch.plugin:x-pack-security
| Versions
[7.8.1,8.19.8)
[9.0.0-beta1,9.1.8)
[9.2.0,9.2.2)
H
Improper Certificate Validation
Affects
org.elasticsearch:elasticsearch-ssl-config
| Versions
[7.8.1,8.19.8)
[9.0.0-beta1,9.1.8)
[9.2.0,9.2.2)
M
Directory Traversal
Affects
org.webjars.npm:mjml-core
| Versions
[0,]
H
Insertion of Sensitive Information Into Sent Data
Affects
io.airlift:aircompressor-v3
| Versions
[,3.4)
H
Insertion of Sensitive Information Into Sent Data
Affects
io.airlift:aircompressor
| Versions
[0,)
M
Cross-site Scripting (XSS)
Affects
org.webjars.npm:vuetify
| Versions
[2.0.0,3.0.0)
H
Incorrect Authorization
Affects
com.liferay:com.liferay.object.scripting.impl
| Versions
[,1.0.3)
H
Incorrect Authorization
Affects
com.liferay:com.liferay.object.scripting.api
| Versions
[,2.0.0)