Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Cross-site Scripting (XSS)
CVE-2026-27210
Affects
org.webjars.npm:pannellum
| Versions
[2.5.1,]
H
Incorrect Regular Expression
CVE-2026-25896
Affects
org.webjars.npm:fast-xml-parser
| Versions
[4.2.5,]
M
Arbitrary File Upload
CVE-2026-2666
Affects
net.mingsoft:ms-mcms
| Versions
[0,]
H
Cross-site Scripting (XSS)
CVE-2025-14340
Affects
org.glassfish.main.admin:rest-service
| Versions
[0,]
H
Cross-site Scripting (XSS)
CVE-2025-14340
Affects
fish.payara.distributions:payara
| Versions
[,7.2026.1)
M
Cross-site Scripting (XSS)
CVE-2026-27121
Affects
org.webjars.npm:svelte
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2026-27122
Affects
org.webjars.npm:svelte
| Versions
[0,]
M
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-27125
Affects
org.webjars.npm:svelte
| Versions
[0,]
M
Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2026-27100
Affects
org.jenkins-ci.main:jenkins-core
| Versions
[,2.541.2)
[2.500,2.551)
H
Cross-site Scripting (XSS)
CVE-2026-27099
Affects
org.jenkins-ci.main:jenkins-core
| Versions
[2.483,2.541.2)
[2.500,2.551)
C
Prototype Pollution
CVE-2026-27212
Affects
org.webjars.npm:swiper
| Versions
[6.5.7,]
H
Improper Encoding or Escaping of Output
CVE-2026-25940
Affects
org.webjars.npm:jspdf
| Versions
[,4.2.0)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-25535
Affects
org.webjars.npm:jspdf
| Versions
[,4.2.0)
H
Improper Encoding or Escaping of Output
CVE-2026-25755
Affects
org.webjars.npm:jspdf
| Versions
[,4.2.0)
H
Regular Expression Denial of Service (ReDoS)
CVE-2026-26996
Affects
org.webjars.npm:minimatch
| Versions
[0,]
M
Improper Authorization
CVE-2026-2733
Affects
org.keycloak:keycloak-services
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2026-27013
Affects
org.webjars.npm:fabric
| Versions
[0,]
L
Improper Authorization
CVE-2026-24733
Affects
org.apache.tomcat.embed:tomcat-embed-core
| Versions
[,9.0.113)
[10.1.0-M1,10.1.50)
[11.0.0-M1,11.0.15)
L
Improper Authorization
CVE-2026-24733
Affects
org.apache.tomcat:tomcat-coyote
| Versions
[,9.0.113)
[10.1.0-M1,10.1.50)
[11.0.0-M1,11.0.15)
H
Incorrect Authorization
CVE-2026-24734
Affects
org.apache.tomcat:tomcat-coyote-ffm
| Versions
[9.0.83,9.0.114)
[10.1.0-M7,10.1.52)
[11.0.0-M1,11.0.18)
H
Incorrect Authorization
CVE-2026-24734
Affects
org.apache.tomcat.embed:tomcat-embed-core
| Versions
[9.0.83,9.0.114)
[10.1.0-M7,10.1.52)
[11.0.0-M1,11.0.18)
H
Improper Certificate Validation
CVE-2025-66614
Affects
org.apache.tomcat.embed:tomcat-embed-core
| Versions
[8.5.0,9.0.113)
[10.0.0-M1,10.1.50)
[11.0.0-M1,11.0.15)
H
Improper Certificate Validation
CVE-2025-66614
Affects
org.apache.tomcat:tomcat-coyote
| Versions
[8.5.0,9.0.113)
[10.0.0-M1,10.1.50)
[11.0.0-M1,11.0.15)
H
Directory Traversal
CVE-2026-26960
Affects
org.webjars.npm:tar
| Versions
[0,]
H
Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-2575
Affects
org.keycloak:keycloak-services
| Versions
[1.9.0.CR1,]
H
Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-2575
Affects
org.keycloak:keycloak-saml-adapter-core
| Versions
[1.9.0.CR1,]
H
Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-2575
Affects
org.keycloak:keycloak-saml-core
| Versions
[1.9.0.CR1,]
M
Regular Expression Denial of Service (ReDoS)
CVE-2026-2327
Affects
org.webjars.npm:markdown-it
| Versions
[13.0.1,]
H
Missing Authorization
CVE-2026-25903
Affects
org.apache.nifi:nifi-web-api
| Versions
[1.1.0,2.8.0)
H
Arbitrary Code Injection
CVE-2025-33042
Affects
org.apache.avro:avro-compiler
| Versions
[,1.11.5)
[1.12.0,1.12.1)