Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Improper Verification of Cryptographic Signature
CVE-2026-1529
Affects
org.keycloak:keycloak-services
| Versions
[,26.5.3)
H
Improper Restriction of Security Token Assignment
CVE-2026-1609
Affects
org.keycloak:keycloak-services
| Versions
[26.5.2,26.5.3)
H
Improperly Implemented Security Check for Standard
CVE-2026-1486
Affects
org.keycloak:keycloak-services
| Versions
[,26.5.3)
M
Incorrect Privilege Assignment
CVE-2025-14778
Affects
org.keycloak:keycloak-services
| Versions
[,26.5.3)
H
Prototype Pollution
CVE-2026-25639
Affects
org.webjars.npm:axios
| Versions
[,1.13.5)
M
Cross-site Scripting (XSS)
CVE-2026-25581
Affects
org.webjars.npm:sceditor
| Versions
[0,]
M
Directory Traversal
CVE-2026-2111
Affects
org.jeecgframework.boot:jeecg-boot-base-core
| Versions
[,3.9.1)
L
Improper Output Neutralization for Logs
CVE-2026-1337
Affects
org.neo4j:neo4j
| Versions
[,2026.01.3)
L
Server-side Request Forgery (SSRF)
CVE-2025-68157
Affects
org.webjars.npm:webpack
| Versions
[5.75.0,]
L
Server-side Request Forgery (SSRF)
CVE-2025-68458
Affects
org.webjars.npm:webpack
| Versions
[5.75.0,]
M
Insertion of Sensitive Information into Log File
CVE-2026-1622
Affects
org.neo4j:neo4j-configuration
| Versions
[,5.26.21)
[2025.01.0,2026.01.3)
C
Arbitrary Code Injection
CVE-2026-1615
Affects
org.webjars.npm:jsonpath
| Versions
[0,]
H
Prototype Pollution
CVE-2025-61140
Affects
org.webjars.npm:jsonpath
| Versions
[0,]
H
Improper Control of Dynamically-Managed Code Resources
CVE-2026-1770
Affects
org.craftercms:craftercms
| Versions
[4.0.0, 4.5.0)
H
External Control of File Name or Path
CVE-2024-5986
Affects
ai.h2o:h2o-core
| Versions
[0,3.46.0.1)
M
XML External Entity (XXE) Injection
CVE-2026-23795
Affects
org.apache.syncope.client.idrepo:syncope-client-idrepo-console
| Versions
[,3.0.16)
[4.0.0,4.0.4)
M
Cross-site Scripting (XSS)
CVE-2026-23794
Affects
org.apache.syncope.client.idrepo:syncope-client-idrepo-common-ui
| Versions
[,3.0.16)
[4.0.0-M0,4.0.4)
C
Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-25526
Affects
com.hubspot.jinjava:jinjava
| Versions
[,2.7.6)
[2.8.0,2.8.3)
H
Improper Encoding or Escaping of Output
CVE-2026-24737
Affects
org.webjars.npm:jspdf
| Versions
[,4.2.0)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-24133
Affects
org.webjars.npm:jspdf
| Versions
[,4.2.0)
L
Race Condition
CVE-2026-24040
Affects
org.webjars.npm:jspdf
| Versions
[,4.2.0)
M
XML Injection
CVE-2026-24043
Affects
org.webjars.npm:jspdf
| Versions
[,4.2.0)
M
Server-side Request Forgery (SSRF)
CVE-2025-15104
Affects
nu.validator:validator
| Versions
[0,]
M
Server-side Request Forgery (SSRF)
CVE-2026-1518
Affects
org.keycloak:keycloak-services
| Versions
[0,]
H
Allocation of Resources Without Limits or Throttling
CVE-2024-4027
Affects
io.undertow:undertow-core
| Versions
[,2.2.39.Final)
[2.3.0.Alpha1,2.3.21.Final)
[2.4.0.Alpha1,2.4.0.Beta1)
H
Cross-site Scripting (XSS)
CVE-2026-1513
Affects
org.webjars.npm:billboard.js
| Versions
[0,]
M
Incorrect Privilege Assignment
CVE-2025-13881
Affects
org.keycloak:keycloak-server-spi-private
| Versions
[,26.5.2)
H
Uncaught Exception
CVE-2026-25128
Affects
org.webjars.npm:fast-xml-parser
| Versions
[5.2.5,]
M
Directory Traversal
CVE-2026-24842
Affects
org.webjars.npm:tar
| Versions
[0,]
M
Improperly Controlled Sequential Memory Allocation
CVE-2026-24819
Affects
com.foxinmy:weixin4j-base
| Versions
[0,]