Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Prototype Pollution
CVE-2026-44290
Affects
org.webjars.npm:protobufjs
| Versions
[0,]
M
Prototype Pollution
CVE-2026-44292
Affects
org.webjars.npm:protobufjs
| Versions
[0,]
C
Arbitrary Code Injection
CVE-2026-44672
Affects
org.mapfish.print:print-lib
| Versions
[0, ]
H
Prototype Pollution
CVE-2026-44291
Affects
org.webjars.npm:protobufjs
| Versions
[0,]
M
Improper Check for Unusual or Exceptional Conditions
CVE-2026-44294
Affects
org.webjars.npm:protobufjs
| Versions
[0,]
H
Uncontrolled Recursion
CVE-2026-44289
Affects
org.webjars.npm:protobufjs
| Versions
[0,]
M
Timing Attack
CVE-2026-43514
Affects
org.apache.tomcat:tomcat
| Versions
[,9.0.118)
[10.1.0-M1,10.1.55)
[11.0.0-M1,11.0.22)
M
Timing Attack
CVE-2026-43514
Affects
org.apache.tomcat:tomcat-coyote
| Versions
[,9.0.118)
[10.1.0-M1,10.1.55)
[11.0.0-M1,11.0.22)
M
Timing Attack
CVE-2026-43514
Affects
org.apache.tomcat.embed:tomcat-embed-core
| Versions
[,9.0.118)
[10.1.0-M1,10.1.55)
[11.0.0-M1,11.0.22)
M
Timing Attack
CVE-2026-43514
Affects
org.apache.tomcat:tomcat-catalina
| Versions
[,9.0.118)
[10.1.0-M1,10.1.55)
[11.0.0-M1,11.0.22)
M
Exposure of Private Personal Information to an Unauthorized Actor
CVE-2026-42498
Affects
org.apache.tomcat.embed:tomcat-embed-websocket
| Versions
[7.0.83,8.0.1)
[8.5.24,9.0.0.M1)
[9.0.2,9.0.118)
[10.1.0-M1,10.1.55)
[11.0.0-M1,11.0.22)
M
Exposure of Private Personal Information to an Unauthorized Actor
CVE-2026-42498
Affects
org.apache.tomcat:tomcat-websocket
| Versions
[8.5.24,9.0.0.M1)
[9.0.2,9.0.118)
[10.1.0-M1,10.1.55)
[11.0.0-M1,11.0.22)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-41284
Affects
org.apache.tomcat.embed:tomcat-embed-core
| Versions
[9.0.0.M1,9.0.118)
[10.1.0-M1,10.1.55)
[11.0.0-M1,11.0.22)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-41284
Affects
org.apache.tomcat:tomcat-catalina
| Versions
[9.0.0.M1,9.0.118)
[10.1.0-M1,10.1.55)
[11.0.0-M1,11.0.22)
M
Improper Handling of Unicode Encoding
CVE-2026-44288
Affects
org.webjars.npm:protobufjs
| Versions
[0,]
C
Session Fixation
CVE-2026-40010
Affects
org.apache.wicket:wicket-auth-roles
| Versions
[8.0.0-M1,10.9.0)
H
Directory Traversal
CVE-2026-6321
Affects
org.webjars.npm:fast-uri
| Versions
[,3.1.2)
C
Eval Injection
CVE-2026-44643
Affects
org.webjars.npm:angular-expressions
| Versions
[0,]
M
Server-side Request Forgery (SSRF)
CVE-2026-36764
Affects
org.springblade:blade-starter-report
| Versions
[0,]
M
Exposed Dangerous Method or Function
CVE-2026-6402
Affects
org.webjars.npm:webpack-dev-server
| Versions
[0,]
M
Arbitrary Code Injection
CVE-2026-41159
Affects
org.webjars.npm:mermaid
| Versions
[,11.15.0)
M
Arbitrary Code Injection
CVE-2026-41149
Affects
org.webjars.npm:mermaid
| Versions
[,11.15.0)
M
Arbitrary Code Injection
CVE-2026-41148
Affects
org.webjars.npm:mermaid
| Versions
[,11.15.0)
M
Infinite loop
CVE-2026-41150
Affects
org.webjars.npm:mermaid
| Versions
[,11.15.0)
C
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CVE-2026-41883
Affects
org.omnifaces:omnifaces
| Versions
[,1.14.2)
[2.0-RC1,2.7.32)
[3.0-RC1,3.14.16)
[4.0-M1,4.7.5)
[5.0-M1,5.2.3)
H
Incorrect Authorization
CVE-2026-44221
Affects
com.arcadedb:arcadedb-engine
| Versions
[,26.4.2)
H
Incorrect Authorization
CVE-2026-44221
Affects
com.arcadedb:arcadedb-server
| Versions
[,26.4.2)
M
Improper Neutralization of Special Elements in Data Query Logic
CVE-2026-7045
Affects
com.baomidou:dynamic-datasource-spring-boot-common
| Versions
[2.5.0,]
M
Cross-site Scripting (XSS)
CVE-2026-42338
Affects
org.webjars.npm:ip-address
| Versions
[0,]
C
Remote Code Execution (RCE)
CVE-2026-32604
Affects
io.spinnaker.clouddriver:clouddriver-artifacts-gitrepo
| Versions
[,2026.0.1)