Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Improper Enforcement of Behavioral Workflow
CVE-2025-14559
Affects
org.keycloak:keycloak-services
| Versions
[,26.5.2)
L
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-1035
Affects
org.keycloak:keycloak-services
| Versions
[0,]
M
Server-side Request Forgery (SSRF)
CVE-2026-1180
Affects
org.keycloak:keycloak-services
| Versions
[0,2.5.6)
L
Missing XML Validation
CVE-2026-1190
Affects
org.keycloak:keycloak-services
| Versions
[0,26.5.4)
H
SQL Injection
CVE-2026-0603
Affects
org.hibernate:hibernate-core
| Versions
[,5.3.38)
M
Improper Handling of Unicode Encoding
CVE-2026-23950
Affects
org.webjars.npm:tar
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2025-15265
Affects
org.webjars.npm:svelte
| Versions
[5.46.0,5.46.4)
M
Use of a Cryptographic Primitive with a Risky Implementation
CVE-2025-14505
Affects
org.webjars.npm:elliptic
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2026-0601
Affects
org.sonatype.nexus:nexus-extdirect
| Versions
[,3.88.0-08)
M
Encoding Error
CVE-2025-29847
Affects
org.apache.linkis:linkis-common
| Versions
[0,]
M
Insertion of Sensitive Information into Log File
CVE-2025-59355
Affects
org.apache.linkis:linkis-metadata
| Versions
[0,]
M
Cross-site Scripting (XSS)
Affects
org.webjars.npm:svelte
| Versions
[,4.2.2)
H
External Control of File Name or Path
CVE-2026-23529
Affects
com.wepay.kcbq:kcbq-connector
| Versions
[0,]
H
HTTP Request Smuggling
CVE-2026-23527
Affects
org.webjars.npm:h3
| Versions
[,1.15.5)
M
Improper Validation of Syntactic Correctness of Input
CVE-2026-0976
Affects
org.keycloak:keycloak-quarkus-server
| Versions
[,26.5.2)
M
HTTP Request Smuggling
CVE-2026-1002
Affects
io.vertx:vertx-core
| Versions
[,4.5.24)
M
Stored XSS
CVE-2026-0858
Affects
net.sourceforge.plantuml:plantuml
| Versions
[,1.2026.0)
M
Server-side Request Forgery (SSRF)
CVE-2026-0600
Affects
org.sonatype.nexus.plugins:nexus-blobstore-s3
| Versions
[,3.88.0-08)
M
Server-side Request Forgery (SSRF)
CVE-2026-0600
Affects
org.sonatype.nexus:nexus-validation
| Versions
[,3.88.0-08)
M
Server-side Request Forgery (SSRF)
CVE-2026-0600
Affects
org.sonatype.nexus:nexus-repository-services
| Versions
[,3.88.0-08)
M
Allocation of Resources Without Limits or Throttling
CVE-2026-22036
Affects
org.webjars.npm:undici
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2026-22787
Affects
org.webjars.npm:html2pdf.js
| Versions
[0,]
H
Use of a Broken or Risky Cryptographic Algorithm
CVE-2025-68702
Affects
net.gleske:jervis
| Versions
[,2.2)
M
Improper Verification of Cryptographic Signature
CVE-2025-68925
Affects
net.gleske:jervis
| Versions
[,2.2)
H
Use of a Broken or Risky Cryptographic Algorithm
CVE-2025-68931
Affects
net.gleske:jervis
| Versions
[,2.2)
H
Use of a Broken or Risky Cryptographic Algorithm
CVE-2025-68701
Affects
net.gleske:jervis
| Versions
[,2.2)
H
Use of a Broken or Risky Cryptographic Algorithm
CVE-2025-68698
Affects
net.gleske:jervis
| Versions
[,2.2)
H
Insecure Randomness
CVE-2025-68704
Affects
net.gleske:jervis
| Versions
[,2.2)
H
Inadequate Encryption Strength
CVE-2025-68703
Affects
net.gleske:jervis
| Versions
[,2.2)
C
Improper Neutralization of Special Elements in Data Query Logic
CVE-2025-66169
Affects
org.apache.camel:camel-neo4j
| Versions
[4.10.0,4.10.8)
[4.14.0,4.14.3)
[4.15.0,4.17.0)