Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Infinite loop
CVE-2026-59874
Affects
org.webjars.npm:tar
| Versions
[,7.5.18)
M
Incorrect Type Conversion or Cast
CVE-2026-59871
Affects
org.webjars.npm:tar
| Versions
[,7.5.18)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-59873
Affects
org.webjars.npm:tar
| Versions
[,7.5.19)
H
Directory Traversal
CVE-2026-39245
Affects
org.webjars.npm:decompress
| Versions
[0,]
M
Symlink Attack
CVE-2026-39243
Affects
org.webjars.npm:decompress
| Versions
[0,]
M
Symlink Attack
CVE-2026-39246
Affects
org.webjars.npm:decompress
| Versions
[0,]
H
Arbitrary Code Injection
CVE-2026-73651
Affects
org.webjars.npm:typeorm
| Versions
[,0.3.31)
[1.0.0,1.1.0)
M
Incomplete List of Disallowed Inputs
CVE-2026-73650
Affects
org.webjars.npm:svgo
| Versions
[,2.8.3)
[3.0.0,3.3.4)
[4.0.0,4.0.2)
H
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
CVE-2026-73569
Affects
org.webjars.npm:fast-xml-parser
| Versions
[5.9.3,5.10.1)
H
Interpretation Conflict
CVE-2026-16221
Affects
org.webjars.npm:fast-uri
| Versions
[2.3.1,2.4.3)
[3.0.0,3.1.4)
[4.0.0,4.1.1)
M
Regular Expression Denial of Service (ReDoS)
CVE-2023-26117
Affects
org.webjars.npm:angular-resource
| Versions
[0,]
H
Allocation of Resources Without Limits or Throttling
CVE-2026-54490
Affects
org.webjars.npm:websocket-driver
| Versions
[,0.7.5)
H
Improper Encoding or Escaping of Output
CVE-2026-70609
Affects
org.webjars.npm:electron
| Versions
[,39.8.7)
[40.0.0-alpha.2,40.9.1)
[41.0.0-alpha.1,41.2.0)
[42.0.0-alpha.1,42.0.0-beta.1)
M
External Control of System or Configuration Setting
CVE-2026-70607
Affects
org.webjars.npm:electron
| Versions
[,39.8.8)
[40.0.0-alpha.2,40.9.1)
[41.0.0-alpha.1,41.2.1)
[42.0.0-alpha.1,42.0.0-beta.3)
M
Command Injection
CVE-2026-70611
Affects
org.webjars.npm:electron
| Versions
[,39.8.9)
[40.0.0-alpha.2,40.9.2)
[41.0.0-alpha.1,41.2.1)
[42.0.0-alpha.1,42.0.0-beta.3)
M
Authentication Bypass by Primary Weakness
CVE-2026-70606
Affects
org.webjars.npm:electron
| Versions
[40.0.0-alpha.2,40.10.6)
[41.0.0-alpha.1,41.9.1)
[42.0.0-alpha.1,42.5.1)
[43.0.0-alpha.1,43.0.0)
L
Improper Restriction of Rendered UI Layers or Frames
CVE-2026-70600
Affects
org.webjars.npm:electron
| Versions
[,39.8.8)
[40.0.0-alpha.2,40.9.1)
[41.0.0-alpha.1,41.2.1)
[42.0.0-alpha.1,42.0.0-beta.3)
M
Exposure of Data Element to Wrong Session
CVE-2026-70602
Affects
org.webjars.npm:electron
| Versions
[,39.8.8)
[40.0.0-alpha.2,40.9.1)
[41.0.0-alpha.1,41.2.1)
[42.0.0-alpha.1,42.0.0-beta.3)
H
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-70597
Affects
org.webjars.npm:electron
| Versions
[,39.8.8)
[40.0.0-alpha.2,40.9.1)
[41.0.0-alpha.1,41.2.1)
[42.0.0-alpha.1,42.0.0-beta.3)
M
Out-of-bounds Read
CVE-2026-70598
Affects
org.webjars.npm:electron
| Versions
[,39.8.10)
[40.0.0-alpha.2,40.9.1)
[41.0.0-alpha.1,41.2.1)
[42.0.0-alpha.1,42.0.0-beta.3)
M
Incorrect Permission Assignment for Critical Resource
CVE-2026-70612
Affects
org.webjars.npm:electron
| Versions
[,39.8.8)
[40.0.0-alpha.2,40.9.1)
[41.0.0-alpha.1,41.2.1)
[42.0.0-alpha.1,42.0.0-beta.3)
H
Origin Validation Error
CVE-2026-70599
Affects
org.webjars.npm:electron
| Versions
[,39.8.7)
[40.0.0-alpha.2,40.9.1)
[41.0.0-alpha.1,41.2.0)
[42.0.0-alpha.1,42.0.0-beta.1)
M
Permissive Cross-domain Policy with Untrusted Domains
CVE-2026-70604
Affects
org.webjars.npm:electron
| Versions
[,39.8.10)
[40.0.0-alpha.2,40.9.3)
[41.0.0-alpha.1,41.4.0)
[42.0.0-alpha.1,42.0.0)
M
Improper Neutralization of Null Byte or NUL Character
CVE-2026-70603
Affects
org.webjars.npm:electron
| Versions
[,39.8.6)
[40.0.0-alpha.2,40.9.1)
[41.0.0-alpha.1,41.1.1)
[42.0.0-alpha.1,42.0.0-beta.1)
H
Server-side Request Forgery (SSRF)
CVE-2026-70605
Affects
org.webjars.npm:electron
| Versions
[,39.8.8)
[40.0.0-alpha.2,40.9.1)
[41.0.0-alpha.1,41.2.1)
[42.0.0-alpha.1,42.0.0-beta.3)
H
Symlink Attack
CVE-2026-71476
Affects
org.webjars.npm:nx
| Versions
[20.8.0,22.7.7)
[23.0.0,23.0.2)
[23.1.0-beta.0,23.1.0-beta.5)
H
Inefficient Algorithmic Complexity
Affects
org.webjars.npm:js-yaml
| Versions
[3.0.0,3.15.1)
[4.0.0,4.3.1)
M
Cross-site Scripting (XSS)
CVE-2026-75838
Affects
org.webjars.npm:dompurify
| Versions
[,3.4.13)
M
Information Exposure
CVE-2026-72744
Affects
org.webjars.npm:nuxt
| Versions
[3.21.7,3.21.10)
[4.4.7,4.5.1)
C
Command Injection
CVE-2026-14802
Affects
org.webjars.npm:react-dev-utils
| Versions
[0,]