Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
HTTP Request Smuggling
CVE-2026-24880
Affects
org.apache.tomcat:tomcat-coyote
| Versions
[7.0.0,9.0.116)
[10.1.0-M1,10.1.53)
[11.0.0-M1,11.0.20)
H
Use of a Broken or Risky Cryptographic Algorithm
CVE-2026-29129
Affects
org.apache.tomcat:tomcat-coyote
| Versions
[9.0.114,9.0.116)
[10.1.51,10.1.53)
[11.0.16,11.0.20)
H
Use of a Broken or Risky Cryptographic Algorithm
CVE-2026-29129
Affects
org.apache.tomcat.embed:tomcat-embed-core
| Versions
[9.0.114,9.0.116)
[10.1.51,10.1.53)
[11.0.16,11.0.20)
M
Insertion of Sensitive Information into Log File
CVE-2026-34487
Affects
org.apache.tomcat:tomcat-tribes
| Versions
[9.0.13,9.0.117)
[10.1.0-M1,10.1.54)
[11.0.0-M1,11.0.21)
H
Missing Encryption of Sensitive Data
CVE-2026-34486
Affects
org.apache.tomcat:tomcat-tribes
| Versions
[9.0.116,9.0.117)
[10.1.53,10.1.54)
[11.0.20,11.0.21)
H
Use of a Broken or Risky Cryptographic Algorithm
CVE-2026-29146
Affects
org.apache.tomcat:tomcat-tribes
| Versions
[9.0.13,9.0.116)
[10.1.50,10.1.53)
[11.0.0-M1,11.0.20)
H
Improper Authentication
CVE-2026-34500
Affects
org.apache.tomcat.embed:tomcat-embed-core
| Versions
[,9.0.117)
[10.1.0-M7,10.1.54)
[11.0.0-M1,11.0.21)
H
Improper Authentication
CVE-2026-34500
Affects
org.apache.tomcat:tomcat-coyote-ffm
| Versions
[9.0.93,9.0.117)
[10.1.26,10.1.54)
[11.0.0-M24,11.0.21)
H
Improper Authentication
CVE-2026-34500
Affects
org.apache.tomcat:tomcat-coyote
| Versions
[10.1.22,10.1.26)
[11.0.0-M14,11.0.0-M24)
H
Improper Authentication
CVE-2026-29145
Affects
org.apache.tomcat:tomcat-coyote
| Versions
[10.1.0-M7,10.1.26)
[11.0.0-M1,11.0.0-M24)
H
Improper Authentication
CVE-2026-29145
Affects
org.apache.tomcat.embed:tomcat-embed-core
| Versions
[,9.0.116)
[10.1.0-M7,10.1.53)
[11.0.0-M1,11.0.20)
H
Improper Authentication
CVE-2026-29145
Affects
org.apache.tomcat:tomcat-coyote-ffm
| Versions
[9.0.93,9.0.116)
[10.1.26,10.1.53)
[11.0.0-M24,11.0.20)
M
Improper Encoding or Escaping of Output
CVE-2026-34483
Affects
org.apache.tomcat.embed:tomcat-embed-core
| Versions
[,9.0.117)
[10.1.0-M1,10.1.54)
[11.0.0-M1,11.0.21)
M
Improper Encoding or Escaping of Output
CVE-2026-34483
Affects
org.apache.tomcat:tomcat-catalina
| Versions
[,9.0.117)
[10.1.0-M1,10.1.54)
[11.0.0-M1,11.0.21)
H
Improperly Controlled Modification of Dynamically-Determined Object Attributes
Affects
org.webjars.npm:mathjs
| Versions
[0,]
H
HTTP Response Splitting
CVE-2026-40175
Affects
org.webjars.npm:axios
| Versions
[,1.15.0)
H
HTTP Request Smuggling
CVE-2026-28369
Affects
io.undertow:undertow-core
| Versions
[0,]
H
HTTP Request Smuggling
CVE-2026-28367
Affects
io.undertow:undertow-core
| Versions
[0,]
H
Always-Incorrect Control Flow Implementation
CVE-2026-22750
Affects
org.springframework.cloud:spring-cloud-gateway-server
| Versions
[4.2.0,4.2.1)
H
Improper Encoding or Escaping of Output
CVE-2026-34479
Affects
org.apache.logging.log4j:log4j-core
| Versions
[2.7, 2.25.4)
[3.0.0-alpha1,]
H
Improper Encoding or Escaping of Output
CVE-2026-34480
Affects
org.apache.logging.log4j:log4j-core
| Versions
[2.0-alpha1, 2.25.4)
[3.0.0-alpha1,]
H
Improper Encoding or Escaping of Output
CVE-2026-34481
Affects
org.apache.logging.log4j:log4j-layout-template-json
| Versions
[2.14.0, 2.25.4)
[3.0.0-alpha1,]
H
Improper Output Neutralization for Logs
CVE-2026-34478
Affects
org.apache.logging.log4j:log4j-core
| Versions
[2.21.0, 2.25.4)
[3.0.0-beta1,]
M
Improper Validation of Certificate with Host Mismatch
CVE-2026-34477
Affects
org.apache.logging.log4j:log4j-core
| Versions
[2.12.0, 2.25.4)
[3.0.0-alpha1,]
M
Incomplete List of Disallowed Inputs
CVE-2026-39315
Affects
org.webjars.npm:unhead
| Versions
[0,]
M
Unintended Proxy or Intermediary ('Confused Deputy')
CVE-2025-62718
Affects
org.webjars.npm:axios
| Versions
[,1.15.0)
H
Privilege Defined With Unsafe Actions
CVE-2026-27314
Affects
org.apache.cassandra:cassandra-all
| Versions
[5.0-alpha1,5.0.7)
L
Improper Control of Interaction Frequency
CVE-2026-32588
Affects
org.apache.cassandra:cassandra-all
| Versions
[4.0-alpha1,4.0.20)
[4.1-alpha1,4.1.11)
[5.0-alpha1,5.0.7)
C
Sensitive Information in Resource Not Removed Before Reuse
CVE-2026-5795
Affects
org.eclipse.jetty.ee9:jetty-ee9-jaspi
| Versions
[,12.0.34)
[12.1.0.alpha0,12.1.8)
C
Sensitive Information in Resource Not Removed Before Reuse
CVE-2026-5795
Affects
org.eclipse.jetty.ee11:jetty-ee11-jaspi
| Versions
[,12.1.8)