Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Directory Traversal
CVE-2026-66755
Affects
org.apache.tika:tika-parser-scientific-module
| Versions
[,3.3.2)
[4.0.0-alpha-1,4.0.0-beta-1)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-73635
Affects
org.apache.struts:struts2-core
| Versions
[,6.11.0)
[7.0.0,7.3.0)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-68075
Affects
org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol
| Versions
[,10.1.0)
H
Uncontrolled Recursion
CVE-2026-68073
Affects
org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol
| Versions
[,10.1.0)
M
Unsynchronized Access to Shared Data in a Multithreaded Context
CVE-2026-73632
Affects
org.apache.struts:struts2-json-plugin
| Versions
[,7.3.0)
H
Unsynchronized Access to Shared Data in a Multithreaded Context
CVE-2026-73631
Affects
org.apache.struts:struts2-json-plugin
| Versions
[,7.3.0)
C
External Control of Assumed-Immutable Web Parameter
CVE-2026-71300
Affects
org.apache.camel:camel-atmosphere-websocket
| Versions
[4.0.0,4.14.9)
[4.15.0,4.18.4)
[4.19.0,4.22.0)
C
Relative Path Traversal
CVE-2026-66906
Affects
org.apache.camel:camel-azure-storage-blob
| Versions
[4.0.0,4.14.9)
[4.15.0,4.18.4)
[4.19.0,4.22.0)
C
Relative Path Traversal
CVE-2026-66906
Affects
org.apache.camel:camel-azure-storage-datalake
| Versions
[4.0.0,4.14.9)
[4.15.0,4.18.4)
[4.19.0,4.22.0)
H
Improper Authentication
CVE-2026-66908
Affects
org.apache.camel:camel-platform-http-main
| Versions
[4.8.0,4.22.0)
C
Replay Attack
CVE-2026-65905
Affects
org.apache.tomcat:tomcat-catalina
| Versions
[9.0.0.M1,9.0.121)
[11.0.0-M1,10.1.58)
[11.0.0-M1,11.0.25)
H
Improper Handling of URL Encoding (Hex Encoding)
CVE-2026-59083
Affects
org.apache.tomcat:tomcat-catalina
| Versions
[9.0.0.M1, 9.0.120)
[10.1.0-M1, 10.1.57)
[11.0.0-M1, 11.0.24)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-66299
Affects
org.apache.tomcat:tomcat
| Versions
[9.0.89, 9.0.121)
[10.1.24, 10.1.58)
[11.0.0-M20, 11.0.25)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-66299
Affects
org.apache.tomcat:tomcat-websocket
| Versions
[9.0.89, 9.0.121)
[10.1.24, 10.1.58)
[11.0.0-M20, 11.0.25)
M
Improper Validation of Unsafe Equivalence in Input
CVE-2026-65637
Affects
org.apache.tomcat:tomcat-catalina
| Versions
[9.0.115, 9.0.121)
[10.1.53, 10.1.59)
[11.0.20, 11.0.25)
M
Insecure Default Initialization of Resource
CVE-2026-59084
Affects
org.apache.tomcat:tomcat
| Versions
[9.0.13, 9.0.120)
[10.1.0-M1, 10.1.59)
[11.0.0-M1, 11.0.25)
H
Improper Authorization
CVE-2026-66422
Affects
org.apache.tomcat:tomcat-catalina
| Versions
[9.0.25,9.0.121)
[10.1.0-M1,10.1.58)
[11.0.0-M1,11.0.25)
H
Authentication Bypass by Primary Weakness
CVE-2026-68569
Affects
org.apache.tomcat:tomcat-catalina
| Versions
[9.0.0.M1, 9.0.121)
[10.1.0-M1, 10.1.59)
[11.0.0-M1, 11.0.25)
M
Insufficient Session Expiration
CVE-2026-73180
Affects
org.apache.tomcat:tomcat-websocket
| Versions
[9.0.0.M1, 9.0.121)
[10.1.0-M1, 10.1.59)
[11.0.0-M1, 11.0.25)
M
Insufficient Session Expiration
CVE-2026-73180
Affects
org.apache.tomcat:tomcat-catalina
| Versions
[9.0.0.M1, 9.0.121)
[10.1.0-M1, 10.1.59)
[11.0.0-M1, 11.0.25)
C
Missing Critical Step in Authentication
CVE-2026-61466
Affects
org.apache.cxf:cxf-rt-rs-security-oauth2
| Versions
[,3.6.12)
[4.0.0,4.1.8)
[4.2.0,4.2.3)
H
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-57818
Affects
org.apache.cxf:cxf-rt-rs-security-oauth2
| Versions
[,3.6.12)
[4.0.0,4.1.8)
[4.2.0,4.2.3)
C
Insufficient Verification of Data Authenticity
CVE-2026-65583
Affects
org.apache.cxf:cxf-rt-rs-security-sso-oidc
| Versions
[,3.6.12)
[4.0.0,4.1.8)
[4.2.0,4.2.3)
C
Operation on a Resource after Expiration or Release
CVE-2026-68481
Affects
org.apache.cxf:cxf-rt-rs-security-oauth2
| Versions
[,3.6.12)
[4.0.0,4.1.8)
[4.2.0,4.2.3)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-64958
Affects
org.apache.cxf:cxf-core
| Versions
[,3.6.12)
[4.0.0,4.1.8)
[4.2.0,4.2.3)
H
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-65183
Affects
org.apache.tomcat:tomcat-util
| Versions
[9.0.42, 9.0.121)
[10.1.0-M1, 10.1.59)
[11.0.0-M1, 11.0.25)
C
Improper Verification of Cryptographic Signature
CVE-2026-57817
Affects
org.apache.cxf:cxf-rt-rs-security-sso-oidc
| Versions
[,3.6.12)
[4.0.0,4.1.8)
[4.2.0,4.2.3)
M
Replay Attack
CVE-2026-68079
Affects
org.apache.cxf:cxf-rt-rs-security-oauth2
| Versions
[,3.6.12)
[4.0.0,4.1.8)
[4.2.0,4.2.3)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-68763
Affects
org.apache.tomcat:tomcat-coyote
| Versions
[9.0.39, 9.0.121)
[10.1.0-M1, 10.1.59)
[11.0.0-M1, 11.0.25)
H
Insufficient Verification of Data Authenticity
CVE-2026-63687
Affects
org.apache.cxf:cxf-rt-rs-security-oauth2
| Versions
[,3.6.12)
[4.0.0,4.1.8)
[4.2.0,4.2.3)