Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Directory Traversal
CVE-2026-26960
Affects
org.webjars.npm:tar
| Versions
[0,]
H
Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-2575
Affects
org.keycloak:keycloak-services
| Versions
[1.9.0.CR1,]
H
Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-2575
Affects
org.keycloak:keycloak-saml-adapter-core
| Versions
[1.9.0.CR1,]
H
Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-2575
Affects
org.keycloak:keycloak-saml-core
| Versions
[1.9.0.CR1,]
M
Regular Expression Denial of Service (ReDoS)
CVE-2026-2327
Affects
org.webjars.npm:markdown-it
| Versions
[13.0.1,]
H
Missing Authorization
CVE-2026-25903
Affects
org.apache.nifi:nifi-web-api
| Versions
[1.1.0,2.8.0)
H
Arbitrary Code Injection
CVE-2025-33042
Affects
org.apache.avro:avro-compiler
| Versions
[,1.11.5)
[1.12.0,1.12.1)
C
Improper Validation of Certificate with Host Mismatch
CVE-2026-26214
Affects
com.xiaomi.infra.galaxy:galaxy-fds-sdk-android
| Versions
[0,]
H
Denial of Service (DoS)
CVE-2025-70886
Affects
run.halo.app:api
| Versions
[0,]
L
Authorization Bypass Through User-Controlled Key
CVE-2026-2366
Affects
org.keycloak:keycloak-services
| Versions
[0,]
M
Improper Restriction of Rendered UI Layers or Frames
CVE-2026-26000
Affects
org.xwiki.platform:xwiki-platform-web-war
| Versions
[,17.4.6)
M
Improper Restriction of Rendered UI Layers or Frames
CVE-2026-26000
Affects
org.xwiki.platform:xwiki-platform-url-default
| Versions
[,17.4.6)
M
Improper Restriction of Rendered UI Layers or Frames
CVE-2026-26000
Affects
org.xwiki.platform:xwiki-platform-url-api
| Versions
[,17.4.6)
H
Regular Expression Denial of Service (ReDoS)
CVE-2025-69873
Affects
org.webjars.npm:ajv
| Versions
[0,]
H
Insertion of Sensitive Information Into Sent Data
CVE-2026-26010
Affects
org.open-metadata:openmetadata-service
| Versions
[,1.11.8)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-2391
Affects
org.webjars.npm:qs
| Versions
[0,]
M
Improper Output Neutralization for Logs
CVE-2025-11537
Affects
io.quarkus:quarkus-vertx-http
| Versions
[,3.27.2)
[3.28.0.CR1,3.29.1)
C
Missing Authentication
CVE-2026-23906
Affects
org.apache.druid.extensions:druid-basic-security
| Versions
[0.17.0,36.0.0)
M
Authentication Bypass by Alternate Name
CVE-2026-23903
Affects
org.apache.shiro:shiro-core
| Versions
[,2.1.0)
L
Timing Attack
CVE-2026-23901
Affects
org.apache.shiro:shiro-core
| Versions
[,2.1.0)
H
Improper Verification of Cryptographic Signature
CVE-2026-1529
Affects
org.keycloak:keycloak-services
| Versions
[,26.5.3)
H
Improper Restriction of Security Token Assignment
CVE-2026-1609
Affects
org.keycloak:keycloak-services
| Versions
[26.5.2,26.5.3)
H
Improperly Implemented Security Check for Standard
CVE-2026-1486
Affects
org.keycloak:keycloak-services
| Versions
[,26.5.3)
M
Incorrect Privilege Assignment
CVE-2025-14778
Affects
org.keycloak:keycloak-services
| Versions
[,26.5.3)
H
Prototype Pollution
CVE-2026-25639
Affects
org.webjars.npm:axios
| Versions
[,1.13.5)
M
Cross-site Scripting (XSS)
CVE-2026-25581
Affects
org.webjars.npm:sceditor
| Versions
[0,]
M
Directory Traversal
CVE-2026-2111
Affects
org.jeecgframework.boot:jeecg-boot-base-core
| Versions
[,3.9.1)
L
Improper Output Neutralization for Logs
CVE-2026-1337
Affects
org.neo4j:neo4j
| Versions
[,2026.01.3)
L
Server-side Request Forgery (SSRF)
CVE-2025-68157
Affects
org.webjars.npm:webpack
| Versions
[5.75.0,]
L
Server-side Request Forgery (SSRF)
CVE-2025-68458
Affects
org.webjars.npm:webpack
| Versions
[5.75.0,]