Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
L
Missing Authorization
CVE-2026-34766
Affects
org.webjars.npm:electron
| Versions
[0,]
M
HTTP Response Splitting
CVE-2026-34767
Affects
org.webjars.npm:electron
| Versions
[0,]
M
Origin Validation Error
CVE-2026-34777
Affects
org.webjars.npm:electron
| Versions
[0,]
H
Command Injection
CVE-2026-34779
Affects
org.webjars.npm:electron
| Versions
[0,]
M
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-34773
Affects
org.webjars.npm:electron
| Versions
[0,]
H
Use After Free
CVE-2026-34770
Affects
org.webjars.npm:electron
| Versions
[0,]
M
Use After Free
CVE-2026-34772
Affects
org.webjars.npm:electron
| Versions
[0,]
M
Insufficient Verification of Data Authenticity
CVE-2026-34778
Affects
org.webjars.npm:electron
| Versions
[0,]
H
Use After Free
CVE-2026-34771
Affects
org.webjars.npm:electron
| Versions
[0,]
M
Out-of-bounds Read
CVE-2026-34776
Affects
org.webjars.npm:electron
| Versions
[0,]
H
Improper Isolation or Compartmentalization
CVE-2026-34775
Affects
org.webjars.npm:electron
| Versions
[0,]
C
Use After Free
CVE-2026-34774
Affects
org.webjars.npm:electron
| Versions
[0,]
H
Hidden Functionality
CVE-2026-34769
Affects
org.webjars.npm:electron
| Versions
[0,]
M
Permissive List of Allowed Inputs
Affects
org.webjars.npm:dompurify
| Versions
[,3.3.2)
M
Prototype Pollution
Affects
org.webjars.npm:dompurify
| Versions
[,3.3.2)
C
Deserialization of Untrusted Data
Affects
ai.h2o:h2o-core
| Versions
[,3.46.0.10)
H
XML Injection
CVE-2026-34601
Affects
org.webjars.npm:xmldom
| Versions
[0,]
M
Prototype Pollution
CVE-2026-2950
Affects
org.webjars.npm:lodash
| Versions
[4.0.0,]
M
Prototype Pollution
CVE-2026-2950
Affects
org.webjars.npm:lodash-es
| Versions
[,4.18.1)
H
Arbitrary Code Injection
CVE-2026-4800
Affects
org.webjars.npm:lodash-es
| Versions
[,4.18.1)
H
Arbitrary Code Injection
CVE-2026-4800
Affects
org.webjars.npm:lodash.template
| Versions
[0,]
H
Arbitrary Code Injection
CVE-2026-4800
Affects
org.webjars.npm:lodash
| Versions
[0,]
M
Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2026-34214
Affects
io.trino:trino-plugin-toolkit
| Versions
[439, 480)
M
Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2026-34214
Affects
io.trino:trino-main
| Versions
[439, 480)
M
Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2026-34214
Affects
io.trino:trino-spi
| Versions
[439, 480)
M
Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2026-34214
Affects
io.trino:trino-iceberg
| Versions
[439, 480)
M
Permissive Cross-domain Policy with Untrusted Domains
CVE-2026-34237
Affects
io.modelcontextprotocol.sdk:mcp-core
| Versions
[,1.0.1)
[1.1.0,1.1.1)
H
Deserialization of Untrusted Data
CVE-2026-33701
Affects
io.opentelemetry.javaagent:opentelemetry-javaagent
| Versions
[,2.26.1)
H
Deserialization of Untrusted Data
CVE-2026-33701
Affects
io.opentelemetry.javaagent.instrumentation:opentelemetry-javaagent
| Versions
[0,]
H
Denial of Service (DoS)
CVE-2025-8671
Affects
org.apache.httpcomponents.core5:httpcore5-h2
| Versions
[,5.3.5)