Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Origin Validation Error
CVE-2026-34359
Affects
ca.uhn.hapi.fhir:org.hl7.fhir.utilities
| Versions
[6.4.1,6.9.4)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-34043
Affects
org.webjars.npm:serialize-javascript
| Versions
[0,]
H
Improper Check for Unusual or Exceptional Conditions
CVE-2026-33939
Affects
org.webjars.npm:handlebars
| Versions
[4.0.2,]
H
Improper Encoding or Escaping of Output
CVE-2026-33941
Affects
org.webjars.npm:handlebars
| Versions
[4.0.2,]
C
Access of Resource Using Incompatible Type ('Type Confusion')
CVE-2026-33940
Affects
org.webjars.npm:handlebars
| Versions
[4.0.2,]
C
Access of Resource Using Incompatible Type ('Type Confusion')
CVE-2026-33937
Affects
org.webjars.npm:handlebars
| Versions
[4.0.2,]
C
Access of Resource Using Incompatible Type ('Type Confusion')
CVE-2026-33938
Affects
org.webjars.npm:handlebars
| Versions
[4.0.2,]
M
Server-side Request Forgery (SSRF)
CVE-2026-34360
Affects
ca.uhn.hapi.fhir:org.hl7.fhir.utilities
| Versions
[,6.9.4)
H
Deserialization of Untrusted Data
CVE-2026-33728
Affects
com.datadoghq:dd-java-agent
| Versions
[0.40.0,1.60.3)
L
Resources Downloaded over Insecure Protocol
CVE-2026-32735
Affects
io.github.chrimle:openapi-to-java-records-mustache-templates-parent
| Versions
[,3.5.1)
M
Division by zero
CVE-2026-4603
Affects
org.webjars.npm:jsrsasign
| Versions
[0,]
H
Incorrect Conversion between Numeric Types
CVE-2026-4602
Affects
org.webjars.npm:jsrsasign
| Versions
[0,]
C
Missing Cryptographic Step
CVE-2026-4601
Affects
org.webjars.npm:jsrsasign
| Versions
[0,]
C
Improper Verification of Cryptographic Signature
CVE-2026-4600
Affects
org.webjars.npm:jsrsasign
| Versions
[0,]
C
Incomplete Comparison with Missing Factors
CVE-2026-4599
Affects
org.webjars.npm:jsrsasign
| Versions
[8.0.12,]
H
Infinite loop
CVE-2026-4598
Affects
org.webjars.npm:jsrsasign
| Versions
[0,]
M
Cross-site Scripting (XSS)
Affects
org.webjars.npm:trix
| Versions
[0,]
M
Prototype Pollution
Affects
org.webjars.npm:handlebars
| Versions
[4.6.2,]
M
Time-of-check Time-of-use (TOCTOU) Race Condition
Affects
org.webjars.npm:handlebars
| Versions
[4.0.2,]
M
SQL Injection: Hibernate
CVE-2026-4593
Affects
xyz.erupt:erupt-ai
| Versions
[0,]
M
SQL Injection: Hibernate
CVE-2026-4594
Affects
xyz.erupt:erupt-jpa
| Versions
[0,]
M
Cross-site Scripting (XSS)
Affects
org.webjars.npm:dompurify
| Versions
[,3.3.2)
H
Improper Encoding or Escaping of Output
Affects
software.amazon.awssdk:cloudfront
| Versions
[2.18.33,2.41.30)
L
Server-side Request Forgery (SSRF)
CVE-2026-4874
Affects
org.keycloak:keycloak-services
| Versions
[0,]
H
Allocation of Resources Without Limits or Throttling
CVE-2026-3260
Affects
io.undertow:undertow-core
| Versions
[,2.4.0.Beta1)
C
Server-side Request Forgery (SSRF)
CVE-2026-22742
Affects
org.springframework.ai:spring-ai-bedrock-converse
| Versions
[,1.0.5)
[1.1.0-M1,1.1.4)
C
Server-side Request Forgery (SSRF)
CVE-2026-22742
Affects
org.springframework.ai:spring-ai-autoconfigure-model-bedrock-ai
| Versions
[,1.0.5)
[1.1.0-M1,1.1.4)
H
Improper Input Validation
CVE-2026-22743
Affects
org.springframework.ai:spring-ai-neo4j-store
| Versions
[,1.0.5)
[1.1.0-M1,1.1.4)
H
Improper Input Validation
CVE-2026-22744
Affects
org.springframework.ai:spring-ai-redis-store
| Versions
[,1.0.5)
[1.1.0-M1,1.1.4)
C
Arbitrary Code Injection
CVE-2026-22738
Affects
org.springframework.ai:spring-ai-vector-store
| Versions
[,1.0.5)
[1.1.0-M1,1.1.4)