Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
L
Directory Traversal
CVE-2026-23907
Affects
org.apache.pdfbox:pdfbox-examples
| Versions
[2.0.24,3.0.7)
H
Directory Traversal
Affects
org.webjars.npm:h3
| Versions
[0,]
H
Allocation of Resources Without Limits or Throttling
CVE-2026-33013
Affects
io.micronaut:micronaut-json-core
| Versions
[,3.10.5)
[4.0.0-M1,4.10.16)
[5.0.0-M1,5.0.0-M14)
C
Origin Validation Error
CVE-2026-27478
Affects
io.unitycatalog:unitycatalog-server
| Versions
[0,]
H
Allocation of Resources Without Limits or Throttling
CVE-2026-33151
Affects
org.webjars.npm:socket.io-parser
| Versions
[0,]
H
SQL Injection
CVE-2026-22730
Affects
org.springframework.ai:spring-ai-mariadb-store
| Versions
[1.0.0-M5,1.0.4)
[1.1.0-M1,1.1.3)
[2.0.0-M1,2.0.0-M3)
H
SQL Injection
CVE-2026-22729
Affects
org.springframework.ai:spring-ai-vector-store
| Versions
[1.0.0-M5,1.0.4)
[1.1.0-M1,1.1.3)
[2.0.0-M1,2.0.0-M3)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-33012
Affects
io.micronaut:micronaut-http-server
| Versions
[4.7.0,4.10.17)
[5.0.0-M1,5.0.0-M16)
M
Cross-site Scripting (XSS)
CVE-2026-31938
Affects
org.webjars.npm:jspdf
| Versions
[0,]
M
Improper Encoding or Escaping of Output
CVE-2026-31898
Affects
org.webjars.npm:jspdf
| Versions
[0,]
H
XML Entity Expansion
CVE-2026-33036
Affects
org.webjars.npm:fast-xml-parser
| Versions
[4.0.0-beta.0,]
H
Command Injection
CVE-2021-43113
Affects
com.itextpdf:itextpdf
| Versions
[,5.5.13.3)
M
Improper Input Validation
CVE-2025-60012
Affects
org.apache.livy:livy-server
| Versions
[0.7.0-incubating,0.9.0-incubating)
M
Cross-site Scripting (XSS)
CVE-2026-31860
Affects
org.webjars.npm:unhead
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2026-3884
Affects
org.webjars.npm:spin.js
| Versions
[,3.1.0)
H
Deserialization of Untrusted Data
CVE-2025-54920
Affects
org.apache.spark:spark-core_2.13
| Versions
[,3.5.7-rc1)
[4.0.0-preview1-rc1,4.0.1-rc1)
H
Deserialization of Untrusted Data
CVE-2025-54920
Affects
org.apache.spark:spark-core_2.12
| Versions
[,3.5.7-rc1)
[4.0.0-preview1-rc1,4.0.1-rc1)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-32630
Affects
org.webjars.npm:file-type
| Versions
[21.0.0,]
C
Directory Traversal
CVE-2025-66249
Affects
org.apache.livy:livy-server
| Versions
[,0.9.0-incubating)
M
Cross-site Scripting (XSS)
Affects
org.webjars.npm:trix
| Versions
[,2.1.17)
M
HTTP Request Smuggling
CVE-2026-1525
Affects
org.webjars.npm:undici
| Versions
[0,]
H
Uncaught Exception
CVE-2026-1528
Affects
org.webjars.npm:undici
| Versions
[6.23.0,]
H
Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-1526
Affects
org.webjars.npm:undici
| Versions
[0,]
H
Uncaught Exception
CVE-2026-2229
Affects
org.webjars.npm:undici
| Versions
[0,]
M
CRLF Injection
CVE-2026-1527
Affects
org.webjars.npm:undici
| Versions
[0,]
M
Integer Overflow or Wraparound
CVE-2026-3707
Affects
dev.matrixlab.webp4j:webp4j-core
| Versions
[,2.1.1)
C
Binding to an Unrestricted IP Address
CVE-2026-24015
Affects
org.apache.iotdb:node-commons
| Versions
[1.0.0,1.3.7)
[2.0.0,2.0.7)
C
Binding to an Unrestricted IP Address
CVE-2026-24015
Affects
org.apache.iotdb:iotdb-server
| Versions
[1.0.0,1.3.7)
[2.0.0,2.0.7)
M
Comparison Using Wrong Factors
CVE-2026-22723
Affects
org.cloudfoundry.identity:cloudfoundry-identity-server
| Versions
[77.30.0,78.8.0)
L
Directory Traversal
CVE-2026-2741
Affects
com.vaadin:flow-build-tools
| Versions
[25.0.0-rc1,25.0.3)