Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
CVE-2026-92001
Affects
org.apache.sling:org.apache.sling.xss
| Versions
[,2.4.12)
H
Origin Validation Error
CVE-2026-94243
Affects
org.apache.sling:org.apache.sling.security
| Versions
[,1.3.2)
M
Protection Mechanism Failure
CVE-2026-94251
Affects
org.apache.sling:org.apache.sling.security
| Versions
[,1.3.12)
C
Session Fixation
CVE-2026-92609
Affects
org.apache.qpid:qpid-broker-plugins-management-http
| Versions
[,10.1.1)
H
Uncaught Exception
CVE-2026-92608
Affects
org.apache.qpid:qpid-broker-plugins-amqp-msg-conv-0-10-to-1-0
| Versions
[,10.1.1)
H
Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-92573
Affects
org.apache.qpid:qpid-broker-core
| Versions
[,10.1.1)
H
Uncontrolled Recursion
CVE-2026-92564
Affects
org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol
| Versions
[,10.1.1)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-92560
Affects
org.apache.qpid:qpid-broker-plugins-amqp-0-10-protocol
| Versions
[,10.1.1)
H
Memory Allocation with Excessive Size Value
CVE-2026-92550
Affects
org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol
| Versions
[,10.1.1)
M
Incorrect Authorization
CVE-2026-73236
Affects
org.apache.syncope.core.am:syncope-core-am-logic
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
M
Incorrect Authorization
CVE-2026-73370
Affects
org.apache.syncope.core.idm:syncope-core-idm-logic
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
C
Arbitrary Code Injection
CVE-2026-77147
Affects
org.apache.syncope.core:syncope-core-spring
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
M
Incorrect Authorization
CVE-2026-73579
Affects
org.apache.syncope.core:syncope-core-persistence-common
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
M
Insufficiently Protected Credentials
CVE-2026-75015
Affects
org.apache.syncope.core:syncope-core-provisioning-java
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
M
Cross-site Scripting (XSS)
CVE-2026-78318
Affects
org.apache.syncope.client.idrepo:syncope-client-idrepo-common-ui
| Versions
[4.0.4,4.0.8)
[4.1.0-M0,4.1.3)
M
SQL Injection
CVE-2026-82232
Affects
org.apache.syncope.core:syncope-core-persistence-jpa
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
C
Improper Verification of Cryptographic Signature
CVE-2026-87802
Affects
org.apache.syncope:syncope-sra
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
H
User Impersonation
CVE-2026-87785
Affects
org.apache.syncope.core:syncope-core-spring
| Versions
[3.0.15,4.0.0-M0)
[4.0.3,4.0.8)
[4.1.0-M0,4.1.3)
M
Insertion of Sensitive Information into Log File
CVE-2026-87779
Affects
org.apache.syncope.core:syncope-core-spring
| Versions
[3.0.15,4.0.0-M0)
[4.0.3,4.0.8)
[4.1.0-M0,4.1.3)
M
SQL Injection
CVE-2026-86460
Affects
org.apache.syncope.core:syncope-core-persistence-neo4j
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
M
Improper Encoding or Escaping of Output
CVE-2026-73195
Affects
org.apache.syncope.core:syncope-core-provisioning-java
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
M
Incorrect Authorization
CVE-2026-77181
Affects
org.apache.syncope.core.am:syncope-core-am-logic
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
M
SQL Injection
CVE-2026-77051
Affects
org.apache.syncope.core:syncope-core-persistence-jpa
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
M
Incorrect Authorization
CVE-2026-73668
Affects
org.apache.syncope.core.idm:syncope-core-idm-logic
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
M
Information Exposure
CVE-2026-77883
Affects
org.apache.syncope.core:syncope-core-provisioning-api
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
M
Insertion of Sensitive Information Into Sent Data
CVE-2026-78336
Affects
org.apache.syncope.ext.oidcc4ui:syncope-ext-oidcc4ui-logic
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
H
Incorrect Privilege Assignment
CVE-2026-78330
Affects
org.apache.syncope.core:syncope-core-spring
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
M
Open Redirect
CVE-2026-73191
Affects
org.apache.syncope:syncope-sra
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
M
Information Exposure
CVE-2026-73178
Affects
org.apache.syncope.core:syncope-core-provisioning-java
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)
M
Missing Authorization
CVE-2026-75030
Affects
org.apache.syncope.core.idrepo:syncope-core-idrepo-logic
| Versions
[3.0.0-M0,4.0.8)
[4.1.0-M0,4.1.3)