Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Inadequate Encryption Strength
CVE-2025-68703
Affects
net.gleske:jervis
| Versions
[,2.2)
C
Improper Neutralization of Special Elements in Data Query Logic
CVE-2025-66169
Affects
org.apache.camel:camel-neo4j
| Versions
[4.10.0,4.10.8)
[4.14.0,4.14.3)
[4.15.0,4.17.0)
M
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2025-15056
Affects
org.webjars.npm:quill
| Versions
[0,]
H
Missing XML Validation
CVE-2025-68493
Affects
org.apache.struts:struts2-core
| Versions
[,6.1.1)
M
Cross-site Scripting (XSS)
CVE-2025-65110
Affects
org.webjars.npm:vega-selections
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2025-66648
Affects
org.webjars.npm:vega-functions
| Versions
[5.8.0,]
H
Server-side Request Forgery (SSRF)
CVE-2025-61916
Affects
io.spinnaker.clouddriver:clouddriver-aws
| Versions
[,2025.1-6)
[2025.2.0,2025.2-3)
H
Server-side Request Forgery (SSRF)
CVE-2025-61916
Affects
io.spinnaker.orca:orca-clouddriver
| Versions
[,2025.1-6)
[2025.2.0,2025.2-3)
H
XML External Entity (XXE) Injection
CVE-2025-68280
Affects
org.apache.sis.core:sis-metadata
| Versions
[0.4,]
H
Directory Traversal
CVE-2025-66518
Affects
org.apache.kyuubi:kyuubi-server_2.12
| Versions
[1.6.0,1.11.0)
H
Deserialization of Untrusted Data
CVE-2025-10492
Affects
net.sf.jasperreports:jasperreports
| Versions
[0,]
C
Improper Neutralization of Special Elements Used in a Template Engine
Affects
org.open-metadata:openmetadata-service
| Versions
[,1.11.4)
M
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
CVE-2026-0707
Affects
org.keycloak:keycloak-services
| Versions
[9.0.0,]
C
Access of Resource Using Incompatible Type ('Type Confusion')
CVE-2026-22028
Affects
org.webjars.npm:preact
| Versions
[10.26.5,10.26.10)
[10.27.0,10.27.3)
[10.28.0,10.28.2)
H
Unsafe Dependency Resolution
CVE-2025-70974
Affects
com.alibaba:fastjson
| Versions
[,1.2.48)
M
Improper Validation of Syntactic Correctness of Input
CVE-2025-12543
Affects
io.undertow:undertow-core
| Versions
[,2.3.21.Final)
[2.4.0.Alpha1,]
H
Cross-site Scripting (XSS)
CVE-2026-22029
Affects
org.webjars.npm:react-router
| Versions
[7.0.0,7.12.0)
M
Cross-site Request Forgery (CSRF)
CVE-2026-22030
Affects
org.webjars.npm:react-router
| Versions
[7.0.0,7.12.0)
M
Cross-site Scripting (XSS)
CVE-2026-21884
Affects
org.webjars.npm:react-router
| Versions
[7.0.0,7.12.0)
M
Cross-site Scripting (XSS)
CVE-2025-59057
Affects
org.webjars.npm:react-router
| Versions
[7.0.0,7.9.0)
H
Open Redirect
CVE-2025-68470
Affects
org.webjars.npm:react-router
| Versions
[,6.30.2)
[7.0.0,7.9.6)
C
External Control of File Name or Path
CVE-2025-68428
Affects
org.webjars.npm:jspdf
| Versions
[,4.0.0)
H
Allocation of Resources Without Limits or Throttling
CVE-2025-66560
Affects
io.quarkus.vertx.utils:quarkus-vertx-utils
| Versions
[,3.20.5)
[3.21.0.CR1,3.27.2)
[3.28.0.CR1,3.31.0)
M
Cross-site Scripting (XSS)
CVE-2025-15022
Affects
com.vaadin:vaadin-server
| Versions
[7.0.0,7.7.50)
[8.0.0,8.30.0)
M
Cross-site Scripting (XSS)
CVE-2025-15022
Affects
com.vaadin:vaadin-spreadsheet-flow
| Versions
[23.1.0,23.6.6)
[24.0.0,24.8.14)
[24.9.0,24.9.6)
M
Cross-site Scripting (XSS)
CVE-2025-15451
Affects
com.xnx3.wangmarket:wangmarket
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2025-15452
Affects
com.xnx3.wangmarket:wangmarket
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2025-15416
Affects
com.xnx3.wangmarket:wangmarket
| Versions
[0,]
H
Memory Allocation with Excessive Size Value
CVE-2026-21452
Affects
org.msgpack:msgpack-core
| Versions
[0.7.0-M6,0.9.11)
M
Cross-site Scripting (XSS)
Affects
org.webjars.npm:trix
| Versions
[0,]