Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Uncontrolled Recursion
CVE-2026-33532
Affects
org.webjars.npm:yaml
| Versions
[,2.8.3)
M
Prototype Pollution
CVE-2026-33672
Affects
org.webjars.npm:picomatch
| Versions
[0,]
H
Regular Expression Denial of Service (ReDoS)
CVE-2026-33671
Affects
org.webjars.npm:picomatch
| Versions
[0,]
C
Directory Traversal
CVE-2026-33166
Affects
io.qameta.allure:allure-generator
| Versions
[,2.38.0)
H
Command Injection
CVE-2026-32948
Affects
org.scala-sbt:main_2.12
| Versions
[, 1.12.7)
H
Command Injection
CVE-2026-32948
Affects
org.scala-sbt:main_2.11
| Versions
[0,]
H
Directory Traversal
CVE-2026-22739
Affects
org.springframework.cloud:spring-cloud-config-server
| Versions
[,4.3.2)
[5.0.0-M1, 5.0.2)
H
Improper Verification of Cryptographic Signature
CVE-2026-4258
Affects
org.webjars.npm:sjcl
| Versions
[0,]
C
Race Condition
CVE-2026-32887
Affects
org.webjars.npm:effect
| Versions
[0,]
M
CRLF Injection
Affects
org.webjars.npm:h3
| Versions
[1.0.2,]
H
Directory Traversal
Affects
org.webjars.npm:h3
| Versions
[1.0.2,]
M
Server-side Request Forgery (SSRF)
CVE-2026-25534
Affects
io.spinnaker.orca:orca-core
| Versions
[,2025.2.4)
[2025.3.0,2025.3.1)
[2025.4.0,2025.4.1)
M
Server-side Request Forgery (SSRF)
CVE-2026-25534
Affects
io.spinnaker.clouddriver:clouddriver-artifacts
| Versions
[,2025.2.4)
[2025.3.0,2025.3.1)
[2025.4.0,2025.4.1)
M
Cross-site Scripting (XSS)
CVE-2023-1932
Affects
org.hibernate:hibernate-validator
| Versions
[,6.2.0)
M
Arbitrary Code Injection
CVE-2025-35036
Affects
org.hibernate:hibernate-validator
| Versions
[,6.2.0.CR1)
[7.0.0.Alpha1,7.0.0.CR1)
H
Directory Traversal
CVE-2026-22737
Affects
springframework:spring-webmvc
| Versions
[0,]
H
Directory Traversal
CVE-2026-22737
Affects
org.springframework:spring-webmvc
| Versions
[,6.2.17)
[7.0.0-M1,7.0.6)
H
Directory Traversal
CVE-2026-22737
Affects
org.springframework:spring-webflux
| Versions
[,6.2.17)
[7.0.0-M1,7.0.6)
H
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-22731
Affects
org.springframework.boot:spring-boot-actuator
| Versions
[3.4.0,3.5.12)
[4.0.0-M1,4.0.4)
H
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-22731
Affects
org.springframework.boot:spring-boot-actuator-autoconfigure
| Versions
[3.4.0,3.5.12)
[4.0.0-M1,4.0.4)
H
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-22733
Affects
org.springframework.boot:spring-boot-actuator
| Versions
[,3.5.12)
[4.0.0-M1,4.0.4)
H
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-22733
Affects
org.springframework.boot:spring-boot-actuator-autoconfigure
| Versions
[,3.5.12)
[4.0.0-M1,4.0.4)
C
Use of Cache Containing Sensitive Information
CVE-2026-22732
Affects
org.springframework.security:spring-security-web
| Versions
[3.2.8,6.5.9)
[7.0.0-M1,7.0.4)
L
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-22735
Affects
springframework:spring-web
| Versions
[0,]
L
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-22735
Affects
springframework:spring-webmvc
| Versions
[0,]
L
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-22735
Affects
org.springframework:spring-webmvc
| Versions
[,6.2.17)
[7.0.0,7.0.6)
L
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-22735
Affects
org.springframework:spring-web
| Versions
[,6.2.17)
[7.0.0,7.0.6)
H
DNS Rebinding
CVE-2026-33002
Affects
org.jenkins-ci.main:jenkins-core
| Versions
[2.426.3,2.427)
[2.442,2.555)
H
UNIX Symbolic Link (Symlink) Following
CVE-2026-33001
Affects
org.jenkins-ci.main:jenkins-core
| Versions
[,2.555)
C
Prototype Pollution
CVE-2026-33228
Affects
org.webjars.npm:flatted
| Versions
[0,]