Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
CVE-2026-53666
Affects
org.webjars.npm:react-router
| Versions
[6.4.0,7.18.0)
H
Open Redirect
CVE-2026-53669
Affects
org.webjars.npm:react-router
| Versions
[6.0.0,7.18.0)
M
Open Redirect
CVE-2026-53668
Affects
org.webjars.npm:react-router
| Versions
[7.9.6,7.13.0)
H
Infinite loop
CVE-2026-59877
Affects
org.webjars.npm:protobufjs
| Versions
[7.5.0,7.6.5)
[8.0.0,8.6.6)
M
Cross-site Scripting (XSS)
CVE-2026-17528
Affects
org.webjars.npm:nice-select2
| Versions
[,2.4.1)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-55968
Affects
org.webjars.npm:thrift
| Versions
[,0.24.0)
M
Improper Neutralization
CVE-2026-16729
Affects
org.webjars.npm:undici
| Versions
[,6.28.0)
[7.0.0,7.29.0)
[8.0.0,8.9.0)
M
HTTP Request Smuggling
CVE-2026-16728
Affects
org.webjars.npm:undici
| Versions
[,6.28.0)
[7.0.0,7.29.0)
[8.0.0,8.9.0)
L
CRLF Injection
CVE-2026-15157
Affects
org.webjars.npm:undici
| Versions
[,6.28.0)
[7.0.0,7.29.0)
[8.0.0,8.9.0)
C
Improper Handling of Length Parameter Inconsistency
CVE-2026-54466
Affects
org.webjars.npm:websocket-driver
| Versions
[,0.7.5)
M
Prototype Pollution
CVE-2026-67320
Affects
org.webjars.npm:axios
| Versions
[0.31.1,0.33.0)
[1.0.0,1.18.0)
H
Interpretation Conflict
CVE-2026-18446
Affects
org.webjars.npm:fast-uri
| Versions
[,2.4.4)
[3.0.0,3.1.5)
[4.0.0,4.1.2)
M
Cross-site Scripting (XSS)
CVE-2026-65841
Affects
org.webjars.npm:jodit
| Versions
[,4.13.6)
H
Insertion of Sensitive Information Into Sent Data
CVE-2026-16072
Affects
org.keycloak:keycloak-services
| Versions
[26.5.0,]
M
Cross-site Scripting (XSS)
CVE-2026-62324
Affects
org.webjars.npm:jodit
| Versions
[,4.12.31)
H
Inefficient Algorithmic Complexity
CVE-2026-55685
Affects
org.webjars.npm:react-router
| Versions
[7.0.0,7.18.0)
M
Server-side Request Forgery (SSRF)
CVE-2026-69192
Affects
org.webjars.npm:ip-address
| Versions
[,10.3.1)
M
Server-side Request Forgery (SSRF)
CVE-2026-69198
Affects
org.webjars.npm:ip-address
| Versions
[10.1.1,10.2.2)
M
SQL Injection
CVE-2026-69240
Affects
org.webjars.npm:sequelize
| Versions
[,6.37.4)
H
Improper Check for Unusual or Exceptional Conditions
CVE-2026-69185
Affects
org.webjars.npm:socket.io-parser
| Versions
[,3.3.6)
[3.4.0,3.4.5)
[4.0.0,4.2.7)
H
Directory Traversal
CVE-2026-71215
Affects
org.webjars.npm:art-template
| Versions
[0,]
H
Information Exposure
CVE-2026-13697
Affects
org.webjars.npm:undici
| Versions
[7.0.0,7.29.0)
[8.0.0,8.9.0)
H
Interpretation Conflict
CVE-2026-14643
Affects
org.webjars.npm:undici
| Versions
[7.0.0,7.29.0)
[8.0.0,8.9.0)
M
Improper Restriction of Rendered UI Layers or Frames
CVE-2026-70608
Affects
org.webjars.npm:electron
| Versions
[,39.8.10)
[40.0.0-alpha.2,41.10.3)
[42.0.0-alpha.1,42.0.1)
M
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
CVE-2026-71318
Affects
org.webjars.npm:nuxt
| Versions
[3.1.0,3.21.10)
[4.0.0,4.5.1)
H
Improper Validation of Specified Quantity in Input
CVE-2026-71314
Affects
org.webjars.npm:nuxt
| Versions
[3.1.0,3.21.10)
[4.0.0,4.5.1)
H
Incorrect Authorization
CVE-2026-71315
Affects
org.webjars.npm:nuxt
| Versions
[3.21.7,3.21.10)
[4.4.7,4.5.1)
M
Arbitrary Code Injection
CVE-2026-50159
Affects
org.webjars.npm:mermaid
| Versions
[,10.9.8)
[11.0.0-alpha.1,11.16.1)
M
Use of Blocking Code in Single-threaded, Non-blocking Context
CVE-2026-71439
Affects
org.webjars.npm:mermaid
| Versions
[11.6.0,11.16.1)
L
Prototype Pollution
CVE-2026-71438
Affects
org.webjars.npm:mermaid
| Versions
[,10.9.8)
[11.0.0-alpha.1,11.16.1)