Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Regular Expression Denial of Service (ReDoS)
CVE-2026-23956
Affects
org.webjars.npm:seroval
| Versions
[0,]
M
Prototype Pollution
CVE-2026-23736
Affects
org.webjars.npm:seroval
| Versions
[0,]
H
Allocation of Resources Without Limits or Throttling
CVE-2026-23957
Affects
org.webjars.npm:seroval
| Versions
[0,]
L
External Initialization of Trusted Variables or Data Stores
CVE-2026-1225
Affects
ch.qos.logback:logback-core
| Versions
[0.9.20,1.5.25)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-24006
Affects
org.webjars.npm:seroval
| Versions
[0,]
H
Files or Directories Accessible to External Parties
CVE-2026-22444
Affects
org.apache.solr:solr-core
| Versions
[8.6.0,9.10.1)
H
Missing Authorization
CVE-2026-22022
Affects
org.apache.solr:solr-core
| Versions
[5.3.0,9.10.1)
H
Allocation of Resources Without Limits or Throttling
CVE-2024-3884
Affects
io.undertow:undertow-core
| Versions
[,2.3.21.Final)
[2.4.0.Alpha1,]
M
Prototype Pollution
CVE-2025-13465
Affects
org.webjars.npm:lodash
| Versions
[4.0.0,]
M
Prototype Pollution
CVE-2025-13465
Affects
org.webjars.npm:lodash-es
| Versions
[4.0.0,]
M
Injection
CVE-2026-1050
Affects
net.risesoft:risenet-y9boot-support-platform-service
| Versions
[0,]
M
Injection
CVE-2026-1050
Affects
net.risesoft:risenet-y9boot-support-platform-jpa-repository
| Versions
[0,]
C
Improper Neutralization of Special Elements Used in a Template Engine
CVE-2025-64087
Affects
fr.opensagres.xdocreport:fr.opensagres.xdocreport.template.freemarker
| Versions
[0,]
H
XML External Entity (XXE) Injection
CVE-2025-65482
Affects
fr.opensagres.xdocreport:fr.opensagres.xdocreport.document.docx
| Versions
[0,]
H
Improper Enforcement of Behavioral Workflow
CVE-2025-14559
Affects
org.keycloak:keycloak-services
| Versions
[,26.5.2)
L
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-1035
Affects
org.keycloak:keycloak-services
| Versions
[0,]
M
Server-side Request Forgery (SSRF)
CVE-2026-1180
Affects
org.keycloak:keycloak-services
| Versions
[0,]
L
Missing XML Validation
CVE-2026-1190
Affects
org.keycloak:keycloak-services
| Versions
[0,]
H
SQL Injection
CVE-2026-0603
Affects
org.hibernate:hibernate-core
| Versions
[,5.3.38)
M
Improper Handling of Unicode Encoding
CVE-2026-23950
Affects
org.webjars.npm:tar
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2025-15265
Affects
org.webjars.npm:svelte
| Versions
[5.46.0,5.46.4)
M
Use of a Cryptographic Primitive with a Risky Implementation
CVE-2025-14505
Affects
org.webjars.npm:elliptic
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2026-0601
Affects
org.sonatype.nexus:nexus-extdirect
| Versions
[,3.88.0-08)
M
Encoding Error
CVE-2025-29847
Affects
org.apache.linkis:linkis-common
| Versions
[0,]
M
Insertion of Sensitive Information into Log File
CVE-2025-59355
Affects
org.apache.linkis:linkis-metadata
| Versions
[0,]
M
Cross-site Scripting (XSS)
Affects
org.webjars.npm:svelte
| Versions
[,4.2.2)
H
External Control of File Name or Path
CVE-2026-23529
Affects
com.wepay.kcbq:kcbq-connector
| Versions
[0,]
H
HTTP Request Smuggling
CVE-2026-23527
Affects
org.webjars.npm:h3
| Versions
[,1.15.5)
M
Improper Validation of Syntactic Correctness of Input
CVE-2026-0976
Affects
org.keycloak:keycloak-quarkus-server
| Versions
[,26.5.2)
M
HTTP Request Smuggling
CVE-2026-1002
Affects
io.vertx:vertx-core
| Versions
[,4.5.24)