Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Arbitrary Command Injection
CVE-2026-2178
Affects
xcode-mcp-server
| Versions
*
L
UNIX Symbolic Link (Symlink) Following
CVE-2026-25724
Affects
@anthropic-ai/claude-code
| Versions
<2.1.7
C
Infinite loop
CVE-2026-25533
Affects
enclave-vm
| Versions
*
C
Infinite loop
CVE-2026-25533
Affects
@enclave-vm/core
| Versions
<2.10.1
H
Command Injection
CVE-2026-25722
Affects
@anthropic-ai/claude-code
| Versions
<2.0.57
M
Arbitrary Command Injection
CVE-2026-2130
Affects
mcp-maigret
| Versions
*
M
Cross-site Scripting (XSS)
CVE-2026-25581
Affects
sceditor
| Versions
<3.2.1
M
Open Redirect
CVE-2026-25651
Affects
client-certificate-auth
| Versions
>=0.2.1 <1.0.0
H
Command Injection
CVE-2026-25723
Affects
@anthropic-ai/claude-code
| Versions
<2.0.55
H
Allocation of Resources Without Limits or Throttling
CVE-2026-25762
Affects
@adonisjs/bodyparser
| Versions
<10.1.3
>=11.0.0-next.0 <11.0.0-next.9
M
Prototype Pollution
CVE-2026-25754
Affects
@adonisjs/bodyparser
| Versions
<10.1.3
>=11.0.0-next.0 <11.0.0-next.9
C
Prototype Pollution
CVE-2026-25520
Affects
@nyariv/sandboxjs
| Versions
<0.8.29
C
Prototype Pollution
CVE-2026-25586
Affects
@nyariv/sandboxjs
| Versions
<0.8.29
C
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-25641
Affects
@nyariv/sandboxjs
| Versions
<0.8.29
C
Arbitrary Code Injection
CVE-2026-25587
Affects
@nyariv/sandboxjs
| Versions
<0.8.29
C
Malicious Package
Affects
web3-chain-sinon
| Versions
*
C
Malicious Package
Affects
web3-sinon
| Versions
*
C
Malicious Package
Affects
aligned-arrays
| Versions
*
C
Embedded Malicious Code
Affects
@dydxprotocol/v4-client-js
| Versions
=1.0.31
=1.15.2
=1.22.1
=3.4.1
C
Malicious Package
Affects
@meli-lint/eslint-config-base
| Versions
*
C
Malicious Package
Affects
@hashicorp-internal/vault-reporting
| Versions
*
C
Malicious Package
Affects
@opposhop/nuxt-ssr-cache
| Versions
*
C
Malicious Package
Affects
@rsgweb/locale-tools
| Versions
*
C
Malicious Package
Affects
@rsgweb/rockstar-account
| Versions
*
C
Malicious Package
Affects
@rdxportal/ui-components
| Versions
*
C
Malicious Package
Affects
@sbseg-plugin/qbo-web-app-ui
| Versions
*
C
Malicious Package
Affects
@meli-lint/eslint-config-base-ts
| Versions
*
C
Malicious Package
Affects
@sporting-life/sportinglife-betslip-sdk
| Versions
*
C
Malicious Package
Affects
@meli-lint/eslint-config-tests-jest
| Versions
*
C
Malicious Package
Affects
@rsgweb/tina
| Versions
*