Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Weak Password Recovery Mechanism for Forgotten Password
Affects
@workflow/core
| Versions
<4.2.0-beta.64
M
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-3484
Affects
mcp-nmap-server
| Versions
*
M
Missing Authorization
CVE-2026-30850
Affects
parse-server
| Versions
<8.6.9
>=9.0.0-alpha.1 <9.5.0-alpha.9
H
Improper Verification of Cryptographic Signature
CVE-2026-30863
Affects
parse-server
| Versions
<8.6.10
>=9.0.0-alpha.1 <9.5.0-alpha.11
H
Directory Traversal
CVE-2026-30848
Affects
parse-server
| Versions
<8.6.8
>=9.0.0-alpha.1 <9.5.0-alpha.8
M
Incorrect Authorization
CVE-2026-30854
Affects
parse-server
| Versions
>=9.3.1-alpha.3 <9.5.0-alpha.10
M
Information Exposure
CVE-2026-30835
Affects
parse-server
| Versions
<8.6.7
>=9.0.0-alpha.1 <9.5.0-alpha.6
H
Incorrect Authorization
CVE-2026-30229
Affects
parse-server
| Versions
<8.6.6
>=9.0.0-alpha.1 <9.5.0-alpha.4
H
Incorrect Authorization
CVE-2026-30228
Affects
parse-server
| Versions
<8.6.5
>=9.0.0-alpha.1 <9.5.0-alpha.3
M
Symlink Attack
CVE-2026-30916
Affects
shescape
| Versions
<2.1.9
M
Improper Authentication
Affects
@x402/svm
| Versions
<2.6.0
H
Uncontrolled Recursion
CVE-2026-30241
Affects
mercurius
| Versions
<16.8.0
H
Insertion of Sensitive Information Into Sent Data
Affects
flowise
| Versions
<3.0.13
M
Use of Password Hash With Insufficient Computational Effort
Affects
flowise
| Versions
<3.0.13
H
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-29053
Affects
ghost
| Versions
<6.19.1
H
Cross-site Request Forgery (CSRF)
CVE-2026-29784
Affects
ghost
| Versions
>=5.101.6 <6.19.3
C
Malicious Package
Affects
@wgu-edu/wgu-core
| Versions
*
C
Malicious Package
Affects
@wgu-edu/wgu-icons
| Versions
*
H
Server-side Request Forgery (SSRF)
CVE-2026-3125
Affects
@opennextjs/cloudflare
| Versions
<1.17.1
H
Missing Authentication for Critical Function
CVE-2026-29613
Affects
openclaw
| Versions
<2026.2.12
C
Malicious Package
Affects
pino-sdk-v2
| Versions
*
C
Malicious Package
Affects
dc-web-app
| Versions
*
C
Malicious Package
Affects
test-mal-npm-pkg-local
| Versions
*
C
Malicious Package
Affects
@shenira/libsignal-node
| Versions
*
C
Malicious Package
Affects
@shenira/baileys
| Versions
*
C
Malicious Package
Affects
aaaaaxxxxx
| Versions
*
C
Malicious Package
Affects
@shenira/baileysx
| Versions
*
C
Malicious Package
Affects
test-mal-npm-pkg-2
| Versions
*
C
Malicious Package
Affects
test-mal-npm-pkg-not-local
| Versions
*
C
Malicious Package
Affects
tether-dev-docs
| Versions
*