Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Missing Authentication for Critical Function
CVE-2026-39363
Affects
vite-plus
| Versions
<0.1.16
H
Missing Authentication for Critical Function
CVE-2026-39363
Affects
vite
| Versions
>=6.0.0 <6.4.2
>=7.0.0 <7.3.2
>=8.0.0 <8.0.5
M
Directory Traversal
CVE-2026-39365
Affects
vite-plus
| Versions
<0.1.16
M
Directory Traversal
CVE-2026-39365
Affects
vite
| Versions
<6.4.2
>7.0.0 <7.3.2
>8.0.0 <8.0.5
H
Allocation of Resources Without Limits or Throttling
CVE-2026-23864
Affects
next
| Versions
>=13.0.0 <15.0.8
>=15.1.0 <15.1.12
>=15.2.0-canary.0 <15.2.9
>=15.3.0-canary.0 <15.3.9
>=15.4.0-canary.0 <15.4.11
>=15.5.0 <15.5.10
>=15.6.0-canary.0 <15.6.0-canary.61
>=16.0.0-canary.0 <16.0.11
>=16.1.0-canary.0 <16.1.5
>=16.2.0-canary.0 <16.2.0-canary.9
M
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-35515
Affects
@nestjs/core
| Versions
<11.1.18
M
Incomplete List of Disallowed Inputs
CVE-2026-34425
Affects
@openclaw/discord
| Versions
>=0.0.0
M
Incomplete List of Disallowed Inputs
CVE-2026-34425
Affects
openclaw
| Versions
<2026.4.2
C
Improper Control of Dynamically-Managed Code Resources
CVE-2026-34156
Affects
@nocobase/plugin-workflow-javascript
| Versions
<2.0.28
H
Improper Authorization in Handler for Custom URL Scheme
CVE-2026-35394
Affects
@mobilenext/mobile-mcp
| Versions
<0.0.50
H
Command Injection
CVE-2026-25044
Affects
@budibase/types
| Versions
<3.33.4
H
Command Injection
CVE-2026-25044
Affects
@budibase/shared-core
| Versions
<3.33.4
H
Command Injection
CVE-2026-25044
Affects
@budibase/server
| Versions
<3.33.4
C
Command Injection
CVE-2026-35216
Affects
@budibase/shared-core
| Versions
<3.33.4
C
Command Injection
CVE-2026-35216
Affects
@budibase/types
| Versions
<3.33.4
C
Command Injection
CVE-2026-35216
Affects
@budibase/server
| Versions
<3.33.4
H
Directory Traversal
CVE-2026-35214
Affects
@budibase/types
| Versions
<3.33.4
H
Directory Traversal
CVE-2026-35214
Affects
@budibase/server
| Versions
<3.33.4
C
Insecure Default Initialization of Resource
CVE-2026-31818
Affects
@budibase/backend-core
| Versions
<3.33.4
H
Prototype Pollution
CVE-2026-34221
Affects
@mikro-orm/core
| Versions
<6.6.10-dev.1
>=7.0.0-dev.0 <7.0.6-dev.8
C
SQL Injection
CVE-2026-34220
Affects
@mikro-orm/mariadb
| Versions
<6.6.10-dev.1
C
SQL Injection
CVE-2026-34220
Affects
@mikro-orm/core
| Versions
<6.6.10-dev.1
>=7.0.0-dev.0 <7.0.6-dev.8
M
Out-of-bounds Read
CVE-2026-35038
Affects
signalk-server
| Versions
<2.24.0
H
Arbitrary Code Injection
CVE-2026-34725
Affects
dbgate-web
| Versions
>=7.0.0-alpha.10 <7.1.5
H
Prototype Pollution
CVE-2026-35209
Affects
defu
| Versions
<6.1.5
M
Missing Authentication for Critical Function
CVE-2026-33951
Affects
signalk-server
| Versions
<2.24.0-beta.3
C
Improper Verification of Cryptographic Signature
Affects
@stablelib/cbor
| Versions
<2.0.3
C
Improper Verification of Cryptographic Signature
Affects
@stablelib/ed25519
| Versions
<2.1.0
H
Prototype Pollution
Affects
@stablelib/cbor
| Versions
<2.0.3
M
Use of GET Request Method With Sensitive Query Strings
CVE-2026-25118
Affects
@immich/sdk
| Versions
<2.6.0