Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Directory Traversal
CVE-2026-27606
Affects
rollup
| Versions
<2.80.0
>=3.0.0-0 <3.30.0
>=4.0.0-1 <4.59.0
C
Malicious Package
Affects
ultimates-express
| Versions
*
C
Malicious Package
Affects
express-soaps
| Versions
*
C
Malicious Package
Affects
modify-setting
| Versions
*
C
Malicious Package
Affects
chai-tools
| Versions
*
C
Malicious Package
Affects
chai-as-pause
| Versions
*
C
Malicious Package
Affects
es1int-config
| Versions
*
C
Malicious Package
Affects
argon-web3-chain
| Versions
*
C
Malicious Package
Affects
json-mapping-srcs
| Versions
*
C
Malicious Package
Affects
node-argon
| Versions
*
C
Malicious Package
Affects
es1int-re1ease
| Versions
*
C
Malicious Package
Affects
dotenvx-ext
| Versions
*
H
Allocation of Resources Without Limits or Throttling
CVE-2026-27729
Affects
astro
| Versions
>=5.0.0 <5.17.3
>=6.0.0-alpha.0 <6.0.0-beta.15
H
Server-side Request Forgery (SSRF)
CVE-2026-25545
Affects
astro
| Versions
<5.17.3
>=6.0.0-alpha.0 <6.0.0-beta.7
H
Open Redirect
CVE-2026-27191
Affects
@feathersjs/authentication-oauth
| Versions
<5.0.40
H
Origin Validation Error
CVE-2026-27192
Affects
@feathersjs/authentication-oauth
| Versions
<5.0.40
H
Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2026-27193
Affects
@feathersjs/authentication-oauth
| Versions
<5.0.40
H
CRLF Injection
CVE-2026-27203
Affects
ebay-mcp
| Versions
<1.7.3
L
Exposure of Data Element to Wrong Session
CVE-2026-27492
Affects
lettermint
| Versions
<1.5.1
C
Malicious Package
Affects
eslint-verify-plugin
| Versions
*
C
Malicious Package
Affects
npm-security-testing
| Versions
*
C
Malicious Package
Affects
rbxm-tools
| Versions
*
C
Malicious Package
Affects
react-dropzone-truffle
| Versions
*
H
Unsafe Dependency Resolution
CVE-2026-26974
Affects
@tygo-van-den-hurk/slyde
| Versions
<0.0.5
L
User Impersonation
CVE-2026-27484
Affects
openclaw
| Versions
<2026.2.19
M
Server-side Request Forgery (SSRF)
CVE-2026-27488
Affects
openclaw
| Versions
<2026.2.19
M
Allocation of Resources Without Limits or Throttling
CVE-2026-27576
Affects
openclaw
| Versions
<2026.2.19
M
UNIX Symbolic Link (Symlink) Following
CVE-2026-27485
Affects
openclaw
| Versions
<2026.2.19
H
Incorrect Regular Expression
CVE-2026-25896
Affects
fast-xml-parser
| Versions
>=4.1.3 <4.5.4
>=5.0.0 <5.3.5
C
Malicious Package
Affects
rollup-plugin-polyfill-swc
| Versions
*