Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
DNS Rebinding
Affects
openclaw
| Versions
<2026.3.31-beta.1
M
Time-of-check Time-of-use (TOCTOU) Race Condition
Affects
openclaw
| Versions
<2026.3.31-beta.1
M
Incorrect Authorization
Affects
@openclaw/discord
| Versions
>=0.0.0
M
Incorrect Authorization
Affects
openclaw
| Versions
<2026.3.31-beta.1
L
Missing Authorization
Affects
@openclaw/discord
| Versions
>=0.0.0
L
Missing Authorization
Affects
openclaw
| Versions
<2026.3.31-beta.1
H
Insufficient Verification of Data Authenticity
CVE-2026-34511
Affects
openclaw
| Versions
<2026.4.2
C
Embedded Malicious Code
Affects
mgc
| Versions
*
C
Authentication Bypass Using an Alternate Path or Channel
Affects
better-auth
| Versions
<1.4.9
H
Use of a Broken or Risky Cryptographic Algorithm
CVE-2026-34950
Affects
fast-jwt
| Versions
<6.2.0
C
Improper Validation of Unsafe Equivalence in Input
CVE-2026-35039
Affects
fast-jwt
| Versions
<6.1.0
M
Origin Validation Error
CVE-2026-34777
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.1
>=40.0.0-alpha.2 <40.8.1
>=41.0.0-alpha.1 <41.0.0
H
Command Injection
CVE-2026-34779
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.1
>=40.0.0-alpha.2 <40.8.0
>=41.0.0-alpha.1 <41.0.0-beta.8
M
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-34773
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.1
>=40.0.0-alpha.2 <40.8.1
>=41.0.0-alpha.1 <41.0.0
H
Use After Free
CVE-2026-34770
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.1
>=40.0.0-alpha.2 <40.8.0
>=41.0.0-alpha.1 <41.0.0-beta.8
M
Use After Free
CVE-2026-34772
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.0
>=40.0.0-alpha.2 <40.7.0
>=41.0.0-alpha.1 <41.0.0-beta.7
M
Insufficient Verification of Data Authenticity
CVE-2026-34778
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.1
>=40.0.0-alpha.2 <40.8.1
>=41.0.0-alpha.1 <41.0.0
H
Use After Free
CVE-2026-34771
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.0
>=40.0.0-alpha.2 <40.7.0
>=41.0.0-alpha.1 <41.0.0-beta.8
M
Out-of-bounds Read
CVE-2026-34776
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.1
>=40.0.0-alpha.2 <40.8.1
>=41.0.0-alpha.1 <41.0.0
H
Improper Isolation or Compartmentalization
CVE-2026-34775
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.4
>=40.0.0-alpha.2 <40.8.4
>=41.0.0-alpha.1 <41.0.0
H
Unquoted Search Path or Element
CVE-2026-34768
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.1
>=40.0.0-alpha.2 <40.8.0
>=41.0.0-alpha.1 <41.0.0-beta.8
L
Missing Authorization
CVE-2026-34766
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.0
>=40.0.0-alpha.2 <40.7.0
>=41.0.0-alpha.1 <41.0.0-beta.8
M
HTTP Response Splitting
CVE-2026-34767
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.3
>=40.0.0-alpha.2 <40.8.3
>=41.0.0-alpha.1 <41.0.3
C
Use After Free
CVE-2026-34774
Affects
electron
| Versions
<39.8.1
>=40.0.0-alpha.2 <40.7.0
>=41.0.0-alpha.1 <41.0.0
H
Insecure Default Initialization of Resource
CVE-2026-34780
Affects
electron
| Versions
>=39.0.0-alpha.1 <39.8.0
>=40.0.0-alpha.2 <40.7.0
>=41.0.0-alpha.1 <41.0.0-beta.8
H
Hidden Functionality
CVE-2026-34769
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.0
>=40.0.0-alpha.2 <40.7.0
>=41.0.0-alpha.1 <41.0.0-beta.8
M
Permissive List of Allowed Inputs
Affects
dompurify
| Versions
<3.3.2
M
Prototype Pollution
Affects
dompurify
| Versions
<3.3.2
M
Heap-based Buffer Overflow
CVE-2025-15536
Affects
opencc
| Versions
<1.2.0
H
Directory Traversal
CVE-2026-33989
Affects
@mobilenext/mobile-mcp
| Versions
<0.0.49