Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Improper Restriction of Communication Channel to Intended Endpoints
Affects
@grackle-ai/mcp
| Versions
<0.70.2
M
Server-side Request Forgery (SSRF)
CVE-2026-34746
Affects
payload
| Versions
<3.79.1
M
Cross-site Scripting (XSS)
CVE-2026-34748
Affects
@payloadcms/ui
| Versions
<3.78.0
M
Cross-site Scripting (XSS)
CVE-2026-34748
Affects
@payloadcms/plugin-mcp
| Versions
<3.78.0
H
Directory Traversal
CVE-2026-34750
Affects
@payloadcms/storage-s3
| Versions
<3.78.0
H
Directory Traversal
CVE-2026-34750
Affects
@payloadcms/storage-r2
| Versions
<3.78.0
H
Directory Traversal
CVE-2026-34750
Affects
@payloadcms/storage-gcs
| Versions
<3.78.0
H
Directory Traversal
CVE-2026-34750
Affects
payload
| Versions
<3.78.0
M
Cross-site Request Forgery (CSRF)
CVE-2026-34749
Affects
payload
| Versions
<3.79.1
M
SQL Injection
CVE-2026-34747
Affects
payload
| Versions
<3.79.1
M
SQL Injection
CVE-2026-34747
Affects
@payloadcms/drizzle
| Versions
<3.79.1
M
Deserialization of Untrusted Data
CVE-2026-2265
Affects
replicator
| Versions
*
M
Missing Authentication for Critical Function
Affects
@grackle-ai/powerline
| Versions
<0.70.1
C
Weak Password Recovery Mechanism for Forgotten Password
CVE-2026-34751
Affects
payload
| Versions
<3.79.1
C
Weak Password Recovery Mechanism for Forgotten Password
CVE-2026-34751
Affects
@payloadcms/graphql
| Versions
<3.79.1
M
Cross-site Scripting (XSS)
Affects
@holoviz/panel
| Versions
<1.8.10-rc.0
H
Symlink Attack
CVE-2026-34604
Affects
@tinacms/graphql
| Versions
<2.2.2
H
Symlink Attack
CVE-2026-34603
Affects
@tinacms/graphql
| Versions
<2.2.2
C
Malicious Package
Affects
@logcore/pino-pretty-logger
| Versions
*
C
Malicious Package
Affects
mcp-server-todo
| Versions
*
C
Malicious Package
Affects
base-x-64
| Versions
*
C
Malicious Package
Affects
raydium-bs58
| Versions
*
C
Malicious Package
Affects
ethersproject-wallet
| Versions
*
C
Malicious Package
Affects
bs58-basic
| Versions
*
C
Malicious Package
Affects
jellyfi-pino-pretty-logger
| Versions
*
C
Malicious Package
Affects
jonas-prettier-logger
| Versions
*
C
Malicious Package
Affects
base58-engine
| Versions
*
C
Malicious Package
Affects
base-or-engine
| Versions
*
L
SQL Injection
Affects
@langchain/google-cloud-sql-pg
| Versions
<1.0.22
H
XML Injection
CVE-2026-34601
Affects
xmldom
| Versions
*