Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Insufficiently Protected Credentials
Affects
openclaw
| Versions
>=2026.4.5 <2026.4.20-beta.1
M
Incomplete List of Disallowed Inputs
CVE-2026-44114
Affects
openclaw
| Versions
<2026.4.20-beta.1
M
Insufficient Granularity of Access Control
Affects
openclaw
| Versions
<2026.4.20-beta.1
C
Malicious Package
Affects
modern-events
| Versions
*
M
Unsafe Dependency Resolution
CVE-2026-41355
Affects
openclaw
| Versions
<2026.3.28
L
Origin Validation Error
CVE-2026-41358
Affects
openclaw
| Versions
<2026.4.2
M
Incorrect Authorization
CVE-2026-41909
Affects
openclaw
| Versions
<2026.4.20
L
Incorrect Authorization
CVE-2026-41908
Affects
openclaw
| Versions
<2026.4.20
H
Uncontrolled Recursion
CVE-2026-41311
Affects
liquidjs
| Versions
<10.25.6
C
Incomplete List of Disallowed Inputs
CVE-2026-41264
Affects
flowise-components
| Versions
<3.1.0
H
UNIX Symbolic Link (Symlink) Following
CVE-2026-39861
Affects
@anthropic-ai/claude-code
| Versions
<2.1.64
M
Use of Web Browser Cache Containing Sensitive Information
CVE-2026-41322
Affects
@astrojs/node
| Versions
<10.0.5
L
Server-side Request Forgery (SSRF)
CVE-2026-41321
Affects
@astrojs/cloudflare
| Versions
<13.1.10
H
Missing Authorization
CVE-2026-41679
Affects
@paperclipai/ui
| Versions
<2026.416.0
H
Missing Authorization
CVE-2026-41679
Affects
@paperclipai/server
| Versions
<2026.416.0
C
Malicious Package
Affects
sagat-core
| Versions
*
C
Malicious Package
Affects
auth0-ui-components-docs
| Versions
*
C
Malicious Package
Affects
wrapped-logger-utils
| Versions
*
C
Malicious Package
Affects
react-spa-shadcn
| Versions
*
C
Malicious Package
Affects
next-rwa
| Versions
*
C
Malicious Package
Affects
react-spa-npm
| Versions
*
C
Malicious Package
Affects
env_express
| Versions
*
C
Malicious Package
Affects
chain-promised-await
| Versions
*
C
Malicious Package
Affects
chai-as-optimized
| Versions
*
M
Cross-site Scripting (XSS)
CVE-2026-41305
Affects
postcss
| Versions
<8.5.10
C
Remote Code Execution (RCE)
CVE-2026-6951
Affects
simple-git
| Versions
<3.36.0
C
Embedded Malicious Code
Affects
@bitwarden/cli
| Versions
=2026.4.0
H
XML Injection
CVE-2026-41675
Affects
@xmldom/xmldom
| Versions
<0.8.13
>=0.9.0 <0.9.10
H
XML Injection
CVE-2026-41675
Affects
xmldom
| Versions
*
H
XML Injection
CVE-2026-41674
Affects
@xmldom/xmldom
| Versions
<0.8.13
>=0.9.0 <0.9.10