Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
HTTP Response Splitting
CVE-2026-40175
Affects
axios
| Versions
<1.15.0
H
Allocation of Resources Without Limits or Throttling
CVE-2026-40073
Affects
@sveltejs/kit
| Versions
<2.57.1
M
Improper Handling of Exceptional Conditions
CVE-2026-40074
Affects
@sveltejs/kit
| Versions
<2.57.1
C
Malicious Package
Affects
cline
| Versions
=2.3.0
M
Server-side Request Forgery (SSRF)
Affects
openclaw
| Versions
<2026.4.8
L
Improper Privilege Management
Affects
openclaw
| Versions
<2026.4.8
H
Incomplete List of Disallowed Inputs
Affects
openclaw
| Versions
<2026.4.8
M
Improper Input Validation
Affects
openclaw
| Versions
<2026.4.8
M
Server-side Request Forgery (SSRF)
CVE-2026-6011
Affects
openclaw
| Versions
<2026.1.29
L
Allocation of Resources Without Limits or Throttling
Affects
openclaw
| Versions
<2026.4.5
L
Reliance on Untrusted Inputs in a Security Decision
CVE-2026-35617
Affects
openclaw
| Versions
<2026.3.28-beta.1
M
Server-side Request Forgery (SSRF)
Affects
openclaw
| Versions
<2026.4.8
H
Authentication Bypass Using an Alternate Path or Channel
Affects
openclaw
| Versions
<2026.4.8
M
Server-side Request Forgery (SSRF)
Affects
openclaw
| Versions
<2026.4.8
M
Improper Privilege Management
Affects
openclaw
| Versions
<2026.4.8
L
Cross-site Scripting (XSS)
Affects
telejson
| Versions
<6.0.0
L
Incorrect Regular Expression
CVE-2026-35040
Affects
fast-jwt
| Versions
<6.2.1
M
Regular Expression Denial of Service (ReDoS)
CVE-2026-35041
Affects
fast-jwt
| Versions
>=5.0.0 <6.2.1
M
Incomplete List of Disallowed Inputs
CVE-2026-39315
Affects
unhead
| Versions
<2.1.13
C
Unintended Proxy or Intermediary ('Confused Deputy')
CVE-2025-62718
Affects
axios
| Versions
<0.31.0
>=1.0.0 <1.15.0
M
Arbitrary Command Injection
CVE-2026-5603
Affects
@elgentos/magento2-dev-mcp
| Versions
>=0.0.0
M
Arbitrary Command Injection
CVE-2026-5602
Affects
@nor2/heim-mcp
| Versions
>=0.0.0
H
Uncontrolled Recursion
Affects
@stablelib/cbor
| Versions
<2.0.3
C
Deserialization of Untrusted Data
CVE-2026-39890
Affects
praisonai
| Versions
>=0.0.0
H
Server-side Request Forgery (SSRF)
CVE-2026-39974
Affects
n8n-mcp
| Versions
<2.47.4
M
Arbitrary Code Injection
CVE-2026-39888
Affects
praisonai
| Versions
>=0.0.0
H
Directory Traversal
Affects
praisonai
| Versions
>=0.0.0
H
Allocation of Resources Without Limits or Throttling
CVE-2026-23869
Affects
@modern-js/utils
| Versions
>=2.65.2 <2.70.5
H
Allocation of Resources Without Limits or Throttling
CVE-2026-23869
Affects
next
| Versions
>=13.0.0 <15.5.15
>=15.6.0-canary.0 <16.2.3
H
Allocation of Resources Without Limits or Throttling
CVE-2026-23869
Affects
react-server-dom-webpack
| Versions
>=19.0.0 <19.0.5
>=19.1.0 <19.1.6
>=19.2.0 <19.2.5