Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Missing Authorization
CVE-2026-41266
Affects
flowise
| Versions
<3.1.0
C
Embedded Malicious Code
Affects
kube-health-tools
| Versions
*
H
Arbitrary File Upload
CVE-2026-41269
Affects
flowise-components
| Versions
<3.1.0
H
Arbitrary File Upload
CVE-2026-41269
Affects
flowise
| Versions
<3.1.0
H
Missing Authentication for Critical Function
CVE-2026-41273
Affects
flowise
| Versions
<3.1.0
M
Use of Hard-coded Credentials
Affects
flowise
| Versions
<3.1.0
M
Use of Hard-coded Credentials
Affects
flowise
| Versions
<3.1.0
M
Cross-site Scripting (XSS)
CVE-2026-41067
Affects
astro
| Versions
<6.1.6
C
Malicious Package
Affects
@bitunix/test
| Versions
*
C
Malicious Package
Affects
@usealloy/component-library
| Versions
*
C
Malicious Package
Affects
claudcode-cli
| Versions
*
C
Malicious Package
Affects
aven_types
| Versions
*
C
Malicious Package
Affects
trackora-chain
| Versions
*
C
Malicious Package
Affects
trackora-node
| Versions
*
C
Malicious Package
Affects
js-logger-pack
| Versions
*
C
Malicious Package
Affects
@usealloy/typegen
| Versions
*
C
Malicious Package
Affects
ts-utils-dev
| Versions
*
C
Malicious Package
Affects
claudcode-mcp
| Versions
*
C
Malicious Package
Affects
gleb-js
| Versions
*
C
Malicious Package
Affects
crypto-keccak-js
| Versions
*
C
Malicious Package
Affects
chai-as-encrypted
| Versions
*
C
Embedded Malicious Code
Affects
@openwebconcept/theme-owc
| Versions
>=1.0.1 <=1.0.3
C
Embedded Malicious Code
Affects
@openwebconcept/design-tokens
| Versions
>=1.0.1 <=1.0.3
C
Embedded Malicious Code
Affects
@automagik/genie
| Versions
>=4.260421.33 <=4.260421.39
C
Embedded Malicious Code
Affects
pgserve
| Versions
>=1.1.11 <=1.1.14
C
Malicious Package
Affects
@usealloy/api-contract
| Versions
*
C
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-41267
Affects
flowise
| Versions
<3.1.0
C
Malicious Package
Affects
com.tencent.puerts.agent
| Versions
*
C
Command Injection
CVE-2026-41500
Affects
electerm
| Versions
<3.3.8
M
Server-side Request Forgery (SSRF)
CVE-2026-40346
Affects
@nocobase/plugin-workflow-request
| Versions
<2.0.37