Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Out-of-bounds Read
CVE-2026-34776
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.1
>=40.0.0-alpha.2 <40.8.1
>=41.0.0-alpha.1 <41.0.0
H
Improper Isolation or Compartmentalization
CVE-2026-34775
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.4
>=40.0.0-alpha.2 <40.8.4
>=41.0.0-alpha.1 <41.0.0
L
Unquoted Search Path or Element
CVE-2026-34768
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.1
>=40.0.0-alpha.2 <40.8.0
>=41.0.0-alpha.1 <41.0.0-beta.8
L
Missing Authorization
CVE-2026-34766
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.0
>=40.0.0-alpha.2 <40.7.0
>=41.0.0-alpha.1 <41.0.0-beta.8
M
HTTP Response Splitting
CVE-2026-34767
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.3
>=40.0.0-alpha.2 <40.8.3
>=41.0.0-alpha.1 <41.0.3
C
Use After Free
CVE-2026-34774
Affects
electron
| Versions
<39.8.1
>=40.0.0-alpha.2 <40.7.0
>=41.0.0-alpha.1 <41.0.0
H
Insecure Default Initialization of Resource
CVE-2026-34780
Affects
electron
| Versions
>=39.0.0-alpha.1 <39.8.0
>=40.0.0-alpha.2 <40.7.0
>=41.0.0-alpha.1 <41.0.0-beta.8
H
Hidden Functionality
CVE-2026-34769
Affects
electron
| Versions
<38.8.6
>=39.0.0-alpha.1 <39.8.0
>=40.0.0-alpha.2 <40.7.0
>=41.0.0-alpha.1 <41.0.0-beta.8
M
Permissive List of Allowed Inputs
Affects
dompurify
| Versions
<3.3.2
M
Prototype Pollution
Affects
dompurify
| Versions
<3.3.2
M
Heap-based Buffer Overflow
CVE-2025-15536
Affects
opencc
| Versions
<1.2.0
H
Directory Traversal
CVE-2026-33989
Affects
@mobilenext/mobile-mcp
| Versions
<0.0.49
C
Command Injection
CVE-2026-26832
Affects
node-tesseract-ocr
| Versions
*
C
Malicious Package
Affects
@mgcrae/pino-pretty-logger
| Versions
*
C
Command Injection
CVE-2026-26831
Affects
textract
| Versions
*
H
Improper Restriction of Communication Channel to Intended Endpoints
Affects
@grackle-ai/mcp
| Versions
<0.70.2
M
Server-side Request Forgery (SSRF)
CVE-2026-34746
Affects
payload
| Versions
<3.79.1
M
Cross-site Scripting (XSS)
CVE-2026-34748
Affects
@payloadcms/ui
| Versions
<3.78.0
M
Cross-site Scripting (XSS)
CVE-2026-34748
Affects
@payloadcms/plugin-mcp
| Versions
<3.78.0
H
Directory Traversal
CVE-2026-34750
Affects
@payloadcms/storage-s3
| Versions
<3.78.0
H
Directory Traversal
CVE-2026-34750
Affects
@payloadcms/storage-r2
| Versions
<3.78.0
H
Directory Traversal
CVE-2026-34750
Affects
@payloadcms/storage-gcs
| Versions
<3.78.0
H
Directory Traversal
CVE-2026-34750
Affects
payload
| Versions
<3.78.0
M
Cross-site Request Forgery (CSRF)
CVE-2026-34749
Affects
payload
| Versions
<3.79.1
M
SQL Injection
CVE-2026-34747
Affects
payload
| Versions
<3.79.1
M
SQL Injection
CVE-2026-34747
Affects
@payloadcms/drizzle
| Versions
<3.79.1
M
Deserialization of Untrusted Data
CVE-2026-2265
Affects
replicator
| Versions
*
M
Missing Authentication for Critical Function
Affects
@grackle-ai/powerline
| Versions
<0.70.1
C
Weak Password Recovery Mechanism for Forgotten Password
CVE-2026-34751
Affects
payload
| Versions
<3.79.1
C
Weak Password Recovery Mechanism for Forgotten Password
CVE-2026-34751
Affects
@payloadcms/graphql
| Versions
<3.79.1