Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
C
Malicious Package
Affects
json-dec
| Versions
*
C
Malicious Package
Affects
changelog-utils-structured-logger
| Versions
*
C
Malicious Package
Affects
undicy-http
| Versions
*
C
Malicious Package
Affects
separadordeinfocc
| Versions
*
C
Malicious Package
Affects
changelog-cli-logger
| Versions
*
C
Malicious Package
Affects
@amsterdam-local/forms-component-library
| Versions
*
C
Malicious Package
Affects
shenxun162938
| Versions
*
C
Malicious Package
Affects
spr-i18n-labels
| Versions
*
C
Malicious Package
Affects
json-spacer
| Versions
*
C
Malicious Package
Affects
rollup-plugin-polyfill-route
| Versions
*
C
Malicious Package
Affects
ts-bing
| Versions
*
C
Malicious Package
Affects
ts-moduler
| Versions
*
C
Malicious Package
Affects
vime-azl
| Versions
*
M
XML Injection
CVE-2026-41650
Affects
fast-xml-builder
| Versions
<1.1.5
H
XML Injection
CVE-2026-41672
Affects
xmldom
| Versions
*
H
XML Injection
CVE-2026-41672
Affects
@xmldom/xmldom
| Versions
<0.8.13
>=0.9.0 <0.9.10
M
Improper Validation of Specified Index, Position, or Offset in Input
CVE-2026-41907
Affects
uuid
| Versions
<14.0.0
M
Cross-site Scripting (XSS)
CVE-2026-41238
Affects
dompurify
| Versions
>=3.0.1 <3.4.0
L
Cross-site Scripting (XSS)
CVE-2026-41239
Affects
dompurify
| Versions
>=1.0.10 <3.4.0
C
Malicious Package
Affects
sparkling-sdk
| Versions
*
C
Malicious Package
Affects
color-studio
| Versions
*
C
Malicious Package
Affects
@stlm/common-ui
| Versions
*
H
Missing Authorization
CVE-2026-41266
Affects
flowise
| Versions
<3.1.0
C
Embedded Malicious Code
Affects
kube-health-tools
| Versions
*
H
Arbitrary File Upload
CVE-2026-41269
Affects
flowise-components
| Versions
<3.1.0
H
Arbitrary File Upload
CVE-2026-41269
Affects
flowise
| Versions
<3.1.0
H
Missing Authentication for Critical Function
CVE-2026-41273
Affects
flowise
| Versions
<3.1.0
M
Use of Hard-coded Credentials
Affects
flowise
| Versions
<3.1.0
M
Use of Hard-coded Credentials
Affects
flowise
| Versions
<3.1.0
M
Cross-site Scripting (XSS)
CVE-2026-41067
Affects
astro
| Versions
<6.1.6