Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Cross-site Request Forgery (CSRF)
CVE-2025-64166
Affects
mercurius
| Versions
<16.4.0
M
Incorrect Regular Expression
CVE-2026-3419
Affects
fastify
| Versions
>=5.7.2 <5.8.1
C
Malicious Package
Affects
pear-apps-utils-date
| Versions
*
C
Malicious Package
Affects
pear-apps-utils-avatar-initials
| Versions
*
C
Malicious Package
Affects
imhuman-fw-logger
| Versions
*
C
Malicious Package
Affects
pear-apps-lib-ui-react-hooks
| Versions
*
C
Malicious Package
Affects
@imhuman/corp-build-utils-poc
| Versions
*
C
Malicious Package
Affects
@imhuman/fw-logger
| Versions
*
M
Directory Traversal
CVE-2026-29185
Affects
@backstage/integration
| Versions
<1.20.1
>=1.21.0-next.0
C
Malicious Package
Affects
nf-referral-backend
| Versions
*
C
Malicious Package
Affects
pearpass-utils-password-check
| Versions
*
C
Malicious Package
Affects
pearpass-lib-data-export
| Versions
*
C
Malicious Package
Affects
pear-apps-utils-qr
| Versions
*
C
Malicious Package
Affects
pearpass-lib-data-import
| Versions
*
C
Malicious Package
Affects
pear-apps-lib-feedback
| Versions
*
C
Malicious Package
Affects
nf-referral-backend-placeholder
| Versions
*
C
Prototype Pollution
CVE-2026-28794
Affects
@orpc/client
| Versions
<1.13.6
H
Incorrect Authorization
CVE-2026-29182
Affects
parse-server
| Versions
<8.6.4
>=9.0.0-alpha.1 <9.4.1-alpha.3
C
Eval Injection
CVE-2026-29091
Affects
locutus
| Versions
<3.0.0
H
Permissive List of Allowed Inputs
CVE-2026-29186
Affects
@backstage/plugin-techdocs-node
| Versions
>=1.13.11 <1.14.3
L
Insertion of Sensitive Information into Log File
CVE-2026-29184
Affects
@backstage/plugin-scaffolder-backend
| Versions
<3.1.4
M
Improper Handling of URL Encoding (Hex Encoding)
CVE-2026-29087
Affects
@hono/node-server
| Versions
<1.19.10
H
XML Entity Expansion (Billion Laughs)
CVE-2026-29074
Affects
svgo
| Versions
>=2.1.0 <2.8.1
>=3.0.0 <3.3.3
>=4.0.0 <4.0.1
M
Directory Traversal
Affects
openclaw
| Versions
<2026.2.21
H
Symlink Attack
Affects
openclaw
| Versions
<2026.2.25
H
Reliance on IP Address for Authentication
Affects
openclaw
| Versions
<2026.2.19
M
Incorrect Authorization
Affects
@openclaw/bluebubbles
| Versions
<2026.2.22
M
Incorrect Authorization
Affects
openclaw
| Versions
<2026.2.22
H
Incorrect Authorization
Affects
openclaw
| Versions
<2026.2.25
M
Authorization Bypass Through User-Controlled Key
Affects
openclaw
| Versions
<2026.2.22