Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Insertion of Sensitive Information into Log File
Affects
langsmith
| Versions
<0.5.19
M
Cross-site Scripting (XSS)
Affects
hono
| Versions
<4.12.14
M
Command Injection
CVE-2026-5528
Affects
code-screenshot-mcp
| Versions
*
M
Server-side Request Forgery (SSRF)
CVE-2026-22662
Affects
prompts.chat
| Versions
*
H
Directory Traversal
CVE-2026-22661
Affects
prompts.chat
| Versions
*
H
Improper Handling of Case Sensitivity
CVE-2026-22665
Affects
prompts.chat
| Versions
*
H
Missing Authorization
CVE-2026-22663
Affects
prompts.chat
| Versions
*
H
Server-side Request Forgery (SSRF)
CVE-2026-22664
Affects
prompts.chat
| Versions
*
M
Operator Precedence Logic Error
Affects
dompurify
| Versions
<3.4.0
M
Server-side Request Forgery (SSRF)
CVE-2026-5470
Affects
google-search-mcp
| Versions
*
C
Malicious Package
Affects
tether-wrk-base
| Versions
*
C
Malicious Package
Affects
tensorzero-node
| Versions
*
C
Malicious Package
Affects
@pnc-cib/cib-core-lib
| Versions
*
C
Malicious Package
Affects
fusion-events
| Versions
*
C
Malicious Package
Affects
vs-supplier-portal-web
| Versions
*
C
Malicious Package
Affects
base-counter-web
| Versions
*
C
Malicious Package
Affects
laserlogsink
| Versions
*
C
Malicious Package
Affects
com.baogong.app_push_permission
| Versions
*
C
Missing Authorization
CVE-2026-39397
Affects
@delmaredigital/payload-puck
| Versions
<0.6.23
H
SQL Injection
Affects
@vendure/core
| Versions
>=1.7.4 <2.3.4
>=3.0.0-next.0 <3.5.7
>=3.6.0 <3.6.2
C
Command Injection
CVE-2026-28291
Affects
simple-git
| Versions
<3.32.0
C
Interpretation Conflict
CVE-2026-33808
Affects
@fastify/express
| Versions
<4.0.5
C
Interpretation Conflict
CVE-2026-33807
Affects
@fastify/express
| Versions
<4.0.5
C
HTTP Header Injection
CVE-2026-33805
Affects
@fastify/http-proxy
| Versions
<11.4.4
C
HTTP Header Injection
CVE-2026-33805
Affects
@fastify/reply-from
| Versions
<12.6.2
M
Open Redirect
CVE-2026-40255
Affects
@adonisjs/http-server
| Versions
<7.8.1
>=8.0.0-next.0 <8.2.0
H
Improper Validation of Specified Type of Input
CVE-2026-33806
Affects
fastify
| Versions
>=4.29.0 <5.8.5
C
Malicious Package
Affects
snitz-chief-cloud-config
| Versions
*
C
Malicious Package
Affects
snitz-chief-cloud
| Versions
*
C
Malicious Package
Affects
pdf-linker
| Versions
*