Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Timing Attack
Affects
hono
| Versions
<4.11.10
L
Cross-site Scripting (XSS)
CVE-2026-27122
Affects
svelte
| Versions
<5.51.5
M
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-27125
Affects
svelte
| Versions
<5.51.5
C
Prototype Pollution
CVE-2026-27212
Affects
swiper
| Versions
>=6.5.1 <12.1.2
L
Prototype Pollution
Affects
devalue
| Versions
<5.6.3
H
Improper Authentication
CVE-2026-28465
Affects
@openclaw/voice-call
| Versions
<2026.2.3
M
Allocation of Resources Without Limits or Throttling
Affects
devalue
| Versions
<5.6.3
H
Improper Encoding or Escaping of Output
CVE-2026-25940
Affects
jspdf
| Versions
<4.2.0
C
User Impersonation
CVE-2026-28474
Affects
@openclaw/nextcloud-talk
| Versions
<2026.2.6
H
Allocation of Resources Without Limits or Throttling
CVE-2026-25535
Affects
jspdf
| Versions
<4.2.0
H
Improper Encoding or Escaping of Output
CVE-2026-25755
Affects
jspdf
| Versions
<4.2.0
H
Command Injection
CVE-2026-26280
Affects
systeminformation
| Versions
<5.30.8
M
Cross-site Scripting (XSS)
CVE-2026-27009
Affects
openclaw
| Versions
<2026.2.15
M
Incorrect Comparison Logic Granularity
CVE-2026-27007
Affects
openclaw
| Versions
<2026.2.15
M
Insufficiently Protected Credentials
CVE-2026-27003
Affects
openclaw
| Versions
<2026.2.15
M
External Control of File Name or Path
CVE-2026-27008
Affects
openclaw
| Versions
<2026.2.15
M
Origin Validation Error
CVE-2026-27004
Affects
openclaw
| Versions
<2026.2.15
H
Arbitrary Command Injection
CVE-2026-27001
Affects
openclaw
| Versions
<2026.2.15
C
SQL Injection
CVE-2026-26980
Affects
ghost
| Versions
>=3.24.0 <6.19.1
H
Execution with Unnecessary Privileges
CVE-2026-27002
Affects
openclaw
| Versions
<2026.2.15
H
Command Injection
CVE-2026-27487
Affects
openclaw
| Versions
<2026.2.14
M
Cross-site Scripting (XSS)
CVE-2026-27013
Affects
fabric
| Versions
<7.2.0
M
Infinite loop
CVE-2026-2739
Affects
bn.js
| Versions
<4.12.3
>=5.0.0 <5.2.3
H
Command Injection
CVE-2026-26318
Affects
systeminformation
| Versions
<5.31.0
H
Regular Expression Denial of Service (ReDoS)
CVE-2026-26996
Affects
minimatch
| Versions
<3.1.3
>=4.0.0 <4.2.4
>=5.0.0 <5.1.7
>=6.0.0 <6.2.1
>=7.0.0 <7.4.7
>=8.0.0 <8.0.5
>=9.0.0 <9.0.6
>=10.0.0 <10.2.1
L
Improper Output Neutralization for Logs
Affects
openclaw
| Versions
<2026.2.13
L
Incorrect Authorization
Affects
openclaw
| Versions
<2026.2.14
L
Arbitrary Code Injection
CVE-2026-24764
Affects
openclaw
| Versions
<2026.2.3
M
Improper Authorization
CVE-2026-28392
Affects
openclaw
| Versions
<2026.2.14
M
User Impersonation
CVE-2026-28480
Affects
openclaw
| Versions
<2026.2.14