Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Cross-site Scripting (XSS)
CVE-2026-22787
Affects
html2pdf.js
| Versions
<0.14.0
M
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-22820
Affects
outray
| Versions
<0.1.5
M
Cross-site Scripting (XSS)
CVE-2026-0824
Affects
@questdb/web-console
| Versions
<1.1.10
H
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-22814
Affects
@adonisjs/lucid
| Versions
<21.8.2
>=22.0.0-next.0 <22.0.0-next.6
M
Regular Expression Denial of Service (ReDoS)
CVE-2026-22809
Affects
tarteaucitronjs
| Versions
<1.29.0
C
Arbitrary Command Injection
CVE-2026-22785
Affects
@orval/mcp
| Versions
<7.18.0
H
Protection Mechanism Failure
CVE-2026-22686
Affects
enclave-vm
| Versions
<2.7.0
C
Improper Validation of Specified Type of Input
CVE-2026-21858
Affects
n8n
| Versions
>=1.65.0 <1.121.0
M
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2025-15056
Affects
quill
| Versions
*
H
Arbitrary Command Injection
Affects
renovate
| Versions
>=39.218.0 <40.33.0
H
Command Injection
Affects
renovate
| Versions
>=32.124.0 <42.68.5
H
Arbitrary Command Injection
Affects
renovate
| Versions
>=35.63.0 <40.33.0
H
Arbitrary Command Injection
Affects
renovate
| Versions
>=31.51.0 <40.33.0
H
Arbitrary Command Injection
Affects
renovate
| Versions
>=39.53.0 <40.33.0
H
Arbitrary Command Injection
Affects
renovate
| Versions
>=32.135.0 <40.33.0
H
Use of a Broken or Risky Cryptographic Algorithm
CVE-2026-22817
Affects
hono
| Versions
<4.11.4
H
Improper Verification of Cryptographic Signature
CVE-2026-22818
Affects
hono
| Versions
<4.11.4
M
Permissive List of Allowed Inputs
CVE-2025-68949
Affects
n8n-nodes-base
| Versions
>=1.36.0 <1.121.7
>=2.0.0-rc.0 <2.2.0
M
Cross-site Scripting (XSS)
CVE-2025-65110
Affects
vega-selections
| Versions
<5.6.3
>=6.0.0 <6.1.2
M
Cross-site Scripting (XSS)
CVE-2025-66648
Affects
vega-functions
| Versions
>=5.8.0 <6.1.1
C
Malicious Package
Affects
n8n-nodes-zalo-vietts
| Versions
*
C
Malicious Package
Affects
n8n-nodes-rooyai-model
| Versions
*
C
Malicious Package
Affects
n8n-nodes-danev
| Versions
*
C
Malicious Package
Affects
n8n-nodes-xkwqpzrt-jmflhvbn-dsyocgxwmkelpt
| Versions
*
C
Malicious Package
Affects
n8n-nodes-gg-udhasudsh-hgjkhg-official
| Versions
*
C
Malicious Package
Affects
n8n-nodes-danev-test-project
| Versions
*
C
Malicious Package
Affects
@diendh/n8n-nodes-tiktok-v2
| Versions
*
C
Malicious Package
Affects
n8n-nodes-zl-vietts
| Versions
*
C
Malicious Package
Affects
n8n-nodes-gasdhgfuy-rejerw-ytjsadx
| Versions
*
H
Integer Overflow or Wraparound
Affects
@openzeppelin/confidential-contracts
| Versions
<0.3.1