Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
XML Entity Expansion (Billion Laughs)
CVE-2026-29074
Affects
svgo
| Versions
>=2.1.0 <2.8.1
>=3.0.0 <3.3.3
>=4.0.0 <4.0.1
M
Directory Traversal
Affects
openclaw
| Versions
<2026.2.21
H
Symlink Attack
Affects
openclaw
| Versions
<2026.2.25
H
Reliance on IP Address for Authentication
Affects
openclaw
| Versions
<2026.2.19
M
Incorrect Authorization
CVE-2026-22170
Affects
@openclaw/bluebubbles
| Versions
<2026.2.22
M
Incorrect Authorization
CVE-2026-22170
Affects
openclaw
| Versions
<2026.2.22
H
Incorrect Authorization
CVE-2026-32005
Affects
openclaw
| Versions
<2026.2.25
M
Authorization Bypass Through User-Controlled Key
Affects
openclaw
| Versions
<2026.2.22
M
Files or Directories Accessible to External Parties
CVE-2026-32002
Affects
openclaw
| Versions
<2026.2.23-beta.1
M
Server-side Request Forgery (SSRF)
CVE-2026-32019
Affects
openclaw
| Versions
<2026.2.22
M
Symlink Attack
Affects
openclaw
| Versions
<2026.2.22
L
Incorrect Authorization
CVE-2026-32067
Affects
@openclaw/zalo
| Versions
<2026.3.1
L
Incorrect Authorization
CVE-2026-32067
Affects
@openclaw/zalouser
| Versions
<2026.3.1
L
Incorrect Authorization
CVE-2026-32067
Affects
@openclaw/nextcloud-talk
| Versions
<2026.3.1
L
Incorrect Authorization
CVE-2026-32067
Affects
@openclaw/msteams
| Versions
<2026.3.1
L
Incorrect Authorization
CVE-2026-32067
Affects
@openclaw/mattermost
| Versions
*
L
Incorrect Authorization
CVE-2026-32067
Affects
@openclaw/matrix
| Versions
<2026.3.1
L
Incorrect Authorization
CVE-2026-32067
Affects
@openclaw/feishu
| Versions
<2026.3.1
L
Incorrect Authorization
CVE-2026-32067
Affects
@openclaw/bluebubbles
| Versions
<2026.3.1
L
Incorrect Authorization
CVE-2026-32067
Affects
openclaw
| Versions
<2026.2.26
M
CRLF Injection
CVE-2026-29085
Affects
hono
| Versions
>=3.8.0 <4.12.4
M
Server-side Request Forgery (SSRF)
Affects
openclaw
| Versions
<2026.2.19
M
Server-side Request Forgery (SSRF)
Affects
@openclaw/nostr
| Versions
<2026.2.19
M
Improper Handling of URL Encoding (Hex Encoding)
CVE-2026-29045
Affects
hono
| Versions
<4.12.4
C
Prototype Pollution
CVE-2026-29063
Affects
immutable
| Versions
<3.8.3
>=4.0.0-rc.1 <4.3.8
>=5.0.0-beta.1 <5.1.5
M
CRLF Injection
CVE-2026-29086
Affects
hono
| Versions
>=0.2.1 <4.12.4
H
Uncontrolled Recursion
CVE-2026-3520
Affects
multer
| Versions
<2.1.1
H
Symlink Attack
CVE-2026-29786
Affects
tar
| Versions
<7.5.10
M
Missing Authorization
Affects
@openclaw/msteams
| Versions
<2026.2.25
M
Missing Authentication for Critical Function
Affects
openclaw
| Versions
<2026.2.19