Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
C
Arbitrary Code Injection
CVE-2026-41137
Affects
flowise
| Versions
<3.1.0
C
Arbitrary Code Injection
CVE-2026-41137
Affects
flowise-components
| Versions
<3.1.0
C
Arbitrary Code Injection
CVE-2026-41137
Affects
flowise-ui
| Versions
<3.1.0
H
Server-side Request Forgery (SSRF)
CVE-2026-41272
Affects
flowise-components
| Versions
<3.1.0
C
Incomplete List of Disallowed Inputs
CVE-2026-41265
Affects
flowise
| Versions
<3.1.0
C
Incomplete List of Disallowed Inputs
CVE-2026-41265
Affects
flowise-components
| Versions
<3.1.0
C
Incomplete List of Disallowed Inputs
CVE-2026-41265
Affects
flowise-ui
| Versions
<3.1.0
H
Symlink Attack
CVE-2026-40931
Affects
compressing
| Versions
<1.10.5
>=2.0.0 <2.1.1
M
Incorrect Authorization
CVE-2026-41427
Affects
@better-auth/oauth-provider
| Versions
>=1.4.8-beta.7 <1.6.5
>=1.7.0-beta.0
C
Malicious Package
Affects
value-slider
| Versions
*
C
Malicious Package
Affects
@than1st/baileys
| Versions
*
C
Malicious Package
Affects
@than-xs/libsignal-node
| Versions
*
C
Malicious Package
Affects
node-red-contrib-yolo-object-detection
| Versions
*
C
Malicious Package
Affects
koa-v3
| Versions
*
L
Time-of-check Time-of-use (TOCTOU) Race Condition
Affects
openclaw
| Versions
<2026.4.10
C
Incorrect Authorization
Affects
@clerk/shared
| Versions
>=2.20.17 <2.22.1
>=3.47.3 <3.47.4
>=4.0.0 <4.8.1
C
Incorrect Authorization
Affects
@clerk/nuxt
| Versions
>=1.1.0 <1.13.28
>=2.0.0 <2.2.2
C
Incorrect Authorization
Affects
@clerk/nextjs
| Versions
>=5.0.0-alpha-v5.0 <5.7.6
>=6.0.0 <6.39.2
>=7.0.0 <7.2.1
C
Incorrect Authorization
Affects
@clerk/astro
| Versions
<1.5.7
>=2.0.0 <2.17.10
>=3.0.0 <3.0.15
C
Interpretation Conflict
CVE-2026-6270
Affects
@fastify/middie
| Versions
<9.3.2
C
Interpretation Conflict
CVE-2026-33804
Affects
@fastify/middie
| Versions
<9.3.2
M
Directory Traversal
CVE-2026-6410
Affects
@fastify/static
| Versions
>=8.0.0 <9.1.1
H
Improper Handling of URL Encoding (Hex Encoding)
CVE-2026-6414
Affects
@fastify/static
| Versions
>=8.0.0 <9.1.1
H
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-40897
Affects
mathjs
| Versions
>=13.1.1 <15.2.0
H
Server-side Request Forgery (SSRF)
Affects
@angular/platform-server
| Versions
<19.2.21
>=20.0.0-next.0 <20.3.19
>=21.0.0-next.0 <21.2.9
>=22.0.0-next.0 <22.0.0-next.8
H
Allocation of Resources Without Limits or Throttling
CVE-2026-41324
Affects
basic-ftp
| Versions
<5.3.0
C
Arbitrary Code Injection
CVE-2026-41242
Affects
protobufjs
| Versions
>=7.5.2 <7.5.5
>=8.0.0-experimental <8.0.1
M
Cross-site Scripting (XSS)
CVE-2026-33889
Affects
apostrophe
| Versions
<4.29.0
M
Incorrect Authorization
CVE-2026-33888
Affects
apostrophe
| Versions
<4.29.0
L
Cross-site Scripting (XSS)
CVE-2026-40186
Affects
sanitize-html
| Versions
>=2.17.2 <2.17.3