Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
C
Improper Authentication
CVE-2026-29792
Affects
@feathersjs/authentication-oauth
| Versions
>=5.0.0 <5.0.42
H
Regular Expression Denial of Service (ReDoS)
CVE-2026-30837
Affects
elysia
| Versions
<1.4.26
M
Directory Traversal
CVE-2026-3089
Affects
@actual-app/sync-server
| Versions
<26.3.0
L
Authorization Bypass Through User-Controlled Key
CVE-2026-30959
Affects
@oneuptime/common
| Versions
<10.0.21
M
Exposed Dangerous Method or Function
CVE-2026-30957
Affects
@oneuptime/common
| Versions
>=10.0.15 <10.0.21
M
Missing Authorization
CVE-2026-30956
Affects
@oneuptime/common
| Versions
<10.0.21
M
Information Exposure
CVE-2026-32098
Affects
parse-server
| Versions
<8.6.35
>=9.0.0-alpha.1 <9.6.0-alpha.9
H
SQL Injection
CVE-2026-32234
Affects
parse-server
| Versions
<8.6.36
>=9.0.0-alpha.1 <9.6.0-alpha.10
H
Incorrect Authorization
CVE-2026-30870
Affects
@powersync/service-sync-rules
| Versions
<0.33.0
C
Missing Authorization
CVE-2026-30966
Affects
parse-server
| Versions
<8.6.20
>=9.0.0-alpha.1 <9.5.2-alpha.7
M
Insufficiently Protected Credentials
CVE-2026-30967
Affects
parse-server
| Versions
<8.6.22
>=9.0.0-alpha.1 <9.5.2-alpha.9
H
Allocation of Resources Without Limits or Throttling
CVE-2026-30946
Affects
parse-server
| Versions
<8.6.15
>=9.0.0-alpha.1 <9.5.2-alpha.2
C
SQL Injection
CVE-2026-31871
Affects
parse-server
| Versions
<8.6.31
>=9.0.0-alpha.1 <9.6.0-alpha.5
H
Incorrect Authorization
CVE-2026-30947
Affects
parse-server
| Versions
<8.6.16
>=9.0.0-alpha.1 <9.5.2-alpha.3
M
Improper Control of Interaction Frequency
CVE-2026-30972
Affects
parse-server
| Versions
<8.6.23
>=9.0.0-alpha.1 <9.5.2-alpha.10
C
Operation on a Resource after Expiration or Release
CVE-2026-31875
Affects
parse-server
| Versions
<8.6.33
>=9.0.0-alpha.1 <9.6.0-alpha.7
C
Improper Neutralization of Special Elements in Data Query Logic
CVE-2026-30941
Affects
parse-server
| Versions
<8.6.14
>=9.0.0-alpha.1 <9.5.2-alpha.1
H
Incorrect Authorization
CVE-2026-31872
Affects
parse-server
| Versions
<8.6.32
>=9.0.0-alpha.1 <9.6.0-alpha.6
M
Information Exposure
CVE-2026-31901
Affects
parse-server
| Versions
<8.6.34
>=9.0.0-alpha.1 <9.6.0-alpha.8
M
Cross-site Scripting (XSS)
CVE-2026-31868
Affects
parse-server
| Versions
<8.6.30
>=9.0.0-alpha.1 <9.6.0-alpha.4
M
LDAP Injection
CVE-2026-31828
Affects
parse-server
| Versions
<8.6.26
>=9.0.0-alpha.1 <9.5.2-alpha.13
H
Incorrect Authorization
CVE-2026-30962
Affects
parse-server
| Versions
<8.6.19
>=9.0.0-alpha.1 <9.5.2-alpha.6
C
Improper Handling of Case Sensitivity
CVE-2026-4047
Affects
@whyour/qinglong
| Versions
<2.20.2-0
H
Missing Authorization
CVE-2026-31800
Affects
parse-server
| Versions
<8.6.25
>=9.0.0-alpha.1 <9.5.2-alpha.12
C
SQL Injection
CVE-2026-31856
Affects
parse-server
| Versions
<8.6.29
>=9.0.0-alpha.1 <9.6.0-alpha.3
C
SQL Injection
CVE-2026-31840
Affects
parse-server
| Versions
<8.6.28
>=9.0.0-alpha.1 <9.6.0-alpha.2
M
Improper Encoding or Escaping of Output
CVE-2026-32094
Affects
shescape
| Versions
<2.1.10
C
Remote Code Execution (RCE)
CVE-2026-3965
Affects
@whyour/qinglong
| Versions
<2.20.2-0
M
Prototype Pollution
CVE-2026-30226
Affects
devalue
| Versions
>=4.0.0 <5.6.4
M
Off-by-one Error
CVE-2026-31988
Affects
yauzl
| Versions
>=3.2.0 <3.2.1