Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
C
Malicious Package
Affects
transform-es2015-spread
| Versions
*
C
Malicious Package
Affects
transform-export-extensions
| Versions
*
C
Malicious Package
Affects
transform-es2015-duplicate-keys
| Versions
*
C
Malicious Package
Affects
syntax-export-extensions
| Versions
*
C
Malicious Package
Affects
syntax-class-constructor-call
| Versions
*
C
Malicious Package
Affects
syntax-async-generators
| Versions
*
C
Malicious Package
Affects
syntax-do-expressions
| Versions
*
C
Malicious Package
Affects
syntax-function-bind
| Versions
*
C
Malicious Package
Affects
webmd-url
| Versions
*
H
Use of Hard-coded Cryptographic Key
Affects
@frangoteam/fuxa
| Versions
<1.3.0
H
HTTP Header Injection
CVE-2025-70948
Affects
@perfood/couch-auth
| Versions
*
M
Timing Attack
CVE-2025-70949
Affects
@perfood/couch-auth
| Versions
*
C
Improper Authentication
CVE-2026-29792
Affects
@feathersjs/authentication-oauth
| Versions
>=5.0.0 <5.0.42
H
Regular Expression Denial of Service (ReDoS)
CVE-2026-30837
Affects
elysia
| Versions
<1.4.26
M
Directory Traversal
CVE-2026-3089
Affects
@actual-app/sync-server
| Versions
<26.3.0
L
Authorization Bypass Through User-Controlled Key
CVE-2026-30959
Affects
@oneuptime/common
| Versions
<10.0.21
M
Exposed Dangerous Method or Function
CVE-2026-30957
Affects
@oneuptime/common
| Versions
>=10.0.15 <10.0.21
M
Missing Authorization
CVE-2026-30956
Affects
@oneuptime/common
| Versions
<10.0.21
M
Information Exposure
CVE-2026-32098
Affects
parse-server
| Versions
<8.6.35
>=9.0.0-alpha.1 <9.6.0-alpha.9
H
SQL Injection
CVE-2026-32234
Affects
parse-server
| Versions
<8.6.36
>=9.0.0-alpha.1 <9.6.0-alpha.10
H
Incorrect Authorization
CVE-2026-30870
Affects
@powersync/service-sync-rules
| Versions
<0.33.0
C
Missing Authorization
CVE-2026-30966
Affects
parse-server
| Versions
<8.6.20
>=9.0.0-alpha.1 <9.5.2-alpha.7
M
Insufficiently Protected Credentials
CVE-2026-30967
Affects
parse-server
| Versions
<8.6.22
>=9.0.0-alpha.1 <9.5.2-alpha.9
H
Allocation of Resources Without Limits or Throttling
CVE-2026-30946
Affects
parse-server
| Versions
<8.6.15
>=9.0.0-alpha.1 <9.5.2-alpha.2
C
SQL Injection
CVE-2026-31871
Affects
parse-server
| Versions
<8.6.31
>=9.0.0-alpha.1 <9.6.0-alpha.5
H
Incorrect Authorization
CVE-2026-30947
Affects
parse-server
| Versions
<8.6.16
>=9.0.0-alpha.1 <9.5.2-alpha.3
M
Improper Control of Interaction Frequency
CVE-2026-30972
Affects
parse-server
| Versions
<8.6.23
>=9.0.0-alpha.1 <9.5.2-alpha.10
C
Operation on a Resource after Expiration or Release
CVE-2026-31875
Affects
parse-server
| Versions
<8.6.33
>=9.0.0-alpha.1 <9.6.0-alpha.7
C
Improper Neutralization of Special Elements in Data Query Logic
CVE-2026-30941
Affects
parse-server
| Versions
<8.6.14
>=9.0.0-alpha.1 <9.5.2-alpha.1
H
Incorrect Authorization
CVE-2026-31872
Affects
parse-server
| Versions
<8.6.32
>=9.0.0-alpha.1 <9.6.0-alpha.6