Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
C
Malicious Package
Affects
transform-json-strings
| Versions
*
C
Malicious Package
Affects
transform-inline-consecutive-adds
| Versions
*
C
Malicious Package
Affects
transform-charcodes
| Versions
*
C
Malicious Package
Affects
transform-for-of
| Versions
*
C
Malicious Package
Affects
transform-new-target
| Versions
*
C
Malicious Package
Affects
transform-typescript
| Versions
*
C
Malicious Package
Affects
transform-es2015-shorthand-properties
| Versions
*
C
Malicious Package
Affects
transform-es2015-parameters
| Versions
*
C
Malicious Package
Affects
add-react-displayname
| Versions
*
C
Malicious Package
Affects
transform-member-expression-literals
| Versions
*
C
Malicious Package
Affects
transform-regexp-constructors
| Versions
*
C
Malicious Package
Affects
transform-proto-to-assign
| Versions
*
C
Malicious Package
Affects
transform-function-bind
| Versions
*
C
Malicious Package
Affects
transform-es2015-spread
| Versions
*
C
Malicious Package
Affects
transform-export-extensions
| Versions
*
C
Malicious Package
Affects
transform-es2015-duplicate-keys
| Versions
*
C
Malicious Package
Affects
syntax-export-extensions
| Versions
*
C
Malicious Package
Affects
syntax-class-constructor-call
| Versions
*
C
Malicious Package
Affects
syntax-async-generators
| Versions
*
C
Malicious Package
Affects
syntax-do-expressions
| Versions
*
C
Malicious Package
Affects
syntax-function-bind
| Versions
*
C
Malicious Package
Affects
webmd-url
| Versions
*
H
Use of Hard-coded Cryptographic Key
Affects
@frangoteam/fuxa
| Versions
<1.3.0
H
HTTP Header Injection
CVE-2025-70948
Affects
@perfood/couch-auth
| Versions
*
M
Timing Attack
CVE-2025-70949
Affects
@perfood/couch-auth
| Versions
*
C
Improper Authentication
CVE-2026-29792
Affects
@feathersjs/authentication-oauth
| Versions
>=5.0.0 <5.0.42
H
Regular Expression Denial of Service (ReDoS)
CVE-2026-30837
Affects
elysia
| Versions
<1.4.26
M
Directory Traversal
CVE-2026-3089
Affects
@actual-app/sync-server
| Versions
<26.3.0
L
Authorization Bypass Through User-Controlled Key
CVE-2026-30959
Affects
@oneuptime/common
| Versions
<10.0.21
M
Exposed Dangerous Method or Function
CVE-2026-30957
Affects
@oneuptime/common
| Versions
>=10.0.15 <10.0.21