Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
C
Malicious Package
Affects
iron-overlay-behavior
| Versions
*
C
Malicious Package
Affects
iron-media-query
| Versions
*
C
Malicious Package
Affects
falcologgerinternalstate
| Versions
*
C
Malicious Package
Affects
@rothaus/falcologgerinternalstate
| Versions
*
C
Malicious Package
Affects
@mmm-otrade/transaction-adapter
| Versions
*
C
Malicious Package
Affects
@platform-growth/guidance-channel-provider
| Versions
*
C
Malicious Package
Affects
iron-localstorage
| Versions
*
C
Malicious Package
Affects
iron-image
| Versions
*
C
Malicious Package
Affects
iron-signals
| Versions
*
C
Malicious Package
Affects
amt-package-united-icons
| Versions
*
C
Malicious Package
Affects
collab-library
| Versions
*
C
Malicious Package
Affects
monoping
| Versions
*
C
Malicious Package
Affects
json-merge-tool
| Versions
*
C
Malicious Package
Affects
jsonify-core
| Versions
*
M
Cross-site Scripting (XSS)
CVE-2026-30830
Affects
defuddle
| Versions
<0.9.0
M
Origin Validation Error
CVE-2025-68467
Affects
darkreader
| Versions
<4.9.117
C
Malicious Package
Affects
odds-analyzer
| Versions
*
C
Malicious Package
Affects
tw-modern-ui
| Versions
*
H
Arbitrary Code Injection
CVE-2026-30887
Affects
@oneuptime/common
| Versions
<10.0.18
H
Access Control Bypass
CVE-2026-30820
Affects
flowise
| Versions
<3.0.13
C
Arbitrary File Upload
CVE-2026-30821
Affects
flowise
| Versions
<3.0.13
C
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-30822
Affects
flowise
| Versions
<3.0.13
H
Missing Authentication for Critical Function
CVE-2026-30824
Affects
flowise
| Versions
<3.0.13
H
Allocation of Resources Without Limits or Throttling
CVE-2026-30827
Affects
express-rate-limit
| Versions
>=8.0.0 <8.0.2
>=8.1.0 <8.1.1
>=8.2.0 <8.2.2
H
Weak Password Recovery Mechanism for Forgotten Password
Affects
@workflow/core
| Versions
<4.2.0-beta.64
M
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-3484
Affects
mcp-nmap-server
| Versions
*
M
Missing Authorization
CVE-2026-30850
Affects
parse-server
| Versions
<8.6.9
>=9.0.0-alpha.1 <9.5.0-alpha.9
H
Improper Verification of Cryptographic Signature
CVE-2026-30863
Affects
parse-server
| Versions
<8.6.10
>=9.0.0-alpha.1 <9.5.0-alpha.11
H
Directory Traversal
CVE-2026-30848
Affects
parse-server
| Versions
<8.6.8
>=9.0.0-alpha.1 <9.5.0-alpha.8
M
Incorrect Authorization
CVE-2026-30854
Affects
parse-server
| Versions
>=9.3.1-alpha.3 <9.5.0-alpha.10