Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
C
User Impersonation
CVE-2026-33131
Affects
h3
| Versions
>=2.0.0-beta.0 <2.0.1-rc.15
H
Timing Attack
CVE-2026-33129
Affects
h3
| Versions
<1.15.8
>=2.0.0-beta.0 <2.0.1-rc.9
H
Information Exposure
CVE-2026-33163
Affects
parse-server
| Versions
<8.6.50
>=9.0.0 <9.6.0-alpha.35
M
CRLF Injection
CVE-2026-33128
Affects
h3
| Versions
<1.15.6
>=2.0.0 <2.0.1-rc.15
H
Server-side Request Forgery (SSRF)
CVE-2026-26801
Affects
pdfmake
| Versions
>=0.3.0-beta.2
C
Prototype Pollution
CVE-2026-32621
Affects
@apollo/federation-internals
| Versions
<2.9.6
>=2.10.0-alpha.0 <2.10.5
>=2.11.0-preview.0 <2.11.6
>=2.12.0-preview.0 <2.12.3
>=2.13.0-preview.0 <2.13.2
C
Prototype Pollution
CVE-2026-32621
Affects
@apollo/gateway
| Versions
<2.9.6
>=2.10.0-alpha.0 <2.10.5
>=2.11.0-preview.0 <2.11.6
>=2.12.0-preview.0 <2.12.3
>=2.13.0-preview.0 <2.13.2
C
Prototype Pollution
CVE-2026-32621
Affects
@apollo/query-planner
| Versions
<2.9.6
>=2.10.0-alpha.0 <2.10.5
>=2.11.0-preview.0 <2.11.6
>=2.12.0-preview.0 <2.12.3
>=2.13.0-preview.0 <2.13.2
C
Arbitrary Code Injection
CVE-2026-30741
Affects
openclaw
| Versions
>=0.0.0
C
Malicious Package
Affects
chai-as-constrained
| Versions
*
H
Directory Traversal
Affects
h3
| Versions
<1.15.6
>=2.0.0-beta.0 <2.0.1-rc.15
H
Always-Incorrect Control Flow Implementation
CVE-2026-33011
Affects
@nestjs/core
| Versions
<11.1.17
H
Prototype Pollution
CVE-2025-65587
Affects
graphql-upload-minimal
| Versions
<1.6.3
H
Allocation of Resources Without Limits or Throttling
CVE-2026-29112
Affects
@dicebear/converter
| Versions
<9.4.0
M
Authorization Bypass Through User-Controlled Key
CVE-2026-32638
Affects
@withstudiocms/effect
| Versions
<0.4.1
M
Authorization Bypass Through User-Controlled Key
CVE-2026-32638
Affects
@withstudiocms/api-spec
| Versions
<0.3.2
M
Authorization Bypass Through User-Controlled Key
CVE-2026-32638
Affects
effectify
| Versions
<0.2.0
M
Authorization Bypass Through User-Controlled Key
CVE-2026-32638
Affects
studiocms
| Versions
<0.4.4
H
Infinite loop
CVE-2026-32256
Affects
music-metadata
| Versions
<11.12.3
H
Allocation of Resources Without Limits or Throttling
CVE-2026-33151
Affects
socket.io-parser
| Versions
<3.3.5
>=3.4.0 <3.4.4
>=4.0.0 <4.2.6
M
Prototype Pollution
CVE-2026-31865
Affects
elysia
| Versions
<1.4.27
H
Command Injection
CVE-2026-22169
Affects
openclaw
| Versions
<2026.2.22
H
Improperly Controlled Sequential Memory Allocation
CVE-2026-32886
Affects
parse-server
| Versions
<8.6.47
>=9.0.0-alpha.1 <9.6.0-alpha.24
M
Weak Authentication
CVE-2026-33042
Affects
parse-server
| Versions
<8.6.49
>=9.0.0-alpha.1 <9.6.0-alpha.29
L
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-32943
Affects
parse-server
| Versions
<8.6.48
>=9.0.0-alpha.1 <9.6.0-alpha.28
M
Prototype Pollution
CVE-2026-32878
Affects
parse-server
| Versions
<8.6.44
>=9.0.0-alpha.1 <9.6.0-alpha.20
H
Improper Validation of Syntactic Correctness of Input
CVE-2026-32770
Affects
parse-server
| Versions
<8.6.43
>=9.0.0-alpha.1 <9.6.0-alpha.19
M
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-32742
Affects
parse-server
| Versions
<8.6.42
>=9.0.0-alpha.1 <9.6.0-alpha.17
H
Uncontrolled Recursion
CVE-2026-32944
Affects
parse-server
| Versions
<8.6.45
>=9.0.0-alpha.1 <9.6.0-alpha.21
C
Malicious Package
Affects
typescript-operations
| Versions
*