Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Improperly Controlled Sequential Memory Allocation
CVE-2026-32886
Affects
parse-server
| Versions
<8.6.47
>=9.0.0-alpha.1 <9.6.0-alpha.24
M
Weak Authentication
CVE-2026-33042
Affects
parse-server
| Versions
<8.6.49
>=9.0.0-alpha.1 <9.6.0-alpha.29
L
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-32943
Affects
parse-server
| Versions
<8.6.48
>=9.0.0-alpha.1 <9.6.0-alpha.28
M
Prototype Pollution
CVE-2026-32878
Affects
parse-server
| Versions
<8.6.44
>=9.0.0-alpha.1 <9.6.0-alpha.20
H
Improper Validation of Syntactic Correctness of Input
CVE-2026-32770
Affects
parse-server
| Versions
<8.6.43
>=9.0.0-alpha.1 <9.6.0-alpha.19
M
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-32742
Affects
parse-server
| Versions
<8.6.42
>=9.0.0-alpha.1 <9.6.0-alpha.17
H
Uncontrolled Recursion
CVE-2026-32944
Affects
parse-server
| Versions
<8.6.45
>=9.0.0-alpha.1 <9.6.0-alpha.21
C
Malicious Package
Affects
typescript-operations
| Versions
*
M
Cross-site Scripting (XSS)
CVE-2026-31938
Affects
jspdf
| Versions
<4.2.1
M
Improper Encoding or Escaping of Output
CVE-2026-31898
Affects
jspdf
| Versions
<4.2.1
H
XML Entity Expansion
CVE-2026-33036
Affects
fast-xml-parser
| Versions
>=4.0.0-beta.0 <5.5.6
L
Missing Origin Validation in WebSockets
CVE-2026-27977
Affects
next
| Versions
>=16.0.1 <16.1.7
>=16.2.0-canary.0 <16.2.0-canary.102
M
Allocation of Resources Without Limits or Throttling
CVE-2026-27979
Affects
next
| Versions
>=16.1.0 <16.1.7
>=16.2.0-canary.0 <16.2.0-canary.51
M
HTTP Request Smuggling
CVE-2026-29057
Affects
next
| Versions
>=9.5.0 <15.5.13
>=16.0.0-beta.0 <16.1.7
>=16.2.0-canary.0 <16.2.0-canary.102
M
Cross-site Request Forgery (CSRF)
CVE-2026-27978
Affects
next
| Versions
>=16.0.1 <16.1.7
>=16.2.0-canary.0 <16.2.0-canary.102
M
Allocation of Resources Without Limits or Throttling
CVE-2026-27980
Affects
next
| Versions
>=10.0.0 <16.1.7
>=16.2.0-canary.0 <16.2.0-canary.54
C
Command Injection
CVE-2026-32917
Affects
openclaw
| Versions
<2026.3.13-beta.1
M
Incorrect Permission Assignment for Critical Resource
CVE-2026-33572
Affects
openclaw
| Versions
<2026.2.17
H
Allocation of Resources Without Limits or Throttling
CVE-2026-32980
Affects
openclaw
| Versions
<2026.3.13-beta.1
H
Improper Privilege Management
CVE-2026-32987
Affects
openclaw
| Versions
<2026.3.13-beta.1
M
Insertion of Sensitive Information into Log File
CVE-2026-32982
Affects
openclaw
| Versions
<2026.3.13-beta.1
L
Race Condition
CVE-2026-32723
Affects
@nyariv/sandboxjs
| Versions
<0.8.35
H
Cross-site Scripting (XSS)
CVE-2026-32728
Affects
parse-server
| Versions
<8.6.41
>=9.0.0-alpha.1 <9.6.0-alpha.15
C
Malicious Package
Affects
@augmentor/experiences
| Versions
*
C
Malicious Package
Affects
pino-logger-utils
| Versions
*
C
Malicious Package
Affects
vitest-config
| Versions
*
C
Malicious Package
Affects
ember-power-calendar-utils
| Versions
*
C
Malicious Package
Affects
asset-delivery
| Versions
*
C
Malicious Package
Affects
strapi-plugin-workspace-plugin
| Versions
*
C
Malicious Package
Affects
graphlib-js
| Versions
*