Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Missing Authorization
CVE-2026-27457
Affects
weblate
| Versions
[,5.16.1)
M
Incomplete List of Disallowed Inputs
Affects
fickling
| Versions
[,0.1.8)
M
SQL Injection
CVE-2026-23980
Affects
apache-superset
| Versions
[,6.0.0)
H
Incorrect Authorization
CVE-2026-23982
Affects
apache-superset
| Versions
[,6.0.0)
H
Incorrect Authorization
CVE-2026-23984
Affects
apache-superset
| Versions
[,6.0.0)
M
SQL Injection
CVE-2026-23969
Affects
apache-superset
| Versions
[,4.1.2)
H
Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-27809
Affects
psd-tools
| Versions
[,1.12.2)
C
Arbitrary Code Injection
CVE-2026-27966
Affects
lfx
| Versions
[0,]
H
Deserialization of Untrusted Data
CVE-2026-27794
Affects
langgraph-checkpoint
| Versions
[,4.0.0)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-27888
Affects
pypdf
| Versions
[,6.7.3)
C
Malicious Package
Affects
polyutil
| Versions
[0,]
C
Malicious Package
Affects
polyclawd
| Versions
[0,]
C
Malicious Package
Affects
clawdist
| Versions
[0,]
C
Malicious Package
Affects
clawdest
| Versions
[0,]
C
Malicious Package
Affects
magicwolf
| Versions
[0,]
C
Malicious Package
Affects
magichat
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2026-27156
Affects
nicegui
| Versions
[,3.8.0)
M
Cross-site Scripting (XSS)
CVE-2026-27614
Affects
bugsink
| Versions
[,2.0.13)
C
Interpretation Conflict
Affects
fickling
| Versions
[,0.1.8)
M
Infinite loop
CVE-2026-27628
Affects
pypdf
| Versions
[,6.7.2)
H
Template Injection
CVE-2024-56373
Affects
apache-airflow
| Versions
[,2.11.1rc2)
M
Insertion of Sensitive Information Into Sent Data
CVE-2025-27555
Affects
apache-airflow
| Versions
[,2.11.1rc1)
C
Generation of Predictable Numbers or Identifiers
CVE-2026-2473
Affects
google-cloud-aiplatform
| Versions
[1.21.0,1.133.0)
H
Signed to Unsigned Conversion Error
CVE-2026-26981
Affects
openexr
| Versions
[3.3.0,3.3.7)
[3.4.0,3.4.5)
H
Cross-site Scripting (XSS)
CVE-2026-2472
Affects
google-cloud-aiplatform
| Versions
[1.98.0,1.131.0)
C
SQL Injection
CVE-2026-26198
Affects
ormar
| Versions
[0.9.9, 0.23.0)
H
Command Injection
CVE-2026-26331
Affects
yt-dlp
| Versions
[2023.6.21,2026.2.21)
H
External Control of File Name or Path
CVE-2026-26975
Affects
music-assistant
| Versions
[0,]
M
Directory Traversal
CVE-2026-25527
Affects
changedetection.io
| Versions
[,0.53.2)
H
Arbitrary Code Injection
CVE-2025-33240
Affects
megatron-bridge
| Versions
[,0.3.0)