Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Allocation of Resources Without Limits or Throttling
CVE-2026-22815
Affects
aiohttp
| Versions
[,3.13.4)
H
Server-side Request Forgery (SSRF)
CVE-2026-34515
Affects
aiohttp
| Versions
[,3.13.4)
M
Allocation of Resources Without Limits or Throttling
CVE-2026-34513
Affects
aiohttp
| Versions
[,3.13.4)
M
HTTP Response Splitting
CVE-2026-34514
Affects
aiohttp
| Versions
[,3.13.4)
M
Information Exposure
CVE-2026-34518
Affects
aiohttp
| Versions
[,3.13.4)
M
Allocation of Resources Without Limits or Throttling
CVE-2026-34517
Affects
aiohttp
| Versions
[,3.13.4)
M
HTTP Request Smuggling
CVE-2026-34525
Affects
aiohttp
| Versions
[,3.13.4)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-34516
Affects
aiohttp
| Versions
[,3.13.4)
M
HTTP Response Splitting
CVE-2026-34519
Affects
aiohttp
| Versions
[,3.13.4)
M
HTTP Response Splitting
CVE-2026-34520
Affects
aiohttp
| Versions
[,3.13.4)
M
Authorization Bypass Through User-Controlled Key
CVE-2026-33511
Affects
pyload-ng
| Versions
[0,]
H
Deserialization of Untrusted Data
CVE-2026-24152
Affects
megatron-core
| Versions
[,0.15.3)
H
Deserialization of Untrusted Data
CVE-2026-24151
Affects
megatron-core
| Versions
[,0.15.3)
H
Deserialization of Untrusted Data
CVE-2026-24150
Affects
megatron-core
| Versions
[,0.15.3)
H
Deserialization of Untrusted Data
CVE-2025-33248
Affects
megatron-core
| Versions
[,0.15.3)
H
Deserialization of Untrusted Data
CVE-2025-33247
Affects
megatron-core
| Versions
[,0.15.3)
H
Unintended Proxy or Intermediary ('Confused Deputy')
CVE-2026-27124
Affects
fastmcp
| Versions
[,3.2.0)
M
Command Injection
CVE-2025-64340
Affects
fastmcp
| Versions
[,3.2.0)
H
Command Injection
CVE-2026-33046
Affects
indico
| Versions
[,3.3.12)
C
Server-side Request Forgery (SSRF)
CVE-2026-32871
Affects
fastmcp
| Versions
[,3.2.0)
H
SQL Injection
CVE-2026-34400
Affects
alerta-server
| Versions
[6.3.0,9.1.0)
M
Weak Password Requirements
CVE-2026-34203
Affects
nautobot
| Versions
[,2.4.30)
[3.0.0a2,3.0.10)
M
Missing Authentication for Critical Function
Affects
litellm
| Versions
[,1.82.4)
H
Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2025-15381
Affects
mlflow-skinny
| Versions
[,3.11.0rc0)
H
Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2025-15381
Affects
mlflow
| Versions
[,3.11.0rc0)
H
Directory Traversal
CVE-2026-35167
Affects
kedro
| Versions
[,1.3.0)
H
UNIX Symbolic Link (Symlink) Following
CVE-2026-27489
Affects
onnx
| Versions
[,1.21.0)
H
Directory Traversal
Affects
onnxruntime
| Versions
[,1.24.1)
H
Arbitrary Code Execution
Affects
fonttools
| Versions
[,4.62.0)
C
Arbitrary Command Injection
CVE-2025-15379
Affects
mlflow-skinny
| Versions
[2.11.0,3.8.1)