Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Cross-site Scripting (XSS)
CVE-2026-59214
Affects
open-webui
| Versions
[,0.10.0)
M
Protection Mechanism Failure
CVE-2026-59223
Affects
open-webui
| Versions
[,0.10.0)
M
Incorrect Authorization
CVE-2026-59227
Affects
open-webui
| Versions
[0.8.11,0.10.0)
M
Incorrect Authorization
CVE-2026-59212
Affects
open-webui
| Versions
[0.9.6,0.10.0)
M
Timing Attack
CVE-2026-59218
Affects
open-webui
| Versions
[,0.10.0)
L
Missing Authentication for Critical Function
CVE-2026-59715
Affects
open-webui
| Versions
[0.6.16,0.10.0)
H
Insufficient Session Expiration
CVE-2026-59219
Affects
open-webui
| Versions
[0.9.0,0.10.0)
M
Information Exposure
CVE-2026-59222
Affects
open-webui
| Versions
[0.7.0,0.10.0)
L
Authorization Bypass Through User-Controlled Key
CVE-2026-59215
Affects
open-webui
| Versions
[,0.10.0)
H
Missing Authorization
CVE-2026-59216
Affects
open-webui
| Versions
[,0.10.0)
M
Incorrect Authorization
CVE-2026-59217
Affects
open-webui
| Versions
[,0.10.0)
L
Use of Cache Containing Sensitive Information
CVE-2026-59213
Affects
open-webui
| Versions
[0.6.27,0.10.0)
H
Information Exposure
CVE-2026-73622
Affects
gitpython
| Versions
[,3.1.55)
H
Arbitrary Argument Injection
CVE-2026-73624
Affects
gitpython
| Versions
[,3.1.54)
H
Incomplete List of Disallowed Inputs
CVE-2026-73623
Affects
gitpython
| Versions
[,3.1.54)
H
Arbitrary Argument Injection
CVE-2026-73625
Affects
gitpython
| Versions
[,3.1.54)
C
Server-side Request Forgery (SSRF)
CVE-2026-63764
Affects
lmdeploy
| Versions
[,0.15.0)
M
Access of Resource Using Incompatible Type ('Type Confusion')
CVE-2026-64608
Affects
fory-compiler
| Versions
[0.15.0,1.4.0)
H
Arbitrary Argument Injection
CVE-2026-16493
Affects
ansible-core
| Versions
[,2.17.6rc1)
H
Improper Encoding or Escaping of Output
CVE-2026-73417
Affects
jupyterlab
| Versions
[3.3.0, 4.5.10)
[4.6.0a0, 4.6.2)
M
Incorrect Behavior Order: Validate Before Canonicalize
CVE-2026-73416
Affects
jupyterlab
| Versions
[,4.5.10)
[4.6.0a0, 4.6.2)
L
Not Failing Securely ('Failing Open')
CVE-2026-73626
Affects
jupyterlab
| Versions
[,4.5.10)
[4.6.0a0, 4.6.2)
H
Cross-site Scripting (XSS)
Affects
jupyterlab
| Versions
[,4.5.10)
[4.6.0a0, 4.6.2)
M
Incorrect Authorization
CVE-2026-73627
Affects
jupyterlab
| Versions
[,4.5.10)
[4.6.0a0, 4.6.2)
H
Arbitrary Argument Injection
CVE-2026-67323
Affects
gitpython
| Versions
[,3.1.51)
H
Command Injection
CVE-2026-67324
Affects
gitpython
| Versions
[3.1.50,3.1.51)
H
Incomplete List of Disallowed Inputs
CVE-2026-67325
Affects
gitpython
| Versions
[,3.1.51)
H
Insertion of Sensitive Information Into Sent Data
CVE-2026-67322
Affects
gitpython
| Versions
[,3.1.52)
C
Malicious Package
Affects
3web
| Versions
[1.0.0]
C
Malicious Package
Affects
afritonpy
| Versions
[1]