Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Insecure Temporary File
CVE-2026-25645
Affects
requests
| Versions
[,2.33.0)
M
Improper Protection of Alternate Path
CVE-2026-4270
Affects
awslabs.aws-api-mcp-server
| Versions
[0.2.14,1.3.9)
H
Missing Authorization
CVE-2026-33125
Affects
frigate
| Versions
[0,]
C
Unsafe Dependency Resolution
CVE-2026-0848
Affects
nltk
| Versions
[,3.9.3)
C
Arbitrary Command Injection
CVE-2025-69902
Affects
kubectl-mcp-tool
| Versions
[,1.2.0)
C
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-33475
Affects
langflow
| Versions
[0,]
C
Embedded Malicious Code
Affects
litellm
| Versions
[1.82.7]
[1.82.8]
H
Allocation of Resources Without Limits or Throttling
CVE-2026-26209
Affects
cbor2
| Versions
[,5.9.0)
L
Cross-site Scripting (XSS)
Affects
justhtml
| Versions
[,1.12.0)
M
Cross-site Scripting (XSS)
Affects
justhtml
| Versions
[,1.12.0)
H
Uncontrolled Recursion
Affects
justhtml
| Versions
[,1.10.0)
H
Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-33154
Affects
dynaconf
| Versions
[,3.2.13)
M
Origin Validation Error
CVE-2026-33314
Affects
pyload-ng
| Versions
[0,]
H
Improper Privilege Management
CVE-2026-33509
Affects
pyload-ng
| Versions
[0,]
H
Directory Traversal
CVE-2026-32711
Affects
pydicom
| Versions
[,2.4.5)
[3.0.0rc1, 3.0.2)
M
SQL Injection
CVE-2026-4513
Affects
vanna
| Versions
[0,]
M
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-4511
Affects
vanna
| Versions
[0,]
M
Deserialization of Untrusted Data
CVE-2026-4538
Affects
torch
| Versions
[0,]
M
Regular Expression Denial of Service (ReDoS)
CVE-2026-4539
Affects
pygments
| Versions
[,2.20.0)
M
Generation of Predictable Numbers or Identifiers
CVE-2026-4269
Affects
bedrock-agentcore-starter-toolkit
| Versions
[,0.1.13)
C
Directory Traversal
CVE-2026-33497
Affects
langflow-base
| Versions
[0,]
H
Missing Authorization
CVE-2026-33484
Affects
langflow-base
| Versions
[0,]
H
Directory Traversal
CVE-2026-33054
Affects
mesop
| Versions
[,1.2.3)
H
Directory Traversal
CVE-2026-3029
Affects
pymupdf
| Versions
[,1.26.7)
M
External Control of File Name or Path
CVE-2026-33309
Affects
langflow-base
| Versions
[0.2.0,0.8.0rc0)
M
Authorization Bypass Through User-Controlled Key
CVE-2026-33053
Affects
langflow-base
| Versions
[0.1.0,0.8.0rc0)
M
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-27953
Affects
ormar
| Versions
[,0.23.1)
M
Improper Validation of Specified Quantity in Input
CVE-2026-33332
Affects
nicegui
| Versions
[,3.9.0)
H
Directory Traversal
CVE-2025-15031
Affects
mlflow
| Versions
[,3.9.0rc0)
M
Uncontrolled Recursion
Affects
nltk
| Versions
[0,3.9.4)