Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Allocation of Resources Without Limits or Throttling
CVE-2026-45554
Affects
nicegui
| Versions
[,3.12.0)
H
External Control of File Name or Path
CVE-2026-45553
Affects
nicegui
| Versions
[,3.12.0)
H
Creation of Temporary File With Insecure Permissions
CVE-2026-4137
Affects
mlflow
| Versions
[,3.11.0rc1)
H
Creation of Temporary File With Insecure Permissions
CVE-2026-4137
Affects
mlflow-skinny
| Versions
[,3.11.0rc1)
H
Creation of Temporary File With Insecure Permissions
CVE-2025-10279
Affects
mlflow-skinny
| Versions
[,3.4.0rc0)
H
Deserialization of Untrusted Data
CVE-2021-47952
Affects
jsonpickle
| Versions
[,4.0.2)
H
Authorization Bypass Through User-Controlled Key
CVE-2026-45402
Affects
open-webui
| Versions
[,0.9.5)
M
Insertion of Sensitive Information Into Sent Data
CVE-2026-45387
Affects
open-webui
| Versions
[0.7.0,0.9.5)
M
Server-side Request Forgery (SSRF)
CVE-2026-45400
Affects
open-webui
| Versions
[0.3.31 ,0.9.5)
M
Cross-site Request Forgery (CSRF)
CVE-2026-45317
Affects
open-webui
| Versions
[,0.9.3)
M
Authorization Bypass Through User-Controlled Key
CVE-2026-45385
Affects
open-webui
| Versions
[0.5.0,0.9.5)
M
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-45396
Affects
open-webui
| Versions
[0.3.33,0.9.5)
M
Server-side Request Forgery (SSRF)
CVE-2026-45338
Affects
open-webui
| Versions
[0.6.8,0.9.0)
M
Server-side Request Forgery (SSRF)
CVE-2026-45401
Affects
open-webui
| Versions
[,0.9.5)
M
Server-side Request Forgery (SSRF)
CVE-2026-45331
Affects
open-webui
| Versions
[0.3.31, 0.9.0)
M
Cross-site Scripting (XSS)
CVE-2026-45346
Affects
open-webui
| Versions
[0.3.31,0.6.31)
H
Incorrect Authorization
CVE-2026-45395
Affects
open-webui
| Versions
[0.3.6,0.9.5)
M
Improper Validation of Specified Quantity in Input
Affects
oxidize-pdf
| Versions
[,0.5.0)
H
Directory Traversal
CVE-2026-45017
Affects
python-liquid
| Versions
[,2.2.0)
M
Improper Encoding or Escaping of Output
CVE-2026-44972
Affects
guarddog
| Versions
[2.6.0,)
H
Incorrect Authorization
CVE-2026-45339
Affects
open-webui
| Versions
[,0.9.0)
L
Insertion of Sensitive Information Into Sent Data
CVE-2026-44970
Affects
dbt-mcp
| Versions
[,1.17.1)
L
Insertion of Sensitive Information into Log File
CVE-2026-44969
Affects
dbt-mcp
| Versions
[,1.17.1)
H
Arbitrary Argument Injection
CVE-2026-44968
Affects
dbt-mcp
| Versions
[,1.17.1)
H
Cross-site Scripting (XSS)
CVE-2026-44541
Affects
ethyca-fides
| Versions
[2.33.0,2.84.5rc0)
H
Improper Privilege Management
CVE-2026-43978
Affects
wger
| Versions
[0,]
H
Access Control Bypass
CVE-2026-43977
Affects
wger
| Versions
[0,]
H
Asymmetric Resource Consumption (Amplification)
CVE-2026-45078
Affects
matrix-synapse
| Versions
[,1.152.1)
M
Improper Check for Unusual or Exceptional Conditions
CVE-2026-45076
Affects
matrix-synapse
| Versions
[,1.152.1)
H
External Control of File Name or Path
CVE-2026-44353
Affects
streamlink
| Versions
[,8.4.0)