Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Improper Restriction of Rendered UI Layers or Frames
CVE-2026-70486
Affects
open-webui
| Versions
[0.9.0,0.11.0)
H
Information Exposure
CVE-2026-70491
Affects
open-webui
| Versions
[,0.11.0)
H
Cross-site Scripting (XSS)
CVE-2026-70492
Affects
open-webui
| Versions
[0.10.0,0.11.0)
M
Missing Authorization
CVE-2026-70487
Affects
open-webui
| Versions
[0.8.8,0.11.0)
M
Server-side Request Forgery (SSRF)
CVE-2026-54020
Affects
open-webui
| Versions
[,0.11.0)
H
Regular Expression Denial of Service (ReDoS)
CVE-2026-70489
Affects
open-webui
| Versions
[0.9.0,0.11.0)
H
Regular Expression Denial of Service (ReDoS)
CVE-2026-70493
Affects
open-webui
| Versions
[0.9.6,0.11.0)
M
Incorrect Authorization
CVE-2026-70490
Affects
open-webui
| Versions
[0.8.8,0.11.0)
H
Incorrect Authorization
CVE-2026-70494
Affects
open-webui
| Versions
[0.10.0,0.11.0)
M
Incorrect Authorization
CVE-2026-70488
Affects
open-webui
| Versions
[0.9.6,0.11.0)
H
Insufficient Verification of Data Authenticity
CVE-2026-67618
Affects
marimo
| Versions
[,0.23.15)
M
HTTP Request Smuggling
CVE-2026-71554
Affects
h2
| Versions
[,4.4.1)
M
Memory Allocation with Excessive Size Value
CVE-2026-71870
Affects
pypdf
| Versions
[,6.15.0)
M
Excessive Iteration
CVE-2026-71852
Affects
pypdf
| Versions
[,6.15.0)
M
Logging of Excessive Data
CVE-2026-54338
Affects
jupyterhub
| Versions
[,5.5.0)
H
Authorization Bypass Through User-Controlled Key
CVE-2026-19111
Affects
strands-agents-tools
| Versions
[,0.8.3)
M
Incorrect Authorization
CVE-2026-71433
Affects
langgraph-checkpoint-postgres
| Versions
[,3.1.1)
M
Incorrect Authorization
CVE-2026-71433
Affects
langgraph-checkpoint-sqlite
| Versions
[,3.1.1)
H
Regular Expression Denial of Service (ReDoS)
CVE-2026-67422
Affects
pymdown-extensions
| Versions
[,11.0.1)
H
Deserialization of Untrusted Data
CVE-2026-12484
Affects
keras
| Versions
[,3.12.3)
[3.13.0,3.15.0)
M
Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-12261
Affects
nltk
| Versions
[0,]
H
Arbitrary Argument Injection
Affects
gitpython
| Versions
[,3.1.58)
H
Arbitrary Code Injection
Affects
gitpython
| Versions
[,3.1.58)
H
External Control of File Name or Path
Affects
gitpython
| Versions
[,3.1.58)
H
External Control of File Name or Path
Affects
gitpython
| Versions
[,3.1.58)
H
Arbitrary Argument Injection
Affects
gitpython
| Versions
[,3.1.58)
H
Arbitrary Argument Injection
Affects
gitpython
| Versions
[,3.1.58)
C
Malicious Package
Affects
decapod-common
| Versions
[1.2.dev2]
[1.2.dev1]
[0.0.0]
C
Malicious Package
Affects
uncrypt
| Versions
[0.1.2]
[0.1.1]
[0.1.0]
C
Malicious Package
Affects
solana-sniper-bot
| Versions
[1.4.2]