Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Server-side Request Forgery (SSRF)
Affects
cowrie
| Versions
[,2.9.0)
M
Cross-site Request Forgery (CSRF)
Affects
fastapi-users
| Versions
[,15.0.2)
M
Arbitrary File Upload
Affects
weblate
| Versions
[,5.15.1)
M
Directory Traversal
Affects
weblate
| Versions
[,5.15.1)
L
XML External Entity (XXE) Injection
Affects
biopython
| Versions
[0,]
M
Arbitrary Argument Injection
Affects
mcp-server-git
| Versions
[,2025.12.18)
M
Directory Traversal
Affects
mcp-server-git
| Versions
[,2025.11.25)
H
Missing Authentication for Critical Function
Affects
open-webui
| Versions
[0,]
H
Out-of-bounds Read
Affects
torch
| Versions
[,2.2.0)
M
Directory Traversal
Affects
mcp-server-git
| Versions
[,2025.9.25)
H
Uncontrolled Search Path Element
Affects
nbconvert
| Versions
[0,]
M
Cross-site Request Forgery (CSRF)
Affects
fastapi-sso
| Versions
[,0.19.0)
H
Incorrect Resource Transfer Between Spheres
Affects
apache-airflow-providers-edge3
| Versions
[,2.0.0rc1)
C
Deserialization of Untrusted Data
Affects
isaaclab
| Versions
[,2.3.0)
H
Insertion of Sensitive Information Into Sent Data
Affects
apache-airflow-task-sdk
| Versions
[1.0.0a2,1.1.4rc1)
M
Cross-site Scripting (XSS)
Affects
mayan-edms
| Versions
[,4.6.12)
[4.7, 4.7.8)
[4.8, 4.8.10)
[4.9, 4.9.7)
[4.10, 4.10.2)
H
UNIX Symbolic Link (Symlink) Following
Affects
nvidia-resiliency-ext
| Versions
[,0.5.0)
H
Race Condition
Affects
nvidia-resiliency-ext
| Versions
[,0.4.1)
M
Improper Verification of Cryptographic Signature
Affects
altcha
| Versions
[,1.0.0)
M
Time-of-check Time-of-use (TOCTOU) Race Condition
Affects
filelock
| Versions
[,3.20.1)
H
Deserialization of Untrusted Data
Affects
fickling
| Versions
[,0.1.6)
H
Deserialization of Untrusted Data
Affects
fickling
| Versions
[,0.1.6)
M
Improper Validation of Syntactic Correctness of Input
Affects
weblate
| Versions
[,5.15)
L
Incorrect User Management
Affects
weblate
| Versions
[,5.15)
M
Improper Authorization
Affects
weblate
| Versions
[,5.15)
M
Open Redirect
Affects
mayan-edms
| Versions
[,4.6.12)
[4.7,4.7.8)
[4.8,4.8.10)
[4.9,4.9.7)
[4.10,4.10.2)
M
Regular Expression Denial of Service (ReDoS)
Affects
pymdown-extensions
| Versions
[,10.16.1)
H
Improper Certificate Validation
Affects
django-allauth
| Versions
[,65.13.0)
M
Insufficient Session Expiration
Affects
django-allauth
| Versions
[,65.13.0)
H
Arbitrary Code Injection
Affects
ultralytics
| Versions
[,8.3.226)