Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Server-side Request Forgery (SSRF)
CVE-2026-87999
Affects
open-webui
| Versions
[,0.11.1)
H
Infinite loop
CVE-2026-88000
Affects
open-webui
| Versions
[0.10.0,0.11.1)
M
Server-side Request Forgery (SSRF)
CVE-2026-88001
Affects
open-webui
| Versions
[0.9.5,0.11.1)
H
Infinite loop
CVE-2026-88002
Affects
open-webui
| Versions
[0.5.0,0.11.1)
M
Incorrect Authorization
CVE-2026-88005
Affects
open-webui
| Versions
[0.8.0,0.9.0)
M
Incorrect Authorization
CVE-2026-88006
Affects
open-webui
| Versions
[0.8.0,0.11.1)
C
Malicious Package
Affects
metrics-sdk
| Versions
[1001.0.0]
[1000.0.0]
[999.0.0]
C
Malicious Package
Affects
claudedashbord
| Versions
[0.1.3]
[0.1.2]
[0.1.1]
[0.1.0]
C
Malicious Package
Affects
metrio
| Versions
[1001.0.0]
[1000.0.0]
[999.0.0]
C
Malicious Package
Affects
donutpromotion
| Versions
[0.1.0]
C
Malicious Package
Affects
donutautosellsrc
| Versions
[0.3.9]
[0.3.8]
[0.3.7]
C
Malicious Package
Affects
requests-cache-utils
| Versions
[1.0.0]
H
Incorrect Authorization
CVE-2026-89032
Affects
litellm
| Versions
[,1.101.0rc1)
M
Not Failing Securely ('Failing Open')
CVE-2026-97636
Affects
apache-airflow-providers-hashicorp
| Versions
[4.6.0,4.8.0)
M
Brute Force
CVE-2026-97764
Affects
django-allauth
| Versions
[0.25.0,65.19.4)
H
Improper Validation of Integrity Check Value
CVE-2026-57175
Affects
social-auth-core
| Versions
[,5.0.0)
H
Authentication Bypass by Alternate Name
CVE-2026-57176
Affects
social-auth-core
| Versions
[,5.0.0)
M
Cross-site Request Forgery (CSRF)
CVE-2026-57177
Affects
social-auth-core
| Versions
[,5.0.0)
C
Improper Verification of Cryptographic Signature
CVE-2026-57178
Affects
social-auth-core
| Versions
[,5.0.0)
L
Session Fixation
CVE-2026-57179
Affects
social-auth-core
| Versions
[,5.0.0)
M
Allocation of Resources Without Limits or Throttling
CVE-2026-100647
Affects
vllm
| Versions
[,0.29.0)
M
Allocation of Resources Without Limits or Throttling
CVE-2026-100648
Affects
vllm
| Versions
[,0.29.0)
M
Allocation of Resources Without Limits or Throttling
CVE-2026-100649
Affects
vllm
| Versions
[,0.29.0)
H
Improper Validation of Specified Quantity in Input
CVE-2026-100650
Affects
vllm
| Versions
[,0.29.0)
H
Improper Check for Unusual or Exceptional Conditions
CVE-2026-100651
Affects
vllm
| Versions
[,0.29.0)
H
Improper Validation of Array Index
CVE-2026-100652
Affects
vllm
| Versions
[0.22.0,0.24.0)
H
Use of Less Trusted Source
CVE-2026-100653
Affects
vllm
| Versions
[0.22.1,0.28.0)
H
Improper Validation of Array Index
CVE-2026-100654
Affects
vllm
| Versions
[,0.29.0)
C
Malicious Package
Affects
sherpy
| Versions
[0.1.1]
[0.1.0]
C
Malicious Package
Affects
tego-managed-agents-test
| Versions
[0.1.0]