Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
L
Cross-site Scripting (XSS)
Affects
justhtml
| Versions
[,1.14.0)
C
Improper Verification of Cryptographic Signature
CVE-2026-39413
Affects
lightrag-hku
| Versions
[,1.4.14)
H
Deserialization of Untrusted Data
Affects
monai
| Versions
[1.0.0,]
H
Use of Password Hash With Insufficient Computational Effort
Affects
litellm
| Versions
[,1.83.0)
M
Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-39373
Affects
jwcrypto
| Versions
[,1.5.7)
M
Cross-site Scripting (XSS)
CVE-2026-33865
Affects
mlflow
| Versions
[,3.11.0rc1)
M
Cross-site Scripting (XSS)
CVE-2026-33865
Affects
mlflow-skinny
| Versions
[,3.11.0rc1)
M
Missing Authorization
CVE-2026-33866
Affects
mlflow
| Versions
[,3.11.0rc1)
M
Missing Authorization
CVE-2026-33866
Affects
mlflow-skinny
| Versions
[,3.11.0rc1)
L
User Impersonation
CVE-2026-3902
Affects
django
| Versions
[4.2a1,4.2.30)
[5.0a1,5.2.13)
[6.0a1,6.0.4)
M
Missing Authorization
CVE-2026-4277
Affects
django
| Versions
[4.2a1,4.2.30)
[5.0a1,5.2.13)
[6.0a1,6.0.4)
M
Inefficient Algorithmic Complexity
CVE-2026-33033
Affects
django
| Versions
[4.2a1,4.2.30)
[5.0a1,5.2.13)
[6.0a1,6.0.4)
M
Allocation of Resources Without Limits or Throttling
CVE-2026-33034
Affects
django
| Versions
[4.2a1,4.2.30)
[5.0a1,5.2.13)
[6.0a1,6.0.4)
M
Missing Authorization
CVE-2026-4292
Affects
django
| Versions
[4.2a1,4.2.30)
[5.0a1,5.2.13)
[6.0a1,6.0.4)
H
Integer Overflow or Wraparound
CVE-2026-3308
Affects
pymupdf
| Versions
[0,]
H
Improper Authentication
CVE-2026-34531
Affects
flask-httpauth
| Versions
[,4.8.1)
C
Server-side Request Forgery (SSRF)
CVE-2026-2286
Affects
crewai
| Versions
[,1.14.0)
C
Server-side Request Forgery (SSRF)
CVE-2026-2286
Affects
crewai-tools
| Versions
[,1.14.0)
C
Arbitrary Code Injection
CVE-2026-2287
Affects
crewai-tools
| Versions
[,1.14.0a4)
H
Exposed Dangerous Method or Function
CVE-2026-2275
Affects
crewai-tools
| Versions
[,1.14.0a4)
H
Directory Traversal
CVE-2026-2285
Affects
crewai-tools
| Versions
[0, 1.12.0a1)
M
Missing Authorization
CVE-2026-34222
Affects
open-webui
| Versions
[,0.8.11)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-35526
Affects
strawberry-graphql
| Versions
[,0.312.3)
H
Missing Authentication for Critical Function
CVE-2026-35523
Affects
strawberry-graphql
| Versions
[,0.312.3)
C
Missing Authentication for Critical Function
CVE-2026-0545
Affects
mlflow-skinny
| Versions
[0,]
C
Missing Authentication for Critical Function
CVE-2026-0545
Affects
mlflow
| Versions
[0,]
C
Command Injection
CVE-2026-0596
Affects
mlflow-skinny
| Versions
[,3.9.0rc0)
C
Command Injection
CVE-2026-0596
Affects
mlflow
| Versions
[,3.9.0rc0)
M
Server-side Request Forgery (SSRF)
CVE-2026-34881
Affects
glance
| Versions
[,29.2.0)
[30.0.0,30.2.0)
[31.0.0,31.1.0)
H
Out-of-bounds Read
CVE-2026-34824
Affects
mesop
| Versions
[1.2.3,1.2.5)