Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Denial of Service (DoS)
CVE-2026-34829
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
M
Incorrect Behavior Order: Validate Before Canonicalize
CVE-2026-34786
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
M
Permissive Regular Expression
CVE-2026-34763
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
M
Denial of Service (DoS)
CVE-2026-34826
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
H
Permissive Regular Expression
CVE-2026-34830
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
M
Denial of Service (DoS)
CVE-2026-34230
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
H
Partial String Comparison
CVE-2026-34785
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
M
Improper Handling of Length Parameter Inconsistency
CVE-2026-34831
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
M
CRLF Injection
CVE-2026-26962
Affects
rack
| Versions
>=3.2.0, <3.2.6
M
Interpretation Conflict
CVE-2026-32762
Affects
rack
| Versions
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
M
Improper Validation of Syntactic Correctness of Input
CVE-2026-34835
Affects
rack
| Versions
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
H
Inefficient Algorithmic Complexity
CVE-2026-34827
Affects
rack
| Versions
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
M
Interpretation Conflict
CVE-2026-26961
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
H
Arbitrary Code Injection
CVE-2026-4800
Affects
lodash-rails
| Versions
>=0.7.0
M
Cross-site Scripting (XSS)
Affects
action_text-trix
| Versions
<2.1.18
H
Arbitrary Code Injection
CVE-2026-34060
Affects
ruby-lsp
| Versions
<0.26.9
H
Improper Control of Dynamically-Managed Code Resources
CVE-2026-33286
Affects
graphiti
| Versions
<1.10.2
H
Session Fixation
CVE-2026-33946
Affects
mcp
| Versions
<0.9.2
L
Allocation of Resources Without Limits or Throttling
CVE-2026-33658
Affects
activestorage
| Versions
<7.2.3.1
>=8.0.0, <8.0.4.1
>=8.1.0, <8.1.2.1
M
SQL Injection
CVE-2026-4324
Affects
katello
| Versions
<4.19.1
M
CRLF Injection
CVE-2026-33635
Affects
icalendar
| Versions
>=2.0.0, <2.12.2
M
Cross-site Scripting (XSS)
CVE-2026-33167
Affects
actionpack
| Versions
>=8.1.0.beta1, <8.1.2.1
L
Cross-site Scripting (XSS)
CVE-2026-33168
Affects
actionview
| Versions
<7.2.3.1
>=8.0.0.beta1, <8.0.4.1
>=8.1.0.beta1, <8.1.2.1
M
Cross-site Scripting (XSS)
CVE-2026-33170
Affects
activesupport
| Versions
<7.2.3.1
>=8.0.0.beta1, <8.0.4.1
>=8.1.0.beta1, <8.1.2.1
H
Memory Allocation with Excessive Size Value
CVE-2026-33174
Affects
activestorage
| Versions
<7.2.3.1
>=8.0.0.beta1, <8.0.4.1
>=8.1.0.beta1, <8.1.2.1
H
Allocation of Resources Without Limits or Throttling
CVE-2026-33176
Affects
activesupport
| Versions
<7.2.3.1
>=8.0.0.beta1, <8.0.4.1
>=8.1.0.beta1, <8.1.2.1
M
Regular Expression Denial of Service (ReDoS)
CVE-2026-33169
Affects
activesupport
| Versions
<7.2.3.1
>=8.0.0.beta1, <8.0.4.1
>=8.1.0.beta1, <8.1.2.1
M
Improper Handling of Values
CVE-2026-33173
Affects
activestorage
| Versions
<7.2.3.1
>=8.0.0.beta1, <8.0.4.1
>=8.1.0.beta1, <8.1.2.1
C
Directory Traversal
CVE-2026-33195
Affects
activestorage
| Versions
<7.2.3.1
>=8.0.0.beta1, <8.0.4.1
>=8.1.0.beta1, <8.1.2.1
M
Glob Injection
CVE-2026-33202
Affects
activestorage
| Versions
<7.2.3.1
>=8.0.0.beta1, <8.0.4.1
>=8.1.0.beta1, <8.1.2.1