Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Unprotected Transport of Credentials
CVE-2026-54603
Affects
oauth2
| Versions
>=0.4.0, <2.0.22
H
User Impersonation
CVE-2026-47737
Affects
puma
| Versions
>=5.5.0, <7.2.1
>=8.0.0, <8.0.2
H
Allocation of Resources Without Limits or Throttling
CVE-2026-47736
Affects
puma
| Versions
>=5.5.0, <7.2.1
>=8.0.0, <8.0.2
M
CSV Injection
Affects
spree_core
| Versions
>=5.2.0, <5.2.8
>=5.3.0, <5.3.6
>=5.4.0, <5.4.3
H
User Impersonation
CVE-2026-44476
Affects
doorkeeper-openid_connect
| Versions
<1.10.0
M
Improper Encoding or Escaping of Output
CVE-2026-44587
Affects
carrierwave
| Versions
<2.2.7
>=3.0.0.beta, <3.1.3
H
Improper Authentication
CVE-2026-45363
Affects
jwt
| Versions
<3.2.0
M
Server-side Request Forgery (SSRF)
CVE-2026-33637
Affects
faraday
| Versions
>=2.0.0.alpha-1, <2.14.2
C
Malicious Package
Affects
knot-simple-formatter
| Versions
>=0.0.0
C
Malicious Package
Affects
knot-rails-assets-pipeline
| Versions
>=0.0.0
C
Malicious Package
Affects
knot-date-utils-rb
| Versions
>=0.0.0
C
Malicious Package
Affects
knot-rspec-formatter-json
| Versions
>=0.0.0
C
Malicious Package
Affects
knot-rack-session-store
| Versions
>=0.0.0
C
Malicious Package
Affects
knot-devise-jwt-helper
| Versions
>=0.0.0
C
Malicious Package
Affects
knot-activesupport-logger
| Versions
>=0.0.0
C
Protection Mechanism Failure
CVE-2026-41316
Affects
erb
| Versions
<4.0.3.1
>=4.0.0, <4.0.4
>=5.0.0, <6.0.1.1
>=6.0.2, <6.0.4
M
Unsafe Dependency Resolution
CVE-2026-44312
Affects
css_parser
| Versions
<1.22.0
>=2.0.0, <2.1.0
M
Cross-site Scripting (XSS)
CVE-2025-67202
Affects
sidekiq-cron
| Versions
<2.4.0
C
Insufficient Session Expiration
CVE-2026-44511
Affects
katalyst-koi
| Versions
<4.20.0
>=5.0.0.alpha.1, <5.6.0
H
Insecure Inherited Permissions
CVE-2026-44836
Affects
view_component
| Versions
>=3.0.0, <3.25.0
>=4.0.0.alpha1, <4.9.0
M
Directory Traversal
CVE-2026-44837
Affects
view_component
| Versions
>=3.0.0, <3.25.0
>=4.0.0.alpha1, <4.9.0
M
Open Redirect
CVE-2026-40295
Affects
devise
| Versions
<5.0.4
H
Missing Release of Memory after Effective Lifetime
Affects
nokogiri
| Versions
<1.19.3
M
Regular Expression Denial of Service (ReDoS)
Affects
nokogiri
| Versions
<1.19.3
M
Allocation of Resources Without Limits or Throttling
Affects
graphql
| Versions
>=2.3.1, <2.3.23
>=2.4.0, <2.4.18
>=2.5.0, <2.5.26
>=2.6.0, <2.6.1
H
Improper Enforcement of Behavioral Workflow
CVE-2026-42246
Affects
net-imap
| Versions
<0.3.10
>=0.4.0, <0.4.24
>=0.5.0, <0.5.14
>=0.6.0, <0.6.4
M
Inefficient Algorithmic Complexity
CVE-2026-42245
Affects
net-imap
| Versions
<0.4.24
>=0.5.0, <0.5.14
>=0.6.0, <0.6.4
H
Use of Blocking Code in Single-threaded, Non-blocking Context
CVE-2026-42256
Affects
net-imap
| Versions
>=0.4.0, <0.4.24
>=0.5.0, <0.5.14
>=0.6.0, <0.6.4
M
CRLF Injection
CVE-2026-42258
Affects
net-imap
| Versions
<0.4.24
>=0.5.0, <0.5.14
>=0.6.0, <0.6.4
H
CRLF Injection
CVE-2026-42257
Affects
net-imap
| Versions
<0.4.24
>=0.5.0, <0.5.14
>=0.6.0, <0.6.4