Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Directory Traversal
CVE-2026-44837
Affects
view_component
| Versions
>=3.0.0, <3.25.0
>=4.0.0.alpha1, <4.9.0
M
Open Redirect
CVE-2026-40295
Affects
devise
| Versions
<5.0.4
H
Missing Release of Memory after Effective Lifetime
Affects
nokogiri
| Versions
<1.19.3
M
Regular Expression Denial of Service (ReDoS)
Affects
nokogiri
| Versions
<1.19.3
M
Allocation of Resources Without Limits or Throttling
Affects
graphql
| Versions
>=2.3.1, <2.3.23
>=2.4.0, <2.4.18
>=2.5.0, <2.5.26
>=2.6.0, <2.6.1
H
Improper Enforcement of Behavioral Workflow
CVE-2026-42246
Affects
net-imap
| Versions
<0.3.10
>=0.4.0, <0.4.24
>=0.5.0, <0.5.14
>=0.6.0, <0.6.4
M
Inefficient Algorithmic Complexity
CVE-2026-42245
Affects
net-imap
| Versions
<0.4.24
>=0.5.0, <0.5.14
>=0.6.0, <0.6.4
H
Use of Blocking Code in Single-threaded, Non-blocking Context
CVE-2026-42256
Affects
net-imap
| Versions
>=0.4.0, <0.4.24
>=0.5.0, <0.5.14
>=0.6.0, <0.6.4
M
CRLF Injection
CVE-2026-42258
Affects
net-imap
| Versions
<0.4.24
>=0.5.0, <0.5.14
>=0.6.0, <0.6.4
H
CRLF Injection
CVE-2026-42257
Affects
net-imap
| Versions
<0.4.24
>=0.5.0, <0.5.14
>=0.6.0, <0.6.4
H
Execution with Unnecessary Privileges
CVE-2026-42088
Affects
openc3
| Versions
<7.0.0-rc3
M
Relative Path Traversal
CVE-2026-42085
Affects
openc3
| Versions
<6.10.5
>=7.0.0.pre.rc1, <7.0.0-rc3
H
Unverified Password Change
CVE-2026-42084
Affects
openc3
| Versions
<6.10.5
>=7.0.0.pre.rc1, <7.0.0-rc3
C
SQL Injection
CVE-2026-42087
Affects
openc3
| Versions
>=6.7.0, <6.10.6
>=7.0.0.pre.rc1, <7.0.0-rc3
H
Authorization Bypass Through User-Controlled Key
CVE-2026-42205
Affects
avo
| Versions
<3.31.1
H
Missing Authorization
CVE-2026-40870
Affects
decidim-comments
| Versions
<0.30.5
>=0.30.0.rc1, <0.31.1
H
Missing Authorization
CVE-2026-40870
Affects
decidim-api
| Versions
<0.30.5
>=0.30.0.rc1, <0.31.1
L
Authorization Bypass Through User-Controlled Key
Affects
fat_free_crm
| Versions
>=0.10.1-rc1, <0.26.0
M
Missing Authorization
CVE-2026-40869
Affects
decidim-budgets
| Versions
>=0.19.0, <0.30.5
>=0.31.0.rc1, <0.31.1
H
Infinite loop
CVE-2026-41146
Affects
iodine
| Versions
>=0.0.1.pre, <0.7.59
C
Cross-site Scripting (XSS)
CVE-2026-23891
Affects
decidim-core
| Versions
<0.31.1
H
Improper Check for Unusual or Exceptional Conditions
CVE-2026-40069
Affects
bsv-sdk
| Versions
<0.8.2
H
Improper Verification of Cryptographic Signature
CVE-2026-40070
Affects
bsv-wallet
| Versions
<0.3.4
H
Improper Verification of Cryptographic Signature
CVE-2026-40070
Affects
bsv-sdk
| Versions
<0.8.2
H
Out-of-bounds Read
CVE-2026-35201
Affects
rdiscount
| Versions
>=1.3.1.1, <2.2.7.4
C
Not Failing Securely ('Failing Open')
CVE-2026-39324
Affects
rack-session
| Versions
>=2.0.0, <2.1.2
H
Regular Expression Denial of Service (ReDoS)
CVE-2026-35611
Affects
addressable
| Versions
>=2.3.0, <2.9.0
H
Denial of Service (DoS)
CVE-2026-34829
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
M
Incorrect Behavior Order: Validate Before Canonicalize
CVE-2026-34786
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
M
Permissive Regular Expression
CVE-2026-34763
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6