Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Denial of Service (DoS)
CVE-2026-34826
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
H
Permissive Regular Expression
CVE-2026-34830
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
H
Denial of Service (DoS)
CVE-2026-34230
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
H
Partial String Comparison
CVE-2026-34785
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
M
Improper Handling of Length Parameter Inconsistency
CVE-2026-34831
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
M
CRLF Injection
CVE-2026-26962
Affects
rack
| Versions
>=3.2.0, <3.2.6
M
Interpretation Conflict
CVE-2026-32762
Affects
rack
| Versions
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
M
Improper Validation of Syntactic Correctness of Input
CVE-2026-34835
Affects
rack
| Versions
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
H
Inefficient Algorithmic Complexity
CVE-2026-34827
Affects
rack
| Versions
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
M
Interpretation Conflict
CVE-2026-26961
Affects
rack
| Versions
<2.2.23
>=3.0.0.beta1, <3.1.21
>=3.2.0, <3.2.6
H
Arbitrary Code Injection
CVE-2026-4800
Affects
lodash-rails
| Versions
>=0.7.0
M
Cross-site Scripting (XSS)
CVE-2026-73427
Affects
action_text-trix
| Versions
<2.1.18
H
Arbitrary Code Injection
CVE-2026-34060
Affects
ruby-lsp
| Versions
<0.26.9
H
Improper Control of Dynamically-Managed Code Resources
CVE-2026-33286
Affects
graphiti
| Versions
<1.10.2
H
Session Fixation
CVE-2026-33946
Affects
mcp
| Versions
<0.9.2
M
Allocation of Resources Without Limits or Throttling
CVE-2026-33658
Affects
activestorage
| Versions
<7.2.3.1
>=8.0.0, <8.0.4.1
>=8.1.0, <8.1.2.1
M
SQL Injection
CVE-2026-4324
Affects
katello
| Versions
<4.19.1
M
CRLF Injection
CVE-2026-33635
Affects
icalendar
| Versions
>=2.0.0, <2.12.2
M
Cross-site Scripting (XSS)
CVE-2026-33167
Affects
actionpack
| Versions
>=8.1.0.beta1, <8.1.2.1
L
Cross-site Scripting (XSS)
CVE-2026-33168
Affects
actionview
| Versions
<7.2.3.1
>=8.0.0.beta1, <8.0.4.1
>=8.1.0.beta1, <8.1.2.1
M
Cross-site Scripting (XSS)
CVE-2026-33170
Affects
activesupport
| Versions
<7.2.3.1
>=8.0.0.beta1, <8.0.4.1
>=8.1.0.beta1, <8.1.2.1
H
Memory Allocation with Excessive Size Value
CVE-2026-33174
Affects
activestorage
| Versions
<7.2.3.1
>=8.0.0.beta1, <8.0.4.1
>=8.1.0.beta1, <8.1.2.1
H
Allocation of Resources Without Limits or Throttling
CVE-2026-33176
Affects
activesupport
| Versions
<7.2.3.1
>=8.0.0.beta1, <8.0.4.1
>=8.1.0.beta1, <8.1.2.1
M
Regular Expression Denial of Service (ReDoS)
CVE-2026-33169
Affects
activesupport
| Versions
<7.2.3.1
>=8.0.0.beta1, <8.0.4.1
>=8.1.0.beta1, <8.1.2.1
M
Improper Handling of Values
CVE-2026-33173
Affects
activestorage
| Versions
<7.2.3.1
>=8.0.0.beta1, <8.0.4.1
>=8.1.0.beta1, <8.1.2.1
C
Directory Traversal
CVE-2026-33195
Affects
activestorage
| Versions
<7.2.3.1
>=8.0.0.beta1, <8.0.4.1
>=8.1.0.beta1, <8.1.2.1
M
Glob Injection
CVE-2026-33202
Affects
activestorage
| Versions
<7.2.3.1
>=8.0.0.beta1, <8.0.4.1
>=8.1.0.beta1, <8.1.2.1
H
Integer Overflow or Wraparound
CVE-2026-33306
Affects
bcrypt
| Versions
<3.1.22
H
Use of Externally-Controlled Format String
CVE-2026-33210
Affects
json
| Versions
>=2.14.0, <2.15.2.1
>=2.16.0, <2.17.1.2
>=2.18.0, <2.19.2
M
Cross-site Scripting (XSS)
CVE-2026-33209
Affects
avo
| Versions
<3.30.3