Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Allocation of Resources Without Limits or Throttling
CVE-2025-49007
Affects
rack
| Versions
>=3.1.0, <3.1.16
L
Race Condition
CVE-2025-46336
Affects
rack-session
| Versions
>=2.0.0, <2.1.1
L
Race Condition
CVE-2025-32441
Affects
rack
| Versions
<2.2.14
H
Allocation of Resources Without Limits or Throttling
CVE-2025-46727
Affects
rack
| Versions
<2.2.14
>=3.0.0.beta1, <3.0.16
>=3.1.0, <3.1.14
M
Improper Validation of Certificate with Host Mismatch
CVE-2025-46551
Affects
jruby-openssl
| Versions
>=0.12.1, <0.15.4
H
Memory Allocation with Excessive Size Value
CVE-2025-43857
Affects
net-imap
| Versions
<0.2.5
>=0.3.0, <0.3.9
>=0.4.0, <0.4.20
>=0.5.0, <0.5.7
L
Buffer Under-read
CVE-2025-32415
Affects
nokogiri
| Versions
<1.18.8
M
Cross-site Scripting (XSS)
CVE-2024-39311
Affects
publify_core
| Versions
<10.0.2
M
HTTP Response Splitting
CVE-2025-30221
Affects
pitchfork
| Versions
<0.11.0
M
Use After Free
CVE-2024-55549
Affects
nokogiri
| Versions
<1.18.4
M
Use After Free
CVE-2025-24855
Affects
nokogiri
| Versions
<1.18.4
C
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2025-2304
Affects
camaleon_cms
| Versions
<2.9.1
C
Arbitrary Code Injection
CVE-2025-27407
Affects
graphql
| Versions
>=1.11.5, <1.11.11
>=1.12.0, <1.12.25
>=1.13.0, <1.13.24
>=2.0.0, <2.0.32
>=2.1.0, <2.1.15
>=2.2.10, <2.2.17
>=2.3.0, <2.3.21
>=2.4.0, <2.4.13
H
Out-of-bounds Read
CVE-2025-27788
Affects
json
| Versions
>=2.10.0, <2.10.2
C
Improper Verification of Cryptographic Signature
CVE-2025-25291
Affects
ruby-saml
| Versions
<1.12.4
>=1.13.0, <1.18.0
C
Improper Verification of Cryptographic Signature
CVE-2025-25292
Affects
ruby-saml
| Versions
<1.12.4
>=1.13.0, <1.18.0
H
Allocation of Resources Without Limits or Throttling
CVE-2025-25293
Affects
ruby-saml
| Versions
<1.12.4
>=1.13.0, <1.18.0
H
Stack-based Buffer Overflow
CVE-2024-7254
Affects
google-protobuf
| Versions
<3.25.5
>=4.0.0.rc.1, <4.27.5
>=4.28.0.rc.1, <4.28.2
H
Relative Path Traversal
CVE-2025-27610
Affects
rack
| Versions
<2.2.13
>=3.0.0.beta1, <3.0.14
>=3.1.0, <3.1.12
M
Improper Output Neutralization for Logs
CVE-2025-27111
Affects
rack
| Versions
<2.2.12
>=3.0.0.beta1, <3.0.13
>=3.1.0, <3.1.11
M
Regular Expression Denial of Service (ReDoS)
CVE-2025-27220
Affects
cgi
| Versions
<0.3.5.1
>=0.3.6, <0.3.7
>=0.4.0, <0.4.2
M
Allocation of Resources Without Limits or Throttling
CVE-2025-27219
Affects
cgi
| Versions
<0.3.5.1
>=0.3.6, <0.3.7
>=0.4.0, <0.4.2
L
Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2025-27221
Affects
uri
| Versions
<0.11.3
>=0.12.0, <0.12.4
>=0.13.0, <0.13.2
>=1.0.0, <1.0.3
H
Directory Traversal
CVE-2025-27590
Affects
oxidized-web
| Versions
<0.15.0
M
Use of Uninitialized Resource
CVE-2025-26803
Affects
passenger
| Versions
>=6.0.21, <6.0.26
H
Use After Free
CVE-2024-56171
Affects
nokogiri
| Versions
<1.18.3
H
Stack-based Buffer Overflow
CVE-2025-24928
Affects
nokogiri
| Versions
<1.18.3
H
Improper Output Neutralization for Logs
CVE-2025-25184
Affects
rack
| Versions
<2.2.11
>=3.0.0, <3.0.12
>=3.1.0, <3.1.10
H
Denial of Service (DoS)
CVE-2025-25186
Affects
net-imap
| Versions
>=0.3.2, <0.3.8
>=0.4.0, <0.4.19
>=0.5.0, <0.5.6
C
Malicious Package
Affects
chauuuyhhn
| Versions
>=0.0.0