Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
L
Remote Code Execution (RCE)
CVE-2020-26222
Affects
dependabot-common
| Versions
>=0.119.0.beta1, <0.125.1
H
Regression in JWT Signature Validation
CVE-2020-15240
Affects
omniauth-auth0
| Versions
>=2.3.0, <2.4.1
H
Authentication Bypass
CVE-2020-15269
Affects
spree
| Versions
>=3.7.0, <3.7.11
>=4.0.0, <4.0.4
>=4.1.0, <4.1.11
H
Cross-site Scripting (XSS)
CVE-2020-8264
Affects
actionpack
| Versions
>=6.0.0, <6.0.3.4
M
Timing Attack
CVE-2020-15237
Affects
shrine
| Versions
<3.3.0
H
HTTP Request Smuggling
CVE-2020-25613
Affects
webrick
| Versions
<1.5.1
>=1.6.0, <1.6.1
H
Man-in-the-Middle (MitM)
CVE-2016-11086
Affects
oauth
| Versions
<0.5.5
H
Cross-site Scripting (XSS)
CVE-2020-25739
Affects
gon
| Versions
<6.4.0
M
Cross-site Scripting (XSS)
CVE-2020-15169
Affects
actionview
| Versions
<5.2.4.4
>=6.0.0.0, <6.0.3.3
M
Improper Input Validation
Affects
personnummer
| Versions
<3.0.1
H
Directory Traversal
CVE-2019-8320
Affects
rubygems-update
| Versions
>=2.7.6, <2.7.9
>=3.0.0, <3.0.3
H
Arbitrary Code Injection
CVE-2019-8322
Affects
rubygems-update
| Versions
>=2.6.0, <2.7.9
>=3.0.0, <3.0.2
H
Arbitrary Code Injection
CVE-2019-8323
Affects
rubygems-update
| Versions
>=2.6.0, <2.7.9
>=3.0.0, <3.0.3
H
Arbitrary Code Injection
CVE-2019-8321
Affects
rubygems-update
| Versions
>=2.6.0, <2.7.9
>=3.0.0, <3.0.3
H
CSS Injection
CVE-2020-16254
Affects
chartkick
| Versions
<3.4.0
H
Cross-site Request Forgery (CSRF)
CVE-2020-16252
Affects
field_test
| Versions
<0.4.0
H
Cross-site Request Forgery (CSRF)
CVE-2020-16253
Affects
pghero
| Versions
<2.7.0
H
Improper Input Validation
CVE-2020-15109
Affects
solidus_api
| Versions
>=2.8.0, <2.8.6
>=2.9.0, <2.9.6
>=2.10.0, <2.10.2
H
Improper Input Validation
CVE-2020-15109
Affects
solidus_frontend
| Versions
>=2.8.0, <2.8.6
>=2.9.0, <2.9.6
>=2.10.0, <2.10.2
H
Improper Certificate Validation
CVE-2020-15133
Affects
faye-websocket
| Versions
<0.11.0
H
Remote Code Execution (RCE)
CVE-2020-14001
Affects
kramdown
| Versions
<2.3.0
H
Improper Authorization
CVE-2020-8185
Affects
actionpack
| Versions
>=6.0.0, <6.0.3.2
C
Cross-site Scripting (XSS)
CVE-2020-4054
Affects
sanitize
| Versions
>=3.0.0, <5.2.1
M
Cross-site Request Forgery (CSRF)
CVE-2020-8184
Affects
rack
| Versions
<2.1.4
>=2.2.0, <2.2.3
M
HTTP Request Smuggling
Affects
iodine
| Versions
<0.7.39
M
Cross-site Scripting (XSS)
CVE-2020-7011
Affects
elastic-app-search
| Versions
<7.7.0
M
HTTP Request Smuggling
CVE-2020-7670
Affects
agoo
| Versions
<2.14.0
M
HTTP Request Smuggling
CVE-2020-7671
Affects
goliath
| Versions
>=0.0.0
H
Regular Expression Denial of Service (ReDoS)
CVE-2020-7662
Affects
websocket-extensions
| Versions
<0.1.5
M
Cross-site Scripting (XSS)
CVE-2020-11082
Affects
kaminari
| Versions
<1.2.1