Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
C
Malicious Package
Affects
modern-events
| Versions
*
M
Authorization Bypass Through User-Controlled Key
CVE-2025-66286
Affects
wpe_webkit
| Versions
[0,]
M
Authorization Bypass Through User-Controlled Key
CVE-2025-66286
Affects
webkitgtk
| Versions
[0,]
H
Out-of-bounds Read
CVE-2026-34003
Affects
xorg/xwayland
| Versions
[,24.1.10)
H
Out-of-bounds Read
CVE-2026-34003
Affects
xorg-server
| Versions
[,21.1.22)
H
Access of Resource Using Incompatible Type ('Type Confusion')
CVE-2026-6732
Affects
libxml2
| Versions
[0,]
H
Access of Resource Using Incompatible Type ('Type Confusion')
CVE-2026-6732
Affects
libxml2
| Versions
[,2.15.3)
M
Exposure of Private Personal Information to an Unauthorized Actor
CVE-2026-6765
Affects
thunderbird
| Versions
[,140.10)
M
Exposure of Private Personal Information to an Unauthorized Actor
CVE-2026-6765
Affects
Firefox-ESR
| Versions
[,140.10)
M
Exposure of Private Personal Information to an Unauthorized Actor
CVE-2026-6765
Affects
Firefox
| Versions
[,150.0)
M
Out-of-Bounds
CVE-2026-6779
Affects
thunderbird
| Versions
[,150.0)
M
Out-of-Bounds
CVE-2026-6779
Affects
Firefox
| Versions
[,150.0)
H
Use of Incorrectly-Resolved Name or Reference
Affects
hickory-dns
| Versions
<0.26.0-beta.3
H
Use of Incorrectly-Resolved Name or Reference
Affects
hickory-recursor
| Versions
*
C
Malicious Package
Affects
mysten-metrics
| Versions
*
C
Malicious Package
Affects
sui-execution-cut
| Versions
*
M
Cross-site Scripting (XSS)
CVE-2026-30139
Affects
org.silverpeas.core:silverpeas-core-war
| Versions
[,6.4.6)
L
Insufficient Granularity of Access Control
CVE-2026-35402
Affects
mcp-neo4j-cypher
| Versions
[,0.6.0)
H
Permissive Regular Expression
CVE-2026-25542
Affects
github.com/tektoncd/pipeline/pkg/trustedresources
| Versions
>=0.43.0 <1.0.2
>=1.1.0 <1.3.4
>=1.4.0 <1.6.2
>=1.7.0 <1.9.3
>=1.10.0 <1.11.1
C
Improper Validation of Specified Index, Position, or Offset in Input
CVE-2026-33557
Affects
org.apache.kafka:kafka-clients
| Versions
[4.1.0,4.1.2)
M
Unsafe Dependency Resolution
CVE-2026-41355
Affects
openclaw
| Versions
<2026.3.28
L
Origin Validation Error
CVE-2026-41358
Affects
openclaw
| Versions
<2026.4.2
M
Incorrect Authorization
CVE-2026-41909
Affects
openclaw
| Versions
<2026.4.20
L
Incorrect Authorization
CVE-2026-41908
Affects
openclaw
| Versions
<2026.4.20
H
Uncontrolled Recursion
CVE-2026-41311
Affects
liquidjs
| Versions
<10.25.6
L
Improper Neutralization
CVE-2026-6019
Affects
cpython
| Versions
[0,]
L
Improper Neutralization
CVE-2026-6019
Affects
python
| Versions
[0,]
M
Symlink Attack
CVE-2026-40977
Affects
org.springframework.boot:spring-boot
| Versions
[,3.5.14)
[4.0.0-M1,4.0.6)
L
Improper Validation of Certificate with Host Mismatch
CVE-2026-40971
Affects
org.springframework.boot:spring-boot-autoconfigure
| Versions
[,3.5.14)
[4.0.0-M1,4.0.6)
H
Insecure Temporary File
CVE-2026-40973
Affects
org.springframework.boot:spring-boot
| Versions
[,3.5.14)
[4.0.0-M1,4.0.6)