Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Arbitrary File Upload
CVE-2026-41587
Affects
ci4-cms-erp/ci4ms
| Versions
>=0.26.0.0, <0.31.7.0
H
SQL Injection
CVE-2026-42474
Affects
mix/mix
| Versions
>=2.0.0
H
SQL Injection
CVE-2026-42475
Affects
mix/mix
| Versions
>=2.0.0
C
Deserialization of Untrusted Data
CVE-2026-42473
Affects
mix/mix
| Versions
>=2.0.0
C
Deserialization of Untrusted Data
CVE-2026-42472
Affects
mix/mix
| Versions
>=2.0.0
C
Deserialization of Untrusted Data
CVE-2026-42471
Affects
mix/mix
| Versions
>=2.0.0
H
Deserialization of Untrusted Data
CVE-2026-37552
Affects
mix/mix
| Versions
>=2.0.0
H
Server-side Request Forgery (SSRF)
CVE-2026-34084
Affects
phpoffice/phpspreadsheet
| Versions
<1.30.3
>=2.0.0, <2.1.15
>=2.2.0, <2.4.4
>=3.3.0, <3.10.4
>=4.0.0, <5.6.0
H
Cross-site Scripting (XSS)
CVE-2026-40863
Affects
phpoffice/phpspreadsheet
| Versions
<1.30.4
>=2.0.0, <2.1.16
>=2.2.0, <2.4.5
>=3.3.0, <3.10.5
>=4.0.0, <5.7.0
H
Cross-site Scripting (XSS)
CVE-2026-40902
Affects
phpoffice/phpspreadsheet
| Versions
<1.30.4
>=2.0.0, <2.1.16
>=2.2.0, <2.4.5
>=3.3.0, <3.10.5
>=4.0.0, <5.7.0
M
Cross-site Scripting (XSS)
CVE-2026-35453
Affects
phpoffice/phpspreadsheet
| Versions
<1.30.4
>=2.0.0, <2.1.16
>=2.2.0, <2.4.5
>=3.3.0, <3.10.5
>=4.0.0, <5.7.0
M
Cross-site Scripting (XSS)
CVE-2026-40296
Affects
phpoffice/phpspreadsheet
| Versions
<1.30.4
>=2.0.0, <2.1.16
>=2.2.0, <2.4.5
>=3.3.0, <3.10.5
>=4.0.0, <5.7.0
M
Improper Neutralization of Special Elements in Data Query Logic
CVE-2026-6626
Affects
cockpit-hq/cockpit
| Versions
>=2.13.0, <2.14.0
H
Command Injection
CVE-2026-7246
Affects
click
| Versions
[8.2.0,8.3.3)
H
SQL Injection
CVE-2026-5394
Affects
pimcore/pimcore
| Versions
>=12.3.3
M
Cross-site Scripting (XSS)
CVE-2026-5362
Affects
pimcore/pimcore
| Versions
>=12.3.3
H
Open Redirect
CVE-2026-40171
Affects
notebook
| Versions
[7.0.0,7.5.6)
H
Open Redirect
CVE-2026-40171
Affects
jupyterlab
| Versions
[,4.5.7)
H
Open Redirect
CVE-2026-40171
Affects
@jupyterlab/help-extension
| Versions
<4.5.7
H
Open Redirect
CVE-2026-40171
Affects
@jupyter-notebook/help-extension
| Versions
>=7.0.0 <7.5.6
M
Reliance on Untrusted Inputs in a Security Decision
CVE-2026-39807
Affects
bandit
| Versions
>=1.0.0 <1.11.0
H
Operation on a Resource after Expiration or Release
Affects
intaglio
| Versions
<1.13.3
L
Missing Authorization
Affects
sequoia-git
| Versions
<0.6.0
H
Allocation of Resources Without Limits or Throttling
CVE-2026-39804
Affects
bandit
| Versions
>=0.5.9 <1.11.0
H
Arbitrary Code Injection
CVE-2026-41414
Affects
skim
| Versions
<4.6.1
H
Allocation of Resources Without Limits or Throttling
CVE-2026-42786
Affects
bandit
| Versions
>=0.5.1 <1.11.0
M
Allocation of Resources Without Limits or Throttling
CVE-2026-42788
Affects
bandit
| Versions
>=3.0.0 <1.11.0
H
Infinite loop
Affects
hickory-net
| Versions
<0.26.1
H
Infinite loop
Affects
hickory-proto
| Versions
<0.26.0-beta.1
M
HTTP Request Smuggling
CVE-2026-39805
Affects
bandit
| Versions
>=0.6.4 <1.11.0