Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Incorrect Privilege Assignment
CVE-2026-27198
Affects
getformwork/formwork
| Versions
>=2.0.0, <2.3.4
H
Open Redirect
CVE-2026-27191
Affects
@feathersjs/authentication-oauth
| Versions
<5.0.40
H
Origin Validation Error
CVE-2026-27192
Affects
@feathersjs/authentication-oauth
| Versions
<5.0.40
H
Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2026-27193
Affects
@feathersjs/authentication-oauth
| Versions
<5.0.40
M
Cross-site Scripting (XSS)
CVE-2026-27196
Affects
statamic/cms
| Versions
<5.73.9
>=6.0.0-alpha.1, <6.3.2
H
CRLF Injection
CVE-2026-27203
Affects
ebay-mcp
| Versions
*
H
Always-Incorrect Control Flow Implementation
CVE-2026-26267
Affects
soroban-sdk-macros
| Versions
<22.0.10
>=23.0.0 <23.5.2
>=25.0.0 <25.1.1
M
Buffer Over-read
CVE-2026-26282
Affects
M2Team/NanaZip
| Versions
[5.0.1252.0,6.0.1630.0)
H
External Control of File Name or Path
CVE-2026-26975
Affects
music-assistant
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2026-27568
Affects
wwbn/avideo
| Versions
<21.0
M
Arbitrary File Upload
CVE-2025-13590
Affects
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl
| Versions
[,9.32.167)
L
Exposure of Data Element to Wrong Session
CVE-2026-27492
Affects
lettermint
| Versions
<1.5.1
M
Information Exposure
CVE-2026-27480
Affects
static-web-server
| Versions
>=2.1.0 <2.41.0
M
Directory Traversal
CVE-2026-25527
Affects
changedetection.io
| Versions
[,0.53.2)
M
Cross-site Scripting (XSS)
CVE-2026-2735
Affects
org.opencms:opencms-core
| Versions
[,19.0)
M
Cross-site Scripting (XSS)
CVE-2026-2736
Affects
org.opencms:opencms-core
| Versions
[,19.0)
C
Malicious Package
Affects
eslint-verify-plugin
| Versions
*
M
Improper Verification of Source of a Communication Channel
CVE-2026-2967
Affects
cesanta/mongoose
| Versions
[0,]
M
Generation of Predictable Numbers or Identifiers
CVE-2026-2966
Affects
cesanta/mongoose
| Versions
[0,]
M
Improper Verification of Cryptographic Signature
CVE-2026-2968
Affects
cesanta/mongoose
| Versions
[0,]
C
Malicious Package
Affects
npm-security-testing
| Versions
*
C
Malicious Package
Affects
rbxm-tools
| Versions
*
C
Malicious Package
Affects
react-dropzone-truffle
| Versions
*
C
Missing Authentication for Critical Function
Affects
github.com/dagu-org/dagu/internal/service/frontend/api/v1
| Versions
>=0.0.0
C
Missing Authentication for Critical Function
Affects
github.com/dagu-org/dagu/internal/common/config
| Versions
>=0.0.0
C
Incorrect Authorization
CVE-2026-27112
Affects
github.com/akuity/kargo/pkg/server
| Versions
>=1.7.0 <1.7.8
>=1.8.0-rc.1 <1.8.11
>=1.9.0-rc.1 <1.9.3
M
Missing Authorization
CVE-2026-27111
Affects
github.com/akuity/kargo/pkg/server
| Versions
>=1.9.0 <1.9.3
M
Out-of-bounds Write
CVE-2026-2940
Affects
Zaher1307/tiny_web_server
| Versions
[0,]
M
NULL Pointer Dereference
CVE-2026-2903
Affects
re2c
| Versions
[0,]
M
NULL Pointer Dereference
CVE-2026-2903
Affects
skvadrik/re2c
| Versions
[0,]