Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-29777
Affects
github.com/traefik/traefik/v2/pkg/provider/kubernetes/gateway
| Versions
*
M
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-29777
Affects
github.com/traefik/traefik/v3/pkg/provider/kubernetes/gateway
| Versions
<3.6.10
M
Cross-site Scripting (XSS)
Affects
action_text-trix
| Versions
<2.1.17
M
Cross-site Scripting (XSS)
Affects
trix
| Versions
<2.1.17
C
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CVE-2026-24713
Affects
org.apache.iotdb:iotdb-core
| Versions
[,1.3.7)
[2.0.1-beta,2.0.7)
H
Symlink Attack
Affects
openclaw
| Versions
<2026.2.26
M
Authentication Bypass by Alternate Name
Affects
openclaw
| Versions
<2026.3.8
H
Incorrect Authorization
Affects
openclaw
| Versions
<2026.2.26
M
Time-of-check Time-of-use (TOCTOU) Race Condition
Affects
openclaw
| Versions
<2026.3.8
M
Time-of-check Time-of-use (TOCTOU) Race Condition
Affects
openclaw
| Versions
<2026.3.8
M
Incorrect Authorization
Affects
openclaw
| Versions
<2026.2.26
H
Symlink Attack
Affects
openclaw
| Versions
<2026.2.26
M
Authentication Bypass Using an Alternate Path or Channel
Affects
openclaw
| Versions
<2026.2.26
M
Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2026-32237
Affects
@backstage/plugin-scaffolder-backend
| Versions
>=3.1.0 <3.1.5
M
Open Redirect
CVE-2026-32235
Affects
@backstage/plugin-auth-backend
| Versions
<0.27.1
M
Server-side Request Forgery (SSRF)
CVE-2026-32236
Affects
@backstage/plugin-auth-backend
| Versions
>=0.27.0 <0.27.1
M
Improper Validation of Specified Type of Input
Affects
devalue
| Versions
<5.6.4
M
Exposure of Private Personal Information to an Unauthorized Actor
CVE-2026-3911
Affects
org.keycloak:keycloak-services
| Versions
[0,]
M
Incorrect Authorization
CVE-2026-29195
Affects
github.com/gravitl/netmaker/controllers
| Versions
<1.5.0
C
Malicious Package
Affects
dazaar-cli
| Versions
*
C
Malicious Package
Affects
dazaar-payment
| Versions
*
C
Malicious Package
Affects
pear-wrk-wdk
| Versions
*
C
Malicious Package
Affects
yoshi-base
| Versions
*
C
Malicious Package
Affects
typescript-nhost
| Versions
*
C
Malicious Package
Affects
typescript-validation-schema
| Versions
*
C
Malicious Package
Affects
typescript-react-query
| Versions
*
C
Malicious Package
Affects
typescript-vue-apollo-smart-ops
| Versions
*
C
Malicious Package
Affects
relay-optimizer-plugin
| Versions
*
C
Malicious Package
Affects
typescript-type-graphql
| Versions
*
C
Malicious Package
Affects
urql-introspection
| Versions
*