Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
C
Malicious Package
Affects
base58-engine
| Versions
*
C
Malicious Package
Affects
base-or-engine
| Versions
*
M
Missing Authentication for Critical Function
Affects
litellm
| Versions
[,1.82.4)
C
Deserialization of Untrusted Data
Affects
ai.h2o:h2o-core
| Versions
[,3.46.0.10)
H
Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2025-15381
Affects
mlflow-skinny
| Versions
[,3.11.0rc0)
H
Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2025-15381
Affects
mlflow
| Versions
[,3.11.0rc0)
H
Directory Traversal
CVE-2026-35167
Affects
kedro
| Versions
[,1.3.0)
L
SQL Injection
Affects
@langchain/google-cloud-sql-pg
| Versions
<1.0.22
H
UNIX Symbolic Link (Symlink) Following
CVE-2026-27489
Affects
onnx
| Versions
[,1.21.0)
H
Directory Traversal
Affects
onnxruntime
| Versions
[,1.24.1)
H
Arbitrary Code Execution
Affects
fonttools
| Versions
[,4.62.0)
H
XML Injection
CVE-2026-34601
Affects
org.webjars.npm:xmldom
| Versions
[0,]
H
XML Injection
CVE-2026-34601
Affects
xmldom
| Versions
*
H
XML Injection
CVE-2026-34601
Affects
@xmldom/xmldom
| Versions
<0.8.12
>=0.9.0 <0.9.9
H
Improper Verification of Cryptographic Signature
CVE-2026-34240
Affects
jose_plus
| Versions
*
H
Improper Verification of Cryptographic Signature
CVE-2026-34240
Affects
jose2
| Versions
*
H
Improper Verification of Cryptographic Signature
CVE-2026-34240
Affects
jose
| Versions
<0.3.5+1
M
Prototype Pollution
CVE-2026-2950
Affects
org.webjars.npm:lodash
| Versions
[4.0.0,]
M
Prototype Pollution
CVE-2026-2950
Affects
org.webjars.npm:lodash-es
| Versions
[4.2.1,]
H
Arbitrary Code Injection
CVE-2026-4800
Affects
org.webjars.npm:lodash-es
| Versions
[0,]
H
Arbitrary Code Injection
CVE-2026-4800
Affects
org.webjars.npm:lodash.template
| Versions
[0,]
H
Arbitrary Code Injection
CVE-2026-4800
Affects
org.webjars.npm:lodash
| Versions
[0,]
H
Arbitrary Code Injection
CVE-2026-4800
Affects
lodash-rails
| Versions
>=0.7.0
H
Arbitrary Code Injection
CVE-2026-4800
Affects
lodash.template
| Versions
<4.18.1
H
Arbitrary Code Injection
CVE-2026-4800
Affects
lodash-es
| Versions
<4.18.1
H
Arbitrary Code Injection
CVE-2026-4800
Affects
lodash-amd
| Versions
<4.18.1
H
Arbitrary Code Injection
CVE-2026-4800
Affects
lodash
| Versions
<4.18.1
M
Prototype Pollution
CVE-2026-2950
Affects
lodash-amd
| Versions
>=4.0.0 <4.18.1
M
Prototype Pollution
CVE-2026-2950
Affects
lodash-es
| Versions
>=4.0.0 <4.18.1
M
Prototype Pollution
CVE-2026-2950
Affects
lodash.unset
| Versions
<4.18.0