Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Uncontrolled Recursion
Affects
nltk
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2026-33230
Affects
nltk
| Versions
[0,]
H
Directory Traversal
CVE-2026-33236
Affects
nltk
| Versions
[0,]
H
Missing Authentication for Critical Function
CVE-2026-33231
Affects
nltk
| Versions
[0,]
H
Use of Externally-Controlled Format String
CVE-2026-33210
Affects
json
| Versions
>=2.14.0, <2.15.2.1
>=2.16.0, <2.17.1.2
>=2.18.0, <2.19.2
M
Information Exposure
CVE-2026-32609
Affects
glances
| Versions
[,4.5.2)
H
SQL Injection
CVE-2026-32611
Affects
glances
| Versions
[,4.5.2)
H
Origin Validation Error
CVE-2026-32634
Affects
glances
| Versions
[,4.5.2)
H
Information Exposure
CVE-2026-32596
Affects
glances
| Versions
[,4.5.2)
M
Origin Validation Error
CVE-2026-32632
Affects
glances
| Versions
[,4.5.2)
C
Information Exposure
CVE-2026-32633
Affects
glances
| Versions
[,4.5.2)
H
Command Injection
CVE-2026-32608
Affects
glances
| Versions
[,4.5.2)
H
Permissive Cross-domain Policy with Untrusted Domains
CVE-2026-32610
Affects
glances
| Versions
[,4.5.2)
M
Cross-site Scripting (XSS)
CVE-2026-33209
Affects
avo
| Versions
<3.30.3
M
Server-side Request Forgery (SSRF)
CVE-2026-33060
Affects
@aborruso/ckan-mcp-server
| Versions
<0.4.85
C
User Impersonation
CVE-2026-33131
Affects
h3
| Versions
>=2.0.0-beta.0 <2.0.1-rc.15
M
Improper Validation of Specified Type of Input
CVE-2026-25783
Affects
github.com/mattermost/mattermost/server/channels/app
| Versions
<10.11.11
>=11.2.0-rc1 <11.2.3
>=11.3.0-rc1 <11.3.1
H
Improper Verification of Cryptographic Signature
Affects
github.com/russellhaering/gosaml2
| Versions
<0.11.0
H
Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-33155
Affects
deepdiff
| Versions
[5.0.0,8.6.2)
H
Improper Validation of Array Index
Affects
github.com/russellhaering/gosaml2
| Versions
<0.11.0
H
Improper Validation of Array Index
Affects
github.com/russellhaering/gosaml2/types
| Versions
<0.11.0
H
Improper Verification of Cryptographic Signature
Affects
github.com/russellhaering/goxmldsig
| Versions
<1.6.0
H
Timing Attack
CVE-2026-33129
Affects
org.webjars.npm:h3
| Versions
[1.0.2,]
H
Timing Attack
CVE-2026-33129
Affects
h3
| Versions
<1.15.8
>=2.0.0-beta.0 <2.0.1-rc.9
H
Information Exposure
CVE-2026-33163
Affects
parse-server
| Versions
<8.6.50
>=9.0.0 <9.6.0-alpha.35
M
CRLF Injection
CVE-2026-33128
Affects
org.webjars.npm:h3
| Versions
[1.0.2,]
M
CRLF Injection
CVE-2026-33128
Affects
h3
| Versions
<1.15.6
>=2.0.0 <2.0.1-rc.15
C
Incorrect Authorization
CVE-2026-33186
Affects
google.golang.org/grpc
| Versions
<1.79.3
C
Incorrect Authorization
CVE-2026-33186
Affects
github.com/grpc/grpc-go
| Versions
<1.79.3
H
Access of Resource Using Incompatible Type ('Type Confusion')
CVE-2026-29079
Affects
lexbor
| Versions
[0,]