Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Improper Encoding or Escaping of Output
CVE-2026-84292
Affects
org.webjars.npm:fast-uri
| Versions
[0,]
H
Host Confusion
CVE-2026-84394
Affects
fast-uri
| Versions
>=2.4.5 <2.4.6
>=3.1.6 <3.1.7
>=4.1.3 <4.1.4
H
Improper Encoding or Escaping of Output
CVE-2026-84292
Affects
fast-uri
| Versions
<2.4.6
>=3.0.0 <3.1.7
>=4.0.0 <4.1.4
M
Insertion of Sensitive Information Into Sent Data
Affects
@pnpm/config
| Versions
>=1002.5.3 <1004.11.6
H
External Control of File Name or Path
Affects
pnpm
| Versions
>=12.0.0-alpha.0 <12.0.0-alpha.5
H
Deserialization of Untrusted Data
Affects
mlflow
| Versions
[2.1.0,3.15.0)
M
Directory Traversal
CVE-2026-9856
Affects
transformers
| Versions
[,5.10.0)
H
Incorrect Authorization
CVE-2026-80047
Affects
transformers
| Versions
[4.49.0,]
H
Out-of-bounds Read
CVE-2026-64609
Affects
org.apache.fury:fury-core
| Versions
[0.5.0,]
H
Out-of-bounds Read
CVE-2026-64609
Affects
org.apache.fory:fory-core
| Versions
[,1.4.0)
M
Improper Protection of Alternate Path
CVE-2026-66756
Affects
org.apache.tika:tika-server
| Versions
[4.0.0-alpha-1,4.0.0-beta-1)
M
Cross-site Scripting (XSS)
CVE-2026-76985
Affects
org.apache.wicket:wicket-extensions
| Versions
[1.4.0,8.19.0)
[9.0.0-M1,9.24.0)
[10.0.0-M1,10.11.0)
M
Cross-site Scripting (XSS)
CVE-2026-76984
Affects
org.apache.wicket:wicket-core
| Versions
[6.17.0,8.19.0)
[9.0.0-M1,9.24.0)
[10.0.0-M1,10.11.0)
M
Cross-site Scripting (XSS)
CVE-2026-76986
Affects
org.apache.wicket:wicket-core
| Versions
[1.5.0,8.19.0)
[9.0.0-M1,9.24.0)
[10.0.0-M1,10.11.0)
H
Missing Authorization
CVE-2026-49326
Affects
org.apache.hbase:hbase-thrift
| Versions
[2.5.0,2.5.15)
[2.6.0,2.6.6)
[3.0.0-alpha-1,3.0.0-beta-1)
M
Cross-site Scripting (XSS)
CVE-2026-76983
Affects
org.apache.wicket:wicket-core
| Versions
[1.5.0,8.19.0)
[9.0.0-M1,9.24.0)
[10.0.0-M1,10.11.0)
M
Cross-site Scripting (XSS)
CVE-2026-75802
Affects
org.apache.wicket:wicket-extensions
| Versions
[1.4.0,8.19.0)
[9.0.0-M1,9.24.0)
[10.0.0-M1,10.11.0)
H
Cross-site Request Forgery (CSRF)
CVE-2026-28813
Affects
org.apache.jspwiki:jspwiki-main
| Versions
[,2.12.4-RC2)
H
Directory Traversal
CVE-2026-62391
Affects
org.apache.kyuubi:kyuubi-server_2.12
| Versions
[1.6.0,1.12.0)
H
Allocation of Resources Without Limits or Throttling
CVE-2026-68078
Affects
org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol
| Versions
[,10.1.0)
M
Cross-site Scripting (XSS)
CVE-2026-66390
Affects
org.apache.wicket:wicket-core
| Versions
[9.0.0-M1, 10.10.0)
M
Directory Traversal
CVE-2026-70449
Affects
org.apache.wicket:wicket-core
| Versions
[,8.19.0)
[9.0.0-M1, 9.24.0)
[10.0.0-M1, 10.10.0)
M
Infinite loop
CVE-2026-84309
Affects
pypdf
| Versions
[,6.16.0)
M
Excessive Iteration
CVE-2026-84311
Affects
pypdf
| Versions
[,6.16.1)
M
Excessive Iteration
CVE-2026-84310
Affects
pypdf
| Versions
[,6.16.1)
H
HTTP Request Smuggling
CVE-2026-78605
Affects
kibana
| Versions
>=8.18.0 <8.19.20
>=9.0.0 <9.4.5
>=9.5.0 <9.5.1
M
Allocation of Resources Without Limits or Throttling
CVE-2026-56143
Affects
kibana
| Versions
>=8.0.0 <8.19.20
>=9.0.0 <9.3.0
H
Deserialization of Untrusted Data
CVE-2026-72649
Affects
kibana
| Versions
>=8.0.0 <8.19.20
>=9.0.0 <9.4.5
>=9.5.0 <9.5.1
M
Asymmetric Resource Consumption (Amplification)
CVE-2026-84364
Affects
hono
| Versions
<4.13.5
M
Missing Authorization
CVE-2026-78607
Affects
kibana
| Versions
>=8.0.0 <8.19.19
>=9.0.0 <9.3.8
>=9.4.0 <9.4.4
>=9.5.0 <9.5.1