Address
:
[go:
up one dir
,
main page
]
Include Form
Remove Scripts
Accept Cookies
Show Images
Show Referer
Rotate13
Base64
Strip Meta
Strip Title
Session Cookies
Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-35515
Affects
@nestjs/core
| Versions
<11.1.18
M
Incomplete List of Disallowed Inputs
CVE-2026-34425
Affects
@openclaw/discord
| Versions
>=0.0.0
M
Incomplete List of Disallowed Inputs
CVE-2026-34425
Affects
openclaw
| Versions
<2026.4.2
H
Logging of Excessive Data
Affects
pocketmine/pocketmine-mp
| Versions
<5.41.1
M
Improper Control of a Resource Through its Lifetime
Affects
pocketmine/pocketmine-mp
| Versions
<5.39.2
H
Allocation of Resources Without Limits or Throttling
Affects
pocketmine/pocketmine-mp
| Versions
<5.39.2
M
Insufficient Control of Network Message Volume (Network Amplification)
Affects
pocketmine/pocketmine-mp
| Versions
<5.39.2
H
Cross-site Scripting (XSS)
CVE-2026-35035
Affects
ci4-cms-erp/ci4ms
| Versions
<0.31.2.0
H
Arbitrary Code Injection
CVE-2026-26026
Affects
glpi/glpi
| Versions
>=11.0.0, <11.0.6
C
SQL Injection
CVE-2026-26263
Affects
glpi/glpi
| Versions
>=11.0.0-alpha, <11.0.6
H
Improper Encoding or Escaping of Output
CVE-2026-25932
Affects
glpi/glpi
| Versions
>=0.60, <10.0.24
>=11.0.0-alpha, <11.0.6
H
SQL Injection
CVE-2026-29047
Affects
glpi/glpi
| Versions
>=10.0.0-beta, <10.0.24
>=11.0.0-alpha, <11.0.6
H
Cross-site Scripting (XSS)
CVE-2026-26027
Affects
glpi/glpi
| Versions
>=11.0.0-alpha, <11.0.6
M
Cross-site Scripting (XSS)
CVE-2026-31350
Affects
feehi/cms
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2026-31352
Affects
feehi/cms
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2026-31353
Affects
feehi/cms
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2026-31354
Affects
feehi/cms
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2026-31313
Affects
feehi/cms
| Versions
>=0.0.0
M
Cross-site Scripting (XSS)
CVE-2026-31351
Affects
feehi/cms
| Versions
>=0.0.0
M
Allocation of Resources Without Limits or Throttling
CVE-2026-33219
Affects
github.com/nats-io/nats-server/v2/server
| Versions
<2.11.15
>=2.12.0-RC.1 <2.12.6
C
Command Injection
CVE-2026-0596
Affects
mlflow-skinny
| Versions
[,3.9.0rc0)
C
Command Injection
CVE-2026-0596
Affects
mlflow
| Versions
[,3.9.0rc0)
M
Server-side Request Forgery (SSRF)
CVE-2026-33990
Affects
github.com/docker/model-runner/pkg/distribution/oci/remote
| Versions
<1.1.25
C
Improper Control of Dynamically-Managed Code Resources
CVE-2026-34156
Affects
@nocobase/plugin-workflow-javascript
| Versions
<2.0.28
H
Improper Authorization in Handler for Custom URL Scheme
CVE-2026-35394
Affects
@mobilenext/mobile-mcp
| Versions
<0.0.50
H
Reachable Assertion
CVE-2026-4046
Affects
glibc
| Versions
[0,]
M
Server-side Request Forgery (SSRF)
CVE-2026-34881
Affects
glance
| Versions
[,29.2.0)
[30.0.0,30.2.0)
[31.0.0,31.1.0)
H
Use of Unmaintained Third Party Components
CVE-2026-4176
Affects
perl5
| Versions
[,5.40.4)
[5.41.0,5.42.2)
[5.43.0,5.43.9)
H
Improper Handling of Values
CVE-2025-59032
Affects
dovecot
| Versions
[,2.4.3)
H
Command Injection
CVE-2026-25044
Affects
@budibase/types
| Versions
<3.33.4