Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
585975
AlmaLinux
4485
Alpaquita
8418
Alpine
3982
Android
3263
BellSoft Hardened Containers
367
Bitnami
6627
Chainguard
5042
CleanStart
415
CRAN
13
crates.io
2055
Debian
52914
Echo
3014
GHC
3
GIT
77868
GitHub Actions
42
Go
5821
Hackage
27
Hex
47
Julia
331
Linux
15372
Mageia
5823
Maven
6193
MinimOS
17083
npm
215521
NuGet
1588
opam
11
openEuler
5999
openSUSE
10442
OSS-Fuzz
3797
Packagist
5769
Pub
10
PyPI
18039
Red Hat
18777
Rocky Linux
2764
Root
10800
RubyGems
1863
SUSE
17256
SwiftURL
47
Ubuntu
50928
VSCode
15
Wolfi
3144
ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-23940
github.com/hexpm/hexpm.git
Denial of Service via Oversized Package Upload
10 hours ago
Fix available
Severity - 7.1 (High)
EEF-CVE-2026-23941
github.com/erlang/otp
Request smuggling via first-wins Content-Length parsing in inets httpd
17 hours ago
Fix available
Severity - 7.0 (High)
EEF-CVE-2026-23943
github.com/erlang/otp
Pre-auth SSH DoS via unbounded zlib inflate
17 hours ago
Fix available
Severity - 6.9 (Medium)
EEF-CVE-2026-23942
github.com/erlang/otp
SFTP root escape via component-agnostic prefix check in ssh_sftpd
17 hours ago
Fix available
Severity - 5.3 (Medium)
PSF-2026-10
github.com/python/cpython
See record for full details
yesterday
No fix available
CVE-2026-31875
github.com/parse-community/parse-server
Parse Server MFA recovery codes not consumed after use
2 days ago
Fix available
Severity - 8.2 (High)
CVE-2026-31872
github.com/parse-community/parse-server
Parse Server has a protected fields bypass via dot-notation in query and sort
2 days ago
Fix available
Severity - 8.7 (High)
CVE-2026-31871
github.com/parse-community/parse-server
Parse Server has a SQL Injection via dot-notation sub-key name in
`
Increment
`
operation on PostgreSQL
2 days ago
Fix available
Severity - 9.3 (Critical)
CVE-2026-31870
github.com/yhirose/cpp-httplib
cpp-httplib Affected by Remote Process Crash via Malformed Content-Length Response Header
2 days ago
Fix available
Severity - 7.5 (High)
CVE-2026-31868
github.com/parse-community/parse-server
Parse Server has Stored XSS via file upload of HTML-renderable file types
2 days ago
Fix available
Severity - 6.3 (Medium)
CVE-2026-31856
github.com/parse-community/parse-server
Parse Server has a SQL injection via
`
Increment
`
operation on nested object field in PostgreSQL
2 days ago
Fix available
Severity - 9.3 (Critical)
CVE-2026-31840
github.com/parse-community/parse-server
Parse Server has a SQL injection via dot-notation field name in PostgreSQL
2 days ago
Fix available
Severity - 9.3 (Critical)
CVE-2026-31813
github.com/supabase/auth
Supabase Auth has insecure Apple and Azure authentication with ID tokens
2 days ago
Fix available
Severity - 4.8 (Medium)
CVE-2026-30868
github.com/opnsense/core
Cross-Site Request Forgery (CSRF) in opnsense/core
2 days ago
Fix available
Severity - 6.3 (Medium)
CVE-2026-30239
github.com/opf/openproject
OpenProject has a Permission Check bypass on Budget deletion allows reassignment of WorkPackages into other budgets
2 days ago
Fix available
Severity - 6.5 (Medium)
CVE-2026-30236
github.com/opf/openproject
OpenProject users that are not project members can be used to calculate Labor Budget, leaking their global hourly rate
2 days ago
Fix available
Severity - 4.3 (Medium)
Load more...
GIT - OSV