Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Severity
Critical
(67,831)
High
(109,893)
Medium
(140,297)
Low
(10,345)
CVSS Score
0.0
10.0
EPSS Score
0.0
1.0
Malware
KEV Status
Published
Affected Ecosystem
option1
option2
option3
option4
option5
Vulnerabilities
382,428
Filter
Sort: Published (Newest first)
5.3
sonatype-2026-001192
Malicious Packages - Tue Mar 17 2026 [Info Stealer]
affected
Severity
Medium
Published
Mar 17, 2026
6.5
CVE-2026-32758
github.com/filebrowser/filebrowser/v2 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
affected
Severity
Medium
Published
Mar 17, 2026
5.3
sonatype-2026-001191
Malicious Packages - Mon Mar 16 2026 [Info Stealer]
affected
Severity
Medium
Published
Mar 17, 2026
8.7
sonatype-2026-001190
Malicious Packages - Mon Mar 16 2026 [Dropper]
affected
Severity
High
Published
Mar 17, 2026
8.7
sonatype-2026-001189
Malicious Packages - Mon Mar 16 2026 [RCE] [Info Stealer]
affected
Severity
High
Published
Mar 17, 2026
3.6
CVE-2026-32722
memray - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
affected
Severity
Low
Published
Mar 17, 2026
7.5
CVE-2026-32609
Glances - Exposure of Sensitive Information to an Unauthorized Actor
affected
Severity
High
Published
Mar 17, 2026
2.7
CVE-2026-32638
studiocms - Authorization Bypass Through User-Controlled Key
affected
Severity
Low
Published
Mar 17, 2026
5.9
CVE-2026-32632
Glances - Origin Validation Error
affected
Severity
Medium
Published
Mar 17, 2026
8.1
CVE-2026-32634
Glances - Origin Validation Error
affected
Severity
High
Published
Mar 17, 2026
9.1
CVE-2026-32633
Glances - Exposure of Sensitive Information to an Unauthorized Actor
affected
Severity
Critical
Published
Mar 17, 2026
7.0
CVE-2026-32608
Glances - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
affected
Severity
High
Published
Mar 17, 2026
8.1
CVE-2026-32610
Glances - Permissive Cross-domain Security Policy with Untrusted Domains
affected
Severity
High
Published
Mar 17, 2026
7.5
CVE-2026-29112
converter - Allocation of Resources Without Limits or Throttling
affected
Severity
High
Published
Mar 17, 2026
7.7
CVE-2026-32606
github.com/lxc/incus-os/incus-osd - Insufficiently Protected Credentials
affected
Severity
High
Published
Mar 17, 2026
7.0
CVE-2026-32611
Glances - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
affected
Severity
High
Published
Mar 17, 2026
9.1
CVE-2026-25534
orca-core - Server-Side Request Forgery (SSRF)
affected
Severity
Critical
Published
Mar 17, 2026
8.6
CVE-2026-28500
onnx - Insufficient Verification of Data Authenticity
affected
Severity
High
Published
Mar 17, 2026
6.3
CVE-2025-66249
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue affects Apache Livy: from 0.3.0 before 0.9.0. The vulnerability can only be exploited with non-default Apache Livy Server settings. If the configuration value "livy.file.local-dir-whitelist" is set to a non-default value, the directory checking can be bypassed. Users are recommended to upgrade to version 0.9.0, which fixes the issue.
affected
Severity
Medium
Published
Mar 17, 2026
10.0
sonatype-2026-001188
NPM Security Holding Packages - Tue Mar 17 2026
affected
Severity
Critical
Published
Mar 17, 2026
8.7
sonatype-2026-001187
Malicious Packages - Mon Mar 16 2026 [Dropper]
affected
Severity
High
Published
Mar 16, 2026
0.0
sonatype-2026-001186
Potentially Unwanted Applications - Mon Mar 16 2026 [PUA]
affected
Severity
None
Published
Mar 16, 2026
5.3
sonatype-2026-001185
Malicious Packages - Mon Mar 16 2026 [Data Corruption]
affected
Severity
Medium
Published
Mar 16, 2026
5.3
sonatype-2026-001184
Malicious Packages - Mon Mar 16 2026 [Info Stealer]
affected
Severity
Medium
Published
Mar 16, 2026
5.4
CVE-2026-32612
Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel color mode preference allows authenticated users with control panel access to inject malicious JavaScript that executes when a higher-privileged user impersonates their account. This has been fixed in 6.6.2.
affected
Severity
Medium
Published
Mar 16, 2026
1-25 of 382,428