Package vulnerability intelligence
Check the version you actually run
Review package metadata, published advisories, exact-version matches, fixes, and CISA known-exploitation evidence across five open-source ecosystems.
Supported registries
Five ecosystems, one evidence model
Each page keeps registry facts, OSV package matches, CISA evidence, and severity separate.
Reading a result
Evidence in the order you need it
Exact version
OSV checks the package and version supplied by its registry.
Known exploitation
An exact CVE match identifies records listed in CISA KEV.
Severity and fixes
CVSS, affected ranges, and fixed versions retain their source context.
CISA catalog
Recently added vulnerabilities
Citrix NetScaler Improper Input Validation Vulnerability
Citrix · NetScaler
CVE-2026-88772Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix · NetScaler
CVE-2026-65660Microsoft SharePoint Code Injection Vulnerability
Microsoft · SharePoint
CVE-2026-67279Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
MikroTik · RouterOS
CVE-2026-87902WordPress Core Remote File Inclusion Vulnerability
WordPress · Core
CVE-2026-5430WSO2 Multiple Products Path Traversal Vulnerability
WSO2 · Multiple Products
Sources: package registries, OSV, and the CISA Known Exploited Vulnerabilities Catalog. Missing advisories do not establish that a package or version has no vulnerabilities.