Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-58500
appium-mcp: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)
CVE-2026-59801
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
CVE-2026-10802
Keystone: GraphQL API Endpoint Lacks Query Depth Limits
CVE-2026-55608
n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode
CVE-2026-14722
TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution
CVE-2026-54335
Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__
CVE-2026-54052
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
CVE-2026-50131
Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
CVE-2026-57481
parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change
CVE-2026-55778
parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
CVE-2026-57480
parse-server: Denial of service via exponential-time processing of deeply nested query operators
CVE-2026-56812
Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
CVE-2022-24785
Path Traversal: 'dir/../../filename' in moment.locale
CVE-2022-31129
Moment.js vulnerable to Inefficient Regular Expression Complexity
CVE-2026-26118
Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network
CVE-2026-45134
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
CVE-2026-41182
LangSmith SDK: Streaming token events bypass output redaction
CVE-2026-25528
LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
CVE-2026-40171
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
CVE-2026-54527
jupyterlab-git extension: Stored XSS leading to RCE
CVE-2026-44721
open-webui Vulnerable to Stored XSS via Model Description
CVE-2026-48779
ws: Memory exhaustion DoS from tiny fragments and data chunks
CVE-2022-36046
Unexpected server crash in Next.js
CVE-2026-56271
Flowise: Weak Default JWT Secrets
CVE-2026-56763
Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
CVE-2026-56354
n8n: Authenticated XSS and Open Redirect via Form Node
GHSA-xrmc-c5cg-rv7x
SafeInstall agent guard shell parsing can miss raw package execution
CVE-2026-10690
DesktopCommanderMCP is vulnerable to SSRF
CVE-2026-10691
DesktopCommanderMCP is vulnerable to Uncontrolled Resource Consumption
CVE-2026-49977
tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies
CVE-2026-49866
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
CVE-2026-5078
morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
CVE-2026-44646
LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`
CVE-2026-44645
LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body
CVE-2026-44644
LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS
CVE-2026-45357
LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)
CVE-2026-45617
LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
CVE-2020-11022
Potential XSS vulnerability in jQuery
CVE-2026-49336
@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter
GHSA-382c-vx95-w3p5
Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
CVE-2026-10291
Claw Orchestrator has inefficient regular expression complexity via validateRegex()
CVE-2026-10281
Claw Orchestrator is missing authentication for the component API Endpoint
CVE-2026-46406
@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
CVE-2026-56778
n8n: Public API Execution Retry Authorization Bypass
CVE-2026-56273
Flowise: Path Traversal in Vector Store basePath
CVE-2026-56775
n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints
CVE-2026-56776
n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
CVE-2026-56360
n8n has Webhook Forgery on Zendesk Trigger Node
CVE-2026-56359
n8n has XSS in its Credential Management Flow
CVE-2026-6402
webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins
CVE-2026-49463
NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries
CVE-2026-49464
NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
CVE-2026-6815
Casdoor: Arbitrary file write possible through Local File System storage provider
CVE-2026-49833
DSpace: Path Traversal is possible through LDN message generation
CVE-2026-49830
DSpace: ORE resource URI does not validate scheme for non-web resources
CVE-2026-10532
Logback vulnerable to Object Injection through HardenedObjectInputStream modules
CVE-2026-49456
Waku has an Open Redirect via `unstable_redirect` Helper
CVE-2026-49455
Waku: Cross-Origin CSRF on RSC Server Action Dispatch
CVE-2026-53649
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
CVE-2026-50197
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
Ready to move
Start Securing
Free, no credit card | First findings in minutes