Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

39,395 vulnerabilities

HIGH 8.4
NuGet

CVE-2026-100368

CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers

HIGH 8.4
NuGet

CVE-2026-100369

CliInvoke: Argument Injection in Extensibility Runner Factory

UNKNOWN
Maven

CVE-2026-12986

Payara Server Full has a Cross-Site Request Forgery vulnerability

MEDIUM 5.4
Maven

CVE-2026-57305

Jenkins Assembla Plugin has a cross-site request forgery (CSRF) vulnerability

MEDIUM 4.2
Maven

CVE-2026-57306

Jenkins Zowe zDevOps Plugin has a CSRF vulnerability

MEDIUM 4.2
Maven

CVE-2026-57307

Jenkins Zowe zDevOps Plugin has a missing permission check

MEDIUM 5.4
Maven

CVE-2026-57304

Jenkins Assembla Plugin has a missing permission check

HIGH 7.1
Maven

CVE-2026-57303

Jenkins Assembla Plugin has an XXE vulnerability

MEDIUM 4.3
Maven

CVE-2026-57302

Jenkins FitNesse Plugin stores passwords unencrypted

HIGH 7.5
RubyGems

CVE-2026-85396

rubyzip path traversal vulnerability

MEDIUM 4.3
Maven

CVE-2026-57299

Jenkins Contrast Continuous Application Security Plugin missing permission checks

MEDIUM 4.3
Maven

CVE-2026-57300

Jenkins MCP Server Plugin missing a permission check

MEDIUM 5.4
Maven

CVE-2026-57298

Jenkins Contrast Continuous Application Security Plugin has a CSRF vulnerability

MEDIUM 5.4
Maven

CVE-2026-57291

Jenkins Gitee Plugin missing permission checks

HIGH 8.8
Maven

CVE-2026-57301

Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE

MEDIUM 5.4
Maven

CVE-2026-57292

Jenkins Gitee Plugin has a cross-site request forgery vulnerability

MEDIUM 4.8
Maven

CVE-2026-57289

Jenkins Bitbucket Push and Pull Request Plugin unconditionally disables SSL/TLS certificate validation

MEDIUM 4.3
Maven

CVE-2026-57290

Jenkins Priority Sorter Plugin has a CSRF vulnerability

HIGH 8.8
Maven

CVE-2026-57296

Jenkins External Workspace Manager Plugin has a path traversal vulnerability

MEDIUM 4.3
Maven

CVE-2026-57297

Jenkins Contrast Continuous Application Security Plugin has a missing permission check

MEDIUM 5.4
Maven

CVE-2026-57294

Jenkins EC2 Fleet Plugin has a missing permission check

MEDIUM 5.4
Maven

CVE-2026-57295

Jenkins EC2 Fleet Plugin has a cross-site request forgery (CSRF) vulnerability

MEDIUM 4.3
Maven

CVE-2026-57293

Jenkins Gitee Plugin has an incorrect permission check that allows enumerating credentials IDs

LOW 3.7
Maven

CVE-2026-57288

Jenkins Active Directory Plugin has an LDAP injection vulnerability

MEDIUM 5.0
Maven

CVE-2026-57282

Jenkins Git client Plugin has an OS command injection vulnerability on agents

HIGH 7.5
Maven

CVE-2026-57281

Jenkins Script Security Plugin has a script security bypass vulnerability

MEDIUM 4.3
Maven

CVE-2026-57285

Jenkins GitHub Branch Source Plugin has missing permission check that allows enumerating GitHub Enterprise server URLs

MEDIUM 4.3
Maven

CVE-2026-57284

Jenkins Pipeline: Groovy Plugin vulnerable to unrestricted instantiation of types

MEDIUM 4.3
Maven

CVE-2026-57286

Jenkins Git Parameter Plugin has a missing permission check that allows listing SCM branch and tag names

MEDIUM 4.3
Maven

CVE-2026-57287

Jenkins Job Configuration History Plugin doesn't redact encrypted values of secrets in job and agent configurations

HIGH 8.8
Maven

CVE-2026-57280

Jenkins Script Security Plugin sandbox bypass vulnerability

MEDIUM 4.3
Maven

CVE-2026-57283

Jenkins Pipeline: Groovy Plugin has a CSRF vulnerability

MEDIUM 6.8
Maven

CVE-2025-37731

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

MEDIUM 6.5
Maven

CVE-2024-52980

Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

NONE 0.0
NuGet

CVE-2026-56379

ImageMagick: SVG-to-MVG Command Injection via coders/svg.c

NONE 0.0
NuGet

CVE-2026-56371

ImageMagick: Memory leak in coders/txt.c without freetype

LOW 3.7
NuGet

CVE-2026-56376

ImageMagick has a possible heap Use After Free vulnerability in its meta coder

LOW 3.7
NuGet

GHSA-8g9f-ccmr-vfvg

Duplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder

NONE 0.0
NuGet

GHSA-98gv-6gmj-cm6m

Duplicate Advisory: ImageMagick: Memory leak in coders/txt.c without freetype

NONE 0.0
NuGet

GHSA-v772-658q-978p

Duplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c

CRITICAL 9.3
Maven

CVE-2026-61741

http4s-scala-xml has an XML External Entity (XXE) processing issue

HIGH 8.8
Maven

CVE-2026-41862

Spring Statemachine's Kryo-based persistence backends deserialize persisted state-machine contexts without enforcing a class allowlist

CRITICAL 9.1
Maven

CVE-2026-84939

Apache FreeMarker template loading mechanism vulnerable to path traversal

CRITICAL 9.6
Maven

CVE-2026-56120

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

HIGH 8.1
Maven

GHSA-vjr9-f93j-mjr7

Duplicate Advisory: OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

HIGH 7.5
Maven

CVE-2025-14813

Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks

UNKNOWN
Maven

GHSA-jrpc-7vxp-69p6

http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact`

HIGH 8.1
Maven

CVE-2026-54148

http4k: `DigestAuthProvider.verify` did not bind to request URI

CRITICAL 9.6
Maven

CVE-2026-85724

Moquette: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bug

MEDIUM 6.5
PyPI

GHSA-8pcw-h6w9-h46g

plone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length

MEDIUM 6.5
PyPI

CVE-2026-57576

plone.app.dexterity has a Denial of Service due to excessive title or description length

HIGH 7.5
Maven

CVE-2026-61814

Jawn: Quadratic parsing effort in AsyncParser

CRITICAL 9.8
PyPI

CVE-2026-56315

PickleScan has multiple stdlib modules with direct RCE not in blocklist

CRITICAL 9.8
PyPI

GHSA-g7vj-qw6x-g3p8

Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist

HIGH 7.5
Maven

CVE-2026-59990

Jawn: Uncontrolled nesting depth in JSON parser

CRITICAL 9.8
PyPI

CVE-2026-56260

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

UNKNOWN
PyPI

MAL-2026-16475

MemoryOS 2.0.34 was published with a credential-stealing binary

UNKNOWN
PyPI

CVE-2026-93421

Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint

CRITICAL 9.9
RubyGems

CVE-2026-77602

OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites)

HIGH 8.8
RubyGems

CVE-2026-77601

OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting

Ready to move

Start Securing

Free, no credit card | First findings in minutes