Meet Corgea at Black Hat, BSides Las Vegas & DEF CON

Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

33,391 vulnerabilities

HIGH 8.2
npm

CVE-2026-58500

appium-mcp: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)

CRITICAL 10.0
npm

CVE-2026-59801

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

MEDIUM 4.3
npm

CVE-2026-10802

Keystone: GraphQL API Endpoint Lacks Query Depth Limits

MEDIUM 4.2
npm

CVE-2026-55608

n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode

CRITICAL 9.6
npm

CVE-2026-14722

TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution

LOW 3.7
npm

CVE-2026-54335

Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__

CRITICAL 9.9
npm

CVE-2026-54052

n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments

HIGH 8.6
npm

CVE-2026-50131

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

UNKNOWN
npm

CVE-2026-57481

parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change

UNKNOWN
npm

CVE-2026-55778

parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist

UNKNOWN
npm

CVE-2026-57480

parse-server: Denial of service via exponential-time processing of deeply nested query operators

UNKNOWN
Hex

CVE-2026-56812

Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff

HIGH 7.5
npm

CVE-2022-24785

Path Traversal: 'dir/../../filename' in moment.locale

HIGH 7.5
npm

CVE-2022-31129

Moment.js vulnerable to Inefficient Regular Expression Complexity

HIGH 8.8
NuGet

CVE-2026-26118

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

HIGH 7.1
PyPI

CVE-2026-45134

LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning

MEDIUM 5.3
npm

CVE-2026-41182

LangSmith SDK: Streaming token events bypass output redaction

MEDIUM 5.8
PyPI

CVE-2026-25528

LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection

UNKNOWN
npm

CVE-2026-40171

Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS

UNKNOWN
PyPI

CVE-2026-54527

jupyterlab-git extension: Stored XSS leading to RCE

HIGH 7.3
npm

CVE-2026-44721

open-webui Vulnerable to Stored XSS via Model Description

HIGH 7.5
npm

CVE-2026-48779

ws: Memory exhaustion DoS from tiny fragments and data chunks

MEDIUM 5.3
npm

CVE-2022-36046

Unexpected server crash in Next.js

MEDIUM 5.6
npm

CVE-2026-56271

Flowise: Weak Default JWT Secrets

MEDIUM 4.8
npm

CVE-2026-56763

Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })

MEDIUM 4.1
npm

CVE-2026-56354

n8n: Authenticated XSS and Open Redirect via Form Node

HIGH 8.8
npm

GHSA-xrmc-c5cg-rv7x

SafeInstall agent guard shell parsing can miss raw package execution

MEDIUM 6.3
npm

CVE-2026-10690

DesktopCommanderMCP is vulnerable to SSRF

MEDIUM 4.3
npm

CVE-2026-10691

DesktopCommanderMCP is vulnerable to Uncontrolled Resource Consumption

MEDIUM 4.3
npm

CVE-2026-49977

tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies

HIGH 7.5
npm

CVE-2026-49866

libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays

MEDIUM 5.3
npm

CVE-2026-5078

morgan vulnerable to Log Forging via unneutralized control characters in :remote-user

MEDIUM 5.3
npm

CVE-2026-44646

LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`

MEDIUM 6.5
npm

CVE-2026-44645

LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body

MEDIUM 6.1
npm

CVE-2026-44644

LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS

HIGH 7.5
npm

CVE-2026-45357

LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)

HIGH 7.5
npm

CVE-2026-45617

LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex

MEDIUM 6.9
npm

CVE-2020-11022

Potential XSS vulnerability in jQuery

UNKNOWN
npm

CVE-2026-49336

@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter

MEDIUM 6.5
npm

GHSA-382c-vx95-w3p5

Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data

MEDIUM 4.3
npm

CVE-2026-10291

Claw Orchestrator has inefficient regular expression complexity via validateRegex()

HIGH 7.3
npm

CVE-2026-10281

Claw Orchestrator is missing authentication for the component API Endpoint

UNKNOWN
npm

CVE-2026-46406

@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write

MEDIUM 6.4
npm

CVE-2026-56778

n8n: Public API Execution Retry Authorization Bypass

UNKNOWN
npm

CVE-2026-56273

Flowise: Path Traversal in Vector Store basePath

MEDIUM 5.4
npm

CVE-2026-56775

n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints

HIGH 7.4
npm

CVE-2026-56776

n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint

MEDIUM 4.0
npm

CVE-2026-56360

n8n has Webhook Forgery on Zendesk Trigger Node

MEDIUM 5.4
npm

CVE-2026-56359

n8n has XSS in its Credential Management Flow

MEDIUM 5.3
npm

CVE-2026-6402

webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins

MEDIUM 6.5
Maven

CVE-2026-49463

NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries

HIGH 8.1
Maven

CVE-2026-49464

NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak

MEDIUM 5.9
Go

CVE-2026-6815

Casdoor: Arbitrary file write possible through Local File System storage provider

MEDIUM 5.5
Maven

CVE-2026-49833

DSpace: Path Traversal is possible through LDN message generation

MEDIUM 4.4
Maven

CVE-2026-49830

DSpace: ORE resource URI does not validate scheme for non-web resources

UNKNOWN
Maven

CVE-2026-10532

Logback vulnerable to Object Injection through HardenedObjectInputStream modules

LOW 3.1
npm

CVE-2026-49456

Waku has an Open Redirect via `unstable_redirect` Helper

MEDIUM 6.5
npm

CVE-2026-49455

Waku: Cross-Origin CSRF on RSC Server Action Dispatch

CRITICAL 9.6
Go

CVE-2026-53649

Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE

CRITICAL 10.0
Go

CVE-2026-50197

Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests

Ready to move

Start Securing

Free, no credit card | First findings in minutes