Meet Corgea at Black Hat, BSides Las Vegas & DEF CON

Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

33,384 vulnerabilities

MEDIUM 5.3
npm

CVE-2022-36046

Unexpected server crash in Next.js

MEDIUM 5.6
npm

CVE-2026-56271

Flowise: Weak Default JWT Secrets

MEDIUM 4.8
npm

CVE-2026-56763

Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })

MEDIUM 4.1
npm

CVE-2026-56354

n8n: Authenticated XSS and Open Redirect via Form Node

HIGH 8.8
npm

GHSA-xrmc-c5cg-rv7x

SafeInstall agent guard shell parsing can miss raw package execution

MEDIUM 6.3
npm

CVE-2026-10690

DesktopCommanderMCP is vulnerable to SSRF

MEDIUM 4.3
npm

CVE-2026-10691

DesktopCommanderMCP is vulnerable to Uncontrolled Resource Consumption

MEDIUM 4.3
npm

CVE-2026-49977

tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies

HIGH 7.5
npm

CVE-2026-49866

libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays

MEDIUM 5.3
npm

CVE-2026-5078

morgan vulnerable to Log Forging via unneutralized control characters in :remote-user

MEDIUM 5.3
npm

CVE-2026-44646

LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`

MEDIUM 6.5
npm

CVE-2026-44645

LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body

MEDIUM 6.1
npm

CVE-2026-44644

LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS

HIGH 7.5
npm

CVE-2026-45357

LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)

HIGH 7.5
npm

CVE-2026-45617

LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex

MEDIUM 6.9
npm

CVE-2020-11022

Potential XSS vulnerability in jQuery

UNKNOWN
npm

CVE-2026-49336

@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter

MEDIUM 6.5
npm

GHSA-382c-vx95-w3p5

Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data

MEDIUM 4.3
npm

CVE-2026-10291

Claw Orchestrator has inefficient regular expression complexity via validateRegex()

HIGH 7.3
npm

CVE-2026-10281

Claw Orchestrator is missing authentication for the component API Endpoint

UNKNOWN
npm

CVE-2026-46406

@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write

MEDIUM 6.4
npm

CVE-2026-56778

n8n: Public API Execution Retry Authorization Bypass

UNKNOWN
npm

CVE-2026-56273

Flowise: Path Traversal in Vector Store basePath

MEDIUM 5.4
npm

CVE-2026-56775

n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints

HIGH 7.4
npm

CVE-2026-56776

n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint

MEDIUM 4.0
npm

CVE-2026-56360

n8n has Webhook Forgery on Zendesk Trigger Node

MEDIUM 5.4
npm

CVE-2026-56359

n8n has XSS in its Credential Management Flow

MEDIUM 5.3
npm

CVE-2026-6402

webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins

MEDIUM 6.5
Maven

CVE-2026-49463

NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries

HIGH 8.1
Maven

CVE-2026-49464

NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak

MEDIUM 5.9
Go

CVE-2026-6815

Casdoor: Arbitrary file write possible through Local File System storage provider

MEDIUM 5.5
Maven

CVE-2026-49833

DSpace: Path Traversal is possible through LDN message generation

MEDIUM 4.4
Maven

CVE-2026-49830

DSpace: ORE resource URI does not validate scheme for non-web resources

UNKNOWN
Maven

CVE-2026-10532

Logback vulnerable to Object Injection through HardenedObjectInputStream modules

LOW 3.1
npm

CVE-2026-49456

Waku has an Open Redirect via `unstable_redirect` Helper

MEDIUM 6.5
npm

CVE-2026-49455

Waku: Cross-Origin CSRF on RSC Server Action Dispatch

CRITICAL 9.6
Go

CVE-2026-53649

Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE

CRITICAL 10.0
Go

CVE-2026-50197

Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests

HIGH 8.0
Maven

CVE-2026-49832

DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN

MEDIUM 5.5
Maven

CVE-2026-49831

DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path

MEDIUM 5.3
Maven

CVE-2026-49328

Apache Fesod is vulnerable to Server-Side Request Forgery through its UrlImageConverter component

CRITICAL 10.0
Go

CVE-2026-52831

Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE

UNKNOWN
Go

CVE-2026-39822

Root escape via symlink plus trailing slash in os

UNKNOWN
Go

CVE-2026-42505

Invoking Encrypted Client Hello privacy leak in crypto/tls

HIGH 7.5
Maven

CVE-2026-49361

Apache Fluss: Unauthenticated remote attackers can exhaust JVM heap memory using crafted frame headers via TabletServer/CoordinatorServer

MEDIUM 6.5
Maven

CVE-2024-52980

Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

MEDIUM 6.1
npm

CVE-2016-10744

Improper Neutralization of Input During Web Page Generation in Select2

MEDIUM 5.3
npm

CVE-2024-1899

Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing

UNKNOWN
npm

GHSA-7wwv-vh3v-89cq

ReDOS vulnerabities: multiple grammars

MEDIUM 6.5
Maven

CVE-2025-48977

Apache Ignite REST API Has a Relative Path Traversal Vulnerability

CRITICAL 9.1
npm

CVE-2026-53486

Decompress: Archive extraction can create files and links outside of the target directory

HIGH 7.2
npm

CVE-2021-23337

Command Injection in lodash

MEDIUM 5.3
npm

CVE-2021-23364

Regular Expression Denial of Service in browserslist

HIGH 7.5
npm

CVE-2022-3517

minimatch ReDoS vulnerability

HIGH 7.5
npm

CVE-2021-3803

Inefficient Regular Expression Complexity in nth-check

UNKNOWN
Go

CVE-2026-40179

Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus

UNKNOWN
Go

CVE-2026-54685

FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel in github.com/gtsteffaniak/filebrowser/backend

UNKNOWN
Maven

CVE-2026-54697

ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing

HIGH 7.7
npm

CVE-2026-47684

Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP

Ready to move

Start Securing

Free, no credit card | First findings in minutes