Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-49463
NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries
CVE-2026-49464
NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
CVE-2026-6815
Casdoor: Arbitrary file write possible through Local File System storage provider
CVE-2026-49833
DSpace: Path Traversal is possible through LDN message generation
CVE-2026-49830
DSpace: ORE resource URI does not validate scheme for non-web resources
CVE-2026-10532
Logback vulnerable to Object Injection through HardenedObjectInputStream modules
CVE-2026-49456
Waku has an Open Redirect via `unstable_redirect` Helper
CVE-2026-49455
Waku: Cross-Origin CSRF on RSC Server Action Dispatch
CVE-2026-53649
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
CVE-2026-50197
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
CVE-2026-49832
DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN
CVE-2026-49831
DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path
CVE-2026-49328
Apache Fesod is vulnerable to Server-Side Request Forgery through its UrlImageConverter component
CVE-2026-52831
Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE
CVE-2026-39822
Root escape via symlink plus trailing slash in os
CVE-2026-42505
Invoking Encrypted Client Hello privacy leak in crypto/tls
CVE-2026-49361
Apache Fluss: Unauthenticated remote attackers can exhaust JVM heap memory using crafted frame headers via TabletServer/CoordinatorServer
CVE-2024-52980
Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
CVE-2016-10744
Improper Neutralization of Input During Web Page Generation in Select2
CVE-2024-1899
Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing
GHSA-7wwv-vh3v-89cq
ReDOS vulnerabities: multiple grammars
CVE-2025-48977
Apache Ignite REST API Has a Relative Path Traversal Vulnerability
CVE-2026-53486
Decompress: Archive extraction can create files and links outside of the target directory
CVE-2021-23337
Command Injection in lodash
CVE-2021-23364
Regular Expression Denial of Service in browserslist
CVE-2022-3517
minimatch ReDoS vulnerability
CVE-2021-3803
Inefficient Regular Expression Complexity in nth-check
CVE-2026-40179
Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus
CVE-2026-54685
FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel in github.com/gtsteffaniak/filebrowser/backend
CVE-2026-54697
ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing
CVE-2026-47684
Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP
CVE-2026-54307
n8n: Credential Exfiltration via Permission Bypass
CVE-2026-54700
ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation
CVE-2026-48017
DbGate: Remote Code Execution via functionName injection in loadReader endpoint
CVE-2026-35433
Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability
CVE-2026-42089
yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation
CVE-2026-47200
Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`
CVE-2026-46342
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
CVE-2025-71261
Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
CVE-2022-32511
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
CVE-2026-44587
CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters
CVE-2026-45670
Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)
CVE-2026-45669
Nuxt: Reflected XSS in `navigateTo()` external redirect
CVE-2022-35278
HTML Injection in ActiveMQ Artemis Web Console
CVE-2022-23913
Apache ActiveMQ Artemis Uncontrolled Resource Consumption (DoS)
CVE-2026-39835
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
CVE-2026-42508
golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status
CVE-2026-46595
golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement
CVE-2026-39830
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
CVE-2026-39832
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
CVE-2026-39828
golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions
CVE-2026-39829
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS
GO-2026-5932
The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
CVE-2026-49835
Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality in github.com/sigstore/timestamp-authority
CVE-2026-21728
Grafana Tempo has an Uncontrolled Resource Consumption issue in github.com/grafana/tempo
CVE-2026-41579
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc
CVE-2021-33623
Uncontrolled Resource Consumption in trim-newlines
CVE-2026-48702
Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic in github.com/sigstore/rekor
CVE-2026-53935
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation in github.com/cilium/cilium
Ready to move
Start Securing
Free, no credit card | First findings in minutes