Meet Corgea at Black Hat, BSides Las Vegas & DEF CON

Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

33,375 vulnerabilities

MEDIUM 6.5
Maven

CVE-2026-49463

NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries

HIGH 8.1
Maven

CVE-2026-49464

NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak

MEDIUM 5.9
Go

CVE-2026-6815

Casdoor: Arbitrary file write possible through Local File System storage provider

MEDIUM 5.5
Maven

CVE-2026-49833

DSpace: Path Traversal is possible through LDN message generation

MEDIUM 4.4
Maven

CVE-2026-49830

DSpace: ORE resource URI does not validate scheme for non-web resources

UNKNOWN
Maven

CVE-2026-10532

Logback vulnerable to Object Injection through HardenedObjectInputStream modules

LOW 3.1
npm

CVE-2026-49456

Waku has an Open Redirect via `unstable_redirect` Helper

MEDIUM 6.5
npm

CVE-2026-49455

Waku: Cross-Origin CSRF on RSC Server Action Dispatch

CRITICAL 9.6
Go

CVE-2026-53649

Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE

CRITICAL 10.0
Go

CVE-2026-50197

Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests

HIGH 8.0
Maven

CVE-2026-49832

DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN

MEDIUM 5.5
Maven

CVE-2026-49831

DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path

MEDIUM 5.3
Maven

CVE-2026-49328

Apache Fesod is vulnerable to Server-Side Request Forgery through its UrlImageConverter component

CRITICAL 10.0
Go

CVE-2026-52831

Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE

UNKNOWN
Go

CVE-2026-39822

Root escape via symlink plus trailing slash in os

UNKNOWN
Go

CVE-2026-42505

Invoking Encrypted Client Hello privacy leak in crypto/tls

HIGH 7.5
Maven

CVE-2026-49361

Apache Fluss: Unauthenticated remote attackers can exhaust JVM heap memory using crafted frame headers via TabletServer/CoordinatorServer

MEDIUM 6.5
Maven

CVE-2024-52980

Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

MEDIUM 6.1
npm

CVE-2016-10744

Improper Neutralization of Input During Web Page Generation in Select2

MEDIUM 5.3
npm

CVE-2024-1899

Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing

UNKNOWN
npm

GHSA-7wwv-vh3v-89cq

ReDOS vulnerabities: multiple grammars

MEDIUM 6.5
Maven

CVE-2025-48977

Apache Ignite REST API Has a Relative Path Traversal Vulnerability

CRITICAL 9.1
npm

CVE-2026-53486

Decompress: Archive extraction can create files and links outside of the target directory

HIGH 7.2
npm

CVE-2021-23337

Command Injection in lodash

MEDIUM 5.3
npm

CVE-2021-23364

Regular Expression Denial of Service in browserslist

HIGH 7.5
npm

CVE-2022-3517

minimatch ReDoS vulnerability

HIGH 7.5
npm

CVE-2021-3803

Inefficient Regular Expression Complexity in nth-check

UNKNOWN
Go

CVE-2026-40179

Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus

UNKNOWN
Go

CVE-2026-54685

FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel in github.com/gtsteffaniak/filebrowser/backend

UNKNOWN
Maven

CVE-2026-54697

ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing

HIGH 7.7
npm

CVE-2026-47684

Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP

CRITICAL 9.6
npm

CVE-2026-54307

n8n: Credential Exfiltration via Permission Bypass

UNKNOWN
Maven

CVE-2026-54700

ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation

HIGH 8.8
npm

CVE-2026-48017

DbGate: Remote Code Execution via functionName injection in loadReader endpoint

HIGH 7.3
NuGet

CVE-2026-35433

Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability

HIGH 8.6
npm

CVE-2026-42089

yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation

MEDIUM 5.3
npm

CVE-2026-47200

Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`

MEDIUM 5.4
npm

CVE-2026-46342

Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning

HIGH 8.6
Go

CVE-2025-71261

Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS

CRITICAL 9.8
RubyGems

CVE-2022-32511

JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable

MEDIUM 4.7
RubyGems

CVE-2026-44587

CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters

MEDIUM 5.4
npm

CVE-2026-45670

Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)

MEDIUM 5.4
npm

CVE-2026-45669

Nuxt: Reflected XSS in `navigateTo()` external redirect

MEDIUM 6.1
Maven

CVE-2022-35278

HTML Injection in ActiveMQ Artemis Web Console

HIGH 7.5
Maven

CVE-2022-23913

Apache ActiveMQ Artemis Uncontrolled Resource Consumption (DoS)

MEDIUM 5.3
Go

CVE-2026-39835

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

CRITICAL 9.1
Go

CVE-2026-42508

golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status

CRITICAL 10.0
Go

CVE-2026-46595

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

CRITICAL 9.1
Go

CVE-2026-39830

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

CRITICAL 9.1
Go

CVE-2026-39832

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

MEDIUM 6.3
Go

CVE-2026-39828

golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions

HIGH 7.5
Go

CVE-2026-39829

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

UNKNOWN
Go

GO-2026-5932

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

UNKNOWN
Go

CVE-2026-49835

Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality in github.com/sigstore/timestamp-authority

UNKNOWN
Go

CVE-2026-21728

Grafana Tempo has an Uncontrolled Resource Consumption issue in github.com/grafana/tempo

UNKNOWN
Go

CVE-2026-41579

Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc

HIGH 7.5
npm

CVE-2021-33623

Uncontrolled Resource Consumption in trim-newlines

UNKNOWN
Go

CVE-2026-48702

Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic in github.com/sigstore/rekor

UNKNOWN
Go

CVE-2026-53935

CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation in github.com/cilium/cilium

Ready to move

Start Securing

Free, no credit card | First findings in minutes