Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2022-36046
Unexpected server crash in Next.js
CVE-2026-56271
Flowise: Weak Default JWT Secrets
CVE-2026-56763
Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
CVE-2026-56354
n8n: Authenticated XSS and Open Redirect via Form Node
GHSA-xrmc-c5cg-rv7x
SafeInstall agent guard shell parsing can miss raw package execution
CVE-2026-10690
DesktopCommanderMCP is vulnerable to SSRF
CVE-2026-10691
DesktopCommanderMCP is vulnerable to Uncontrolled Resource Consumption
CVE-2026-49977
tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies
CVE-2026-49866
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
CVE-2026-5078
morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
CVE-2026-44646
LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`
CVE-2026-44645
LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body
CVE-2026-44644
LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS
CVE-2026-45357
LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)
CVE-2026-45617
LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
CVE-2020-11022
Potential XSS vulnerability in jQuery
CVE-2026-49336
@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter
GHSA-382c-vx95-w3p5
Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
CVE-2026-10291
Claw Orchestrator has inefficient regular expression complexity via validateRegex()
CVE-2026-10281
Claw Orchestrator is missing authentication for the component API Endpoint
CVE-2026-46406
@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
CVE-2026-56778
n8n: Public API Execution Retry Authorization Bypass
CVE-2026-56273
Flowise: Path Traversal in Vector Store basePath
CVE-2026-56775
n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints
CVE-2026-56776
n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
CVE-2026-56360
n8n has Webhook Forgery on Zendesk Trigger Node
CVE-2026-56359
n8n has XSS in its Credential Management Flow
CVE-2026-6402
webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins
CVE-2026-49463
NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries
CVE-2026-49464
NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
CVE-2026-6815
Casdoor: Arbitrary file write possible through Local File System storage provider
CVE-2026-49833
DSpace: Path Traversal is possible through LDN message generation
CVE-2026-49830
DSpace: ORE resource URI does not validate scheme for non-web resources
CVE-2026-10532
Logback vulnerable to Object Injection through HardenedObjectInputStream modules
CVE-2026-49456
Waku has an Open Redirect via `unstable_redirect` Helper
CVE-2026-49455
Waku: Cross-Origin CSRF on RSC Server Action Dispatch
CVE-2026-53649
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
CVE-2026-50197
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
CVE-2026-49832
DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN
CVE-2026-49831
DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path
CVE-2026-49328
Apache Fesod is vulnerable to Server-Side Request Forgery through its UrlImageConverter component
CVE-2026-52831
Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE
CVE-2026-39822
Root escape via symlink plus trailing slash in os
CVE-2026-42505
Invoking Encrypted Client Hello privacy leak in crypto/tls
CVE-2026-49361
Apache Fluss: Unauthenticated remote attackers can exhaust JVM heap memory using crafted frame headers via TabletServer/CoordinatorServer
CVE-2024-52980
Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
CVE-2016-10744
Improper Neutralization of Input During Web Page Generation in Select2
CVE-2024-1899
Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing
GHSA-7wwv-vh3v-89cq
ReDOS vulnerabities: multiple grammars
CVE-2025-48977
Apache Ignite REST API Has a Relative Path Traversal Vulnerability
CVE-2026-53486
Decompress: Archive extraction can create files and links outside of the target directory
CVE-2021-23337
Command Injection in lodash
CVE-2021-23364
Regular Expression Denial of Service in browserslist
CVE-2022-3517
minimatch ReDoS vulnerability
CVE-2021-3803
Inefficient Regular Expression Complexity in nth-check
CVE-2026-40179
Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus
CVE-2026-54685
FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel in github.com/gtsteffaniak/filebrowser/backend
CVE-2026-54697
ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing
CVE-2026-47684
Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP
Ready to move
Start Securing
Free, no credit card | First findings in minutes