Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-79743
MCPHub has Path Traversal via Malicious MCPB Manifest Name
CVE-2026-82864
PDFME Affected by Decompression Bomb in FlateDecode Stream Parsing Causes Memory Exhaustion DoS
CVE-2026-82660
Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization
CVE-2024-58379
nodemailer ReDoS when trying to send a specially crafted email
CVE-2026-82662
Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
CVE-2026-82855
@hulumi/policies: Stack-wide evidence bypassed Cloudflare and deployment-governance guardrails
CVE-2026-82661
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
CVE-2026-82865
PDFME has XSS via Unsanitized i18n Label Injection into innerHTML in multiVariableText propPanel
CVE-2026-82867
Cross-Site Scripting (XSS) via Select Schema Option Value Injection in @pdfme/schemas
CVE-2026-82856
@hulumi/policies: GitHub OIDC trust policy bypass via AWS set-qualified condition operators
CVE-2026-82860
@hulumi/policies: CIS 1.16 admin policy bypass for inline and attached IAM policies
CVE-2026-82866
PDFME has SSRF via Unvalidated URL Fetch in `getB64BasePdf` When `basePdf` Is Attacker-Controlled
CVE-2026-82853
Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)
CVE-2026-82854
Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter
CVE-2026-82861
@hulumi/policies: HULUMI-H1 SecureBucket parent spoof bypass
CVE-2026-82858
@hulumi/drift: Orphan reconciler accepted externally supplied execute plans
CVE-2026-82863
@hulumi/baseline: CloudTrail selector tampering events were not fully detected
CVE-2026-82868
Cross-Site Scripting (XSS) via SVG Schema innerHTML Injection in @pdfme/schemas
CVE-2026-59724
Socket.IO: Engine.IO WebTransport SID DoS
CVE-2026-81888
@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking
CVE-2026-13676
fast-uri vulnerable to host confusion via failed IDN canonicalization
CVE-2026-2391
qs's arrayLimit bypass in comma parsing allows denial of service
CVE-2026-56326
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
CVE-2026-9496
pacote is vulnerable to Denial of Service (DoS) via the addGitSha function
CVE-2026-82258
@sveltejs/kit: `query.batch` cross-talk
CVE-2026-82256
SvelteKit: Big remote form function payloads can cause Node process to crash
CVE-2026-82257
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
CVE-2026-82259
SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)
CVE-2026-55641
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
CVE-2026-55638
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
CVE-2026-53832
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
GHSA-35c7-4r45-9gv3
Duplicate Advisory: OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
GHSA-chqm-wxm2-w73w
Duplicate Advisory: OpenClaw: Mattermost handlers could fall open when channel type was missing
CVE-2026-53834
OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
CVE-2026-53837
OpenClaw: Mattermost handlers could fall open when channel type was missing
GHSA-3qg8-hq7j-jj33
Duplicate Advisory: OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
CVE-2026-55697
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
CVE-2026-73650
SVGO removeScripts plugin leaves some executable scripts intact
CVE-2026-53833
OpenClaw: QQBot streaming command could mutate config without explicit allowFrom
GHSA-r27j-fxmq-rg2q
Duplicate Advisory: OpenClaw: QQBot streaming command could mutate config without explicit allowFrom
CVE-2026-54156
node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS
CVE-2026-54732
libreoffice-convert vulnerable to path traversal / arbitrary file write
CVE-2026-54687
n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)
CVE-2026-73412
Shescape: Path disclosure on Unix with Zsh
CVE-2026-54606
SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed
CVE-2026-50880
YouTransfer has an issue in the sendmail transport integration that allows arbitrary code execution
CVE-2026-54511
@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys
CVE-2026-54356
Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`
CVE-2025-27597
Vue I18n Allows Prototype Pollution in `handleFlatJson`
GHSA-c85p-9pvr-f7f5
Duplicate Advisory: OpenClaw: Node pairing reconnection could confuse approval scope state
CVE-2026-55604
@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
CVE-2026-55605
@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint
CVE-2026-55663
mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
CVE-2026-53838
OpenClaw: Node pairing reconnection could confuse approval scope state
GHSA-gwcq-453v-2frr
Duplicate Advisory: OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
CVE-2026-53831
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
GHSA-ffhm-8fwq-7q27
Duplicate Advisory: OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
CVE-2026-53836
OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
CVE-2026-2366
Keycloak vulnerable to authorization bypass via the Admin API
CVE-2026-55609
consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write
Ready to move
Start Securing
Free, no credit card | First findings in minutes