Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

39,806 vulnerabilities

UNKNOWN
Go

CVE-2026-100836

Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2025-71422

Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2025-71426

Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2025-71424

Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2025-71423

Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2025-71425

Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2026-100838

Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2026-100837

Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2026-100839

Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast

HIGH 8.4
NuGet

CVE-2026-100368

CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers

HIGH 8.4
NuGet

CVE-2026-100369

CliInvoke: Argument Injection in Extensibility Runner Factory

UNKNOWN
Maven

CVE-2026-12986

Payara Server Full has a Cross-Site Request Forgery vulnerability

MEDIUM 5.4
Maven

CVE-2026-57305

Jenkins Assembla Plugin has a cross-site request forgery (CSRF) vulnerability

MEDIUM 4.2
Maven

CVE-2026-57306

Jenkins Zowe zDevOps Plugin has a CSRF vulnerability

MEDIUM 4.2
Maven

CVE-2026-57307

Jenkins Zowe zDevOps Plugin has a missing permission check

MEDIUM 5.4
Maven

CVE-2026-57304

Jenkins Assembla Plugin has a missing permission check

HIGH 7.1
Maven

CVE-2026-57303

Jenkins Assembla Plugin has an XXE vulnerability

MEDIUM 4.3
Maven

CVE-2026-57302

Jenkins FitNesse Plugin stores passwords unencrypted

HIGH 7.5
RubyGems

CVE-2026-85396

rubyzip path traversal vulnerability

UNKNOWN
Go

CVE-2026-53493

Containerd has image-pull DoS via crafted OCI index graph amplification

MEDIUM 4.3
Maven

CVE-2026-57299

Jenkins Contrast Continuous Application Security Plugin missing permission checks

MEDIUM 4.3
Maven

CVE-2026-57300

Jenkins MCP Server Plugin missing a permission check

MEDIUM 5.4
Maven

CVE-2026-57298

Jenkins Contrast Continuous Application Security Plugin has a CSRF vulnerability

MEDIUM 5.4
Maven

CVE-2026-57291

Jenkins Gitee Plugin missing permission checks

HIGH 8.8
Maven

CVE-2026-57301

Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE

MEDIUM 5.4
Maven

CVE-2026-57292

Jenkins Gitee Plugin has a cross-site request forgery vulnerability

MEDIUM 4.8
Maven

CVE-2026-57289

Jenkins Bitbucket Push and Pull Request Plugin unconditionally disables SSL/TLS certificate validation

MEDIUM 4.3
Maven

CVE-2026-57290

Jenkins Priority Sorter Plugin has a CSRF vulnerability

HIGH 8.8
Maven

CVE-2026-57296

Jenkins External Workspace Manager Plugin has a path traversal vulnerability

MEDIUM 4.3
Maven

CVE-2026-57297

Jenkins Contrast Continuous Application Security Plugin has a missing permission check

MEDIUM 5.4
Maven

CVE-2026-57294

Jenkins EC2 Fleet Plugin has a missing permission check

MEDIUM 5.4
Maven

CVE-2026-57295

Jenkins EC2 Fleet Plugin has a cross-site request forgery (CSRF) vulnerability

MEDIUM 4.3
Maven

CVE-2026-57293

Jenkins Gitee Plugin has an incorrect permission check that allows enumerating credentials IDs

LOW 3.7
Maven

CVE-2026-57288

Jenkins Active Directory Plugin has an LDAP injection vulnerability

MEDIUM 5.0
Maven

CVE-2026-57282

Jenkins Git client Plugin has an OS command injection vulnerability on agents

HIGH 7.5
Maven

CVE-2026-57281

Jenkins Script Security Plugin has a script security bypass vulnerability

MEDIUM 4.3
Maven

CVE-2026-57285

Jenkins GitHub Branch Source Plugin has missing permission check that allows enumerating GitHub Enterprise server URLs

MEDIUM 4.3
Maven

CVE-2026-57284

Jenkins Pipeline: Groovy Plugin vulnerable to unrestricted instantiation of types

MEDIUM 4.3
Maven

CVE-2026-57286

Jenkins Git Parameter Plugin has a missing permission check that allows listing SCM branch and tag names

MEDIUM 4.3
Maven

CVE-2026-57287

Jenkins Job Configuration History Plugin doesn't redact encrypted values of secrets in job and agent configurations

HIGH 8.8
Maven

CVE-2026-57280

Jenkins Script Security Plugin sandbox bypass vulnerability

MEDIUM 4.3
Maven

CVE-2026-57283

Jenkins Pipeline: Groovy Plugin has a CSRF vulnerability

UNKNOWN
Go

CVE-2026-84445

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

MEDIUM 6.8
Maven

CVE-2025-37731

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

MEDIUM 6.5
Maven

CVE-2024-52980

Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

HIGH 8.2
Go

CVE-2026-65838

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies

MEDIUM 5.3
Go

CVE-2026-79778

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

MEDIUM 5.3
Go

CVE-2026-79779

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

UNKNOWN
Go

CVE-2026-40575

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing in github.com/oauth2-proxy/oauth2-proxy

Ready to move

Start Securing

Free, no credit card | First findings in minutes