Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-45591
Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability
CVE-2026-48522
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
CVE-2026-48523
PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys
CVE-2026-48526
PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
CVE-2026-48525
PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
CVE-2026-48524
PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
CVE-2020-13932
Cross-site Scripting (XSS) in Apache ActiveMQ Artemis
CVE-2025-3000
PyTorch is vulnerable to memory corruption through its torch.jit.script function
CVE-2020-29367
CVE-2020-29367
CVE-2026-48155
pypdf: Possible large memory usage for large offsets for layout mode text
CVE-2026-48156
pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams
CVE-2026-49854
Tornado has out-of-bounds memory access via C extension
CVE-2026-46373
SQLFluff: Recursive Stack Overflow in Parser
CVE-2026-46374
SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser
CVE-2026-49818
CVE-2026-49818
CVE-2026-53441
Jenkins: Stored XSS vulnerability in node offline cause description
CVE-2026-48710
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
CVE-2026-46557
ImageMagick: Stack overflow in fx operation
CVE-2026-48006
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
CVE-2026-54090
File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection
CVE-2026-48059
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
CVE-2026-48049
@hapi/inert has a static-file confinement bypass via sibling-prefix path
CVE-2026-48096
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
CVE-2026-45013
Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation
CVE-2026-47248
Parse Server's GraphQL "Did you mean ...?" validation suggestions disclose schema to unauthenticated callers
CVE-2026-45011
Apostrophe has stored XSS via javascript: URL in Image Widget Link
CVE-2026-47138
Parse Server: Pre-authentication denial of service via client version header regex backtracking
CVE-2026-42890
actual Allows Electron to Run As Node
CVE-2026-44990
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
CVE-2026-50287
@agenticmail/mcp Missing Authentication for Critical Function
CVE-2026-41568
Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
CVE-2026-42306
Docker: Race condition in docker cp allows bind mount redirection to host path
CVE-2026-42853
@apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input
CVE-2026-45012
Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget
CVE-2026-41731
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
CVE-2026-41726
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
CVE-2026-54091
File Browser has incorrect access control for public directory shares via rule path rebasing
CVE-2026-54093
File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames
CVE-2026-54092
File Browser has a DoS Vulnerability via Public Login API
CVE-2026-54094
File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
CVE-2026-48022
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
CVE-2026-54097
File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
CVE-2026-47140
NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
CVE-2026-46371
Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint
CVE-2026-54096
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
CVE-2026-44311
Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
GHSA-ch3q-cw5r-f4hg
ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation
GHSA-vc8p-8pxg-rfwg
ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing
CVE-2026-46370
Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint
CVE-2026-47430
Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.
CVE-2026-47131
vm2 has a Sandbox Escape issue
CVE-2026-47210
vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
CVE-2026-47208
vm2 is Vulnerable to Sandbox Breakout Through Promise Species
CVE-2026-47137
vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE
CVE-2026-44981
CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression
CVE-2023-45648
Apache Tomcat Improper Input Validation vulnerability
CVE-2026-53999
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
GHSA-gv7w-rqvm-qjhr
esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY
Ready to move
Start Securing
Free, no credit card | First findings in minutes