Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-54090
File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection
CVE-2026-48096
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
CVE-2026-41568
Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
CVE-2026-42306
Docker: Race condition in docker cp allows bind mount redirection to host path
CVE-2026-54091
File Browser has incorrect access control for public directory shares via rule path rebasing
CVE-2026-54093
File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames
CVE-2026-54092
File Browser has a DoS Vulnerability via Public Login API
CVE-2026-54094
File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
CVE-2026-54097
File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
CVE-2026-46371
Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint
CVE-2026-54096
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
CVE-2026-46370
Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint
CVE-2026-44981
CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression
CVE-2026-53999
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
CVE-2026-47190
IPAM controller service account granted unnecessary full access to Secrets
CVE-2026-32936
CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
GHSA-6vgg-xhvh-38ff
nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store
CVE-2026-48154
gorest InMemorySecret2FA race condition allows process crash via concurrent map access (CWE-362)
CVE-2026-48113
Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData Injection
GHSA-9r4w-jg96-92mv
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
CVE-2025-68121
Unexpected session resumption in crypto/tls
CVE-2026-25679
Incorrect parsing of IPv6 host literals in net/url
CVE-2025-61728
Excessive CPU consumption when building archive index in archive/zip
CVE-2025-61729
Excessive resource consumption when printing error string for host certificate validation in crypto/x509
CVE-2025-61726
Memory exhaustion in query parameter parsing in net/url
CVE-2026-47701
OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth
CVE-2026-11401
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
CVE-2026-48089
DevGuard has improper authorization on public assets
CVE-2026-32934
CoreDNS' DoQ worker pool does not bound stream backlog in github.com/coredns/coredns
CVE-2026-48050
Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS
CVE-2026-46668
SpiceDB: Caveat structures with nested lists can result in improper cache reuse
CVE-2026-48020
Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
CVE-2026-47780
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence
CVE-2026-32280
Unexpected work during chain building in crypto/x509
CVE-2026-47768
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
CVE-2026-47753
Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted)
CVE-2026-48058
nebula-mesh: Session and OIDC state cookies lack the Secure attribute
CVE-2026-46614
Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger
CVE-2026-45062
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
CVE-2026-46612
Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives
CVE-2026-46617
Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read
CVE-2026-46618
Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables
CVE-2026-48025
nebula-mesh: Decrypted CA private key persists in heap after signing
CVE-2026-47253
Anyquery has Path Traversal through `clear_plugin_cache`, Allowing Arbitrary Directory Deletion
CVE-2026-49397
Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
CVE-2026-48031
Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery
CVE-2026-49396
Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents
CVE-2024-8063
Ollama Divide by Zero Vulnerability in github.com/ollama/ollama
CVE-2025-51471
Ollama vulnerable to Cross-Domain Token Exposure in github.com/ollama/ollama
CVE-2025-44779
Ollama allows deletion of arbitrary files in github.com/ollama/ollama
CVE-2025-1975
Ollama Server Vulnerable to Denial of Service (DoS) Attack in github.com/ollama/ollama
CVE-2026-32282
TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix
CVE-2026-32283
Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
CVE-2026-39826
Escaper bypass leads to XSS in html/template
GHSA-7qjx-gp9h-65qj
Dex: Token-exchange endpoint is missing AllowedConnectors enforcement
CVE-2026-39824
Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows
Ready to move
Start Securing
Free, no credit card | First findings in minutes