Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-6815
Casdoor: Arbitrary file write possible through Local File System storage provider
CVE-2026-53649
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
CVE-2026-50197
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
CVE-2026-52831
Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE
CVE-2026-39822
Root escape via symlink plus trailing slash in os
CVE-2026-42505
Invoking Encrypted Client Hello privacy leak in crypto/tls
CVE-2026-40179
Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus
CVE-2026-54685
FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel in github.com/gtsteffaniak/filebrowser/backend
CVE-2025-71261
Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
CVE-2026-39835
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
CVE-2026-42508
golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status
CVE-2026-46595
golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement
CVE-2026-39830
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
CVE-2026-39832
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
CVE-2026-39828
golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions
CVE-2026-39829
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS
GO-2026-5932
The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
CVE-2026-49835
Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality in github.com/sigstore/timestamp-authority
CVE-2026-21728
Grafana Tempo has an Uncontrolled Resource Consumption issue in github.com/grafana/tempo
CVE-2026-41579
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc
CVE-2026-48702
Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic in github.com/sigstore/rekor
CVE-2026-53935
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation in github.com/cilium/cilium
CVE-2026-33811
Crash when handling long CNAME response in net
CVE-2025-21613
Argument Injection via the URL field in github.com/go-git/go-git
CVE-2026-27145
Inefficient candidate hostname parsing in crypto/x509
CVE-2026-39821
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
CVE-2026-25679
Incorrect parsing of IPv6 host literals in net/url
CVE-2026-27018
Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)
CVE-2026-40280
Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
CVE-2026-39882
opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies
CVE-2026-58403
Hugo: Symlink confinement bypass in os.ReadFile
CVE-2026-56395
SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
CVE-2026-7461
Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure in github.com/aws/amazon-ecs-agent
CVE-2026-41282
Nuclei: Environment variable disclosure via Response-Derived DSL Expressions in github.com/projectdiscovery/nuclei
CVE-2026-52800
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover
CVE-2026-45152
uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution
CVE-2026-58404
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
CVE-2026-58402
Hugo: XSS via unescaped code-fence language in default code block renderer
CVE-2026-12681
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation
CVE-2026-42880
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd
CVE-2025-54288
Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
CVE-2025-54287
Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns
CVE-2025-54286
Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI
CVE-2025-54289
Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
CVE-2025-26260
Plenti - Code Injection - Denial of Services
CVE-2024-3250
Pebble service manager's file pull API allows access by any user
CVE-2024-5138
CVE-2024-5138: snapd snapctl auth bypass
CVE-2025-53513
Juju zip slip vulnerability via authenticated endpoint
CVE-2024-5154
malicious container creates symlink "mtab" on the host External
CVE-2025-45286
Reflected XSS in go-httpbin due to unrestricted client control over Content-Type
CVE-2025-54293
Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function
Ready to move
Start Securing
Free, no credit card | First findings in minutes