Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-53649
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
CVE-2026-50197
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
CVE-2026-52831
Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE
CVE-2026-42508
golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status
CVE-2026-46595
golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement
CVE-2026-39830
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
CVE-2026-39832
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
CVE-2026-40280
Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
CVE-2026-42880
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
CVE-2023-22647
Rancher vulnerable to Privilege Escalation via manipulation of Secrets
CVE-2023-49569
Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
CVE-2023-3128
Grafana vulnerable to Authentication Bypass by Spoofing
CVE-2021-23365
Authentication Bypass in tyk-identity-broker
CVE-2020-26290
Critical security issues in XML encoding in github.com/dexidp/dex
CVE-2023-50422
Improper Privilege Management in github.com/sap/cloud-security-client-go
CVE-2022-1025
Improper access control allows admin privilege escalation in Argo CD
CVE-2021-41244
Grafana Fine-grained access control vulnerability
CVE-2021-36782
Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials
CVE-2021-28955
Arbitrary code execution due to an uncontrolled search path for the git binary
CVE-2022-31247
Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
CVE-2021-36783
Rancher doesn't properly sanitize credentials in cluster template answers
CVE-2022-31836
Path Traversal in Beego
CVE-2021-32637
Authelia vulnerable to an authentication bypassed with malformed request URI on nginx
CVE-2022-31259
Access control bypass in beego
CVE-2023-22651
Rancher Webhook is misconfigured during upgrade process
CVE-2026-41328
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
CVE-2026-53552
Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers
CVE-2026-48752
Incus has arbitrary file read+write on host via templates/ symlink in malicious image
CVE-2026-48750
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image
CVE-2026-48749
Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image
CVE-2026-48755
Incus has an argument injection in backup compression algorithm leading to AFW and ACE
CVE-2026-48751
Incus has a restricted project bypass leading to arbitrary command execution
CVE-2026-48769
Incus has an arbitrary file write on its client due to trusted image hash
CVE-2025-66719
Free5gc NRF is vulnerable to scope validation bypass via maliciously crafted targetNF value
CVE-2026-48753
Incus has an arbitrary file write via path traversal in S3 multipart upload
CVE-2026-41589
Wish has SCP Path Traversal that allows arbitrary file read/write
GO-2026-5821
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
CVE-2026-7374
KubeVirt has a Link Following vulnerability
CVE-2026-50545
Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover
CVE-2026-50563
Fission Container Executor Function PodSpec Injection Leading to Node Escape
CVE-2026-53519
Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
CVE-2026-50564
Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape
CVE-2026-9098
Casdoor SAML callback handler accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequest
CVE-2026-44939
Rancher vulnerable to command injection through unsanitized YAML parameter
CVE-2026-9090
Casdoor has an authentication bypass
CVE-2026-9097
Casdoor doesn't verify that a JWT used for token exchange is still active
CVE-2026-49445
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
CVE-2026-44935
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
CVE-2026-50566
Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation
CVE-2026-9093
Casdoor does not validate the AudienceRestriction element in SAML assertions
CVE-2026-39834
golang.org/x/crypto vulnerable to infinite loop on large channel writes
CVE-2026-39833
golang.org/x/crypto doesn't enforce invoking key constraints
CVE-2026-39831
golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed
CVE-2024-23827
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature
CVE-2026-26190
Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise
CVE-2020-36645
Squalor SQL Injection vulnerability
CVE-2025-8077
NeuVector admin account has insecure default password
CVE-2024-22036
Rancher Remote Code Execution via Cluster/Node Drivers
Ready to move
Start Securing
Free, no credit card | First findings in minutes