Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-40575
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
CVE-2026-84200
Bypassing Kyverno Policies via Double Policy Exceptions
CVE-2026-12249
Canonical ADSys Uses a Less Trusted Source
CVE-2026-53713
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure
CVE-2026-88044
rclone: RC per-server auth-proxy bypass
CVE-2026-61682
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
CVE-2026-88018
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
CVE-2026-71485
Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends
CVE-2026-39830
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
GHSA-24r3-p3x6-cqvx
Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
CVE-2026-72920
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
CVE-2026-27780
Gitea pre-receive hook scanner errors allow branch-protection bypass
CVE-2026-73843
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
CVE-2026-60004
Gitea: Remote Code Execution via diffpatch Git Hook Installation
CVE-2026-69084
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
CVE-2026-73842
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
CVE-2026-11720
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints
CVE-2026-26292
Gitea LFS mirror operations bypass migration HTTP transport protections
CVE-2026-69083
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB
CVE-2026-73294
Semaphore U: OS Command Injection
CVE-2026-72811
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
CVE-2026-7482
Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader
CVE-2026-41328
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
CVE-2026-41492
Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
CVE-2025-41118
Pyroscope Exposes Storage Secret
CVE-2026-40173
Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
CVE-2025-8077
NeuVector admin account has insecure default password
CVE-2025-49136
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user
CVE-2025-32445
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR
CVE-2025-1974
ingress-nginx admission controller RCE escalation
CVE-2024-45337
Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto
CVE-2026-54061
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import
CVE-2026-73501
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
CVE-2026-54680
Logging operator has Fluentd configuration injection that allows remote code execution
CVE-2026-44939
Rancher vulnerable to command injection through unsanitized YAML parameter
CVE-2026-46595
golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement
GO-2026-5709
Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag
CVE-2026-39834
golang.org/x/crypto vulnerable to infinite loop on large channel writes
CVE-2026-49980
Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix
CVE-2026-39833
golang.org/x/crypto doesn't enforce invoking key constraints
CVE-2026-50195
containerd: CRI checkpoint import allows local image tag poisoning
CVE-2026-39832
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
CVE-2026-53622
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
CVE-2026-39831
golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed
CVE-2026-42508
golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status
CVE-2026-7374
KubeVirt has a Link Following vulnerability
CVE-2026-44477
CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE
CVE-2026-42880
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
CVE-2026-33815
pgx contains memory-safety vulnerability
CVE-2026-34976
Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
CVE-2026-41327
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
CVE-2026-41179
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
CVE-2026-33816
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVE-2026-41176
Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
CVE-2026-30836
step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)
CVE-2026-33186
gRPC-Go has an authorization bypass via missing leading slash in :path
CVE-2026-33211
Path traversal in Tekton Pipelines git resolver allows reading arbitrary files from the resolver pod
CVE-2026-33032
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
CVE-2021-25320
Rancher cloud credentials can be used through proxy API by users without access
CVE-2026-22039
Kyverno Cross-Namespace Privilege Escalation via Policy apiCall
Ready to move
Start Securing
Free, no credit card | First findings in minutes