Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2025-71426
Contrast's unauthenticated recovery allows Coordinator impersonation
CVE-2025-71423
Contrast leaks workload secrets to logs on INFO level
CVE-2025-71425
Contrast workload secrets leak to logs on INFO level
CVE-2026-100838
Contras Affected by CopyFile Policy Subversion via Symlinks
CVE-2026-100839
Contrast BadAML injection allows arbitrary code execution
CVE-2026-65838
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
CVE-2026-84195
Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak)
CVE-2026-84196
Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF
CVE-2026-57231
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
CVE-2026-85057
ZITADEL: Actions V1 sandbox escape: host file read via require()
CVE-2026-85056
ZITADEL: MFA bypass via session reuse in Login V2
CVE-2026-58314
Gitea: Two SSRF findings
CVE-2026-34966
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2026-86065
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)
CVE-2026-86064
Klever-Go: /log controls global node logging
CVE-2026-77633
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service
CVE-2026-76819
Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability
CVE-2026-62182
KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes
CVE-2026-62369
KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join
CVE-2026-62371
KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API
CVE-2026-77560
Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for
CVE-2026-77322
SIPGO: DoS via unvalidated WebSocket frame length
CVE-2026-58268
SIPGO: DoS via unvalidated Content-Length in the stream parser
CVE-2023-54365
Traefik vulnerable to HTTP/2 request causing denial of service
GHSA-pvrg-q6jw-42p7
Duplicate Advisory: Traefik vulnerable to HTTP/2 request causing denial of service
CVE-2026-42127
Grafana: Pre-authentication denial of service in the public dashboard query handler
CVE-2026-9029
Grafana geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug
CVE-2026-42129
Grafana Loki datasource plugin's callResource handler contains a path traversal vulnerability.
CVE-2026-61628
nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition
CVE-2026-61629
nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware
CVE-2026-61687
Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState
CVE-2026-53714
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode
CVE-2026-88045
rclone: S3 multipart declared-length memory exhaustion
GHSA-xwmw-prc4-v3cr
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
GHSA-jgh3-fggc-mcpm
Obot: Server-Side Request Forgery via remote MCP server URL
CVE-2026-58197
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
CVE-2026-61672
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement
CVE-2026-61833
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion
CVE-2026-82399
CoreDNS: Unauthenticated memory exhaustion in custom transports
CVE-2026-86003
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP
GO-2026-6449
Komari: Management Interface CSRF
CVE-2026-59172
Joker linter executed project-local .jokerd/linter.* files during linting
CVE-2026-59185
Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
CVE-2026-88017
rclone: FTP cross-session auth-proxy backend confusion
CVE-2026-56668
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
CVE-2026-85731
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)
CVE-2026-86043
Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)
CVE-2026-63443
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
CVE-2026-61554
emp3r0r has an unauthenticated HTTP Polling DoS
CVE-2026-55108
KubeVela Terraform remote loader DoS via unbounded file read
CVE-2026-72789
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked
CVE-2026-68587
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check
CVE-2026-27660
Gitea draft releases and attachments are exposed without write permission
CVE-2026-72810
SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)
CVE-2026-27779
Gitea forwarded-proto validation allows canonical URL spoofing
CVE-2026-59832
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db
CVE-2026-72795
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
CVE-2026-72809
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy
CVE-2026-73232
ffuf denial of service (OOM) via HTTP response decompression bomb
CVE-2026-72801
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
Ready to move
Start Securing
Free, no credit card | First findings in minutes