Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-42306
Docker: Race condition in docker cp allows bind mount redirection to host path
CVE-2026-54091
File Browser has incorrect access control for public directory shares via rule path rebasing
CVE-2026-53999
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
CVE-2026-32936
CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
CVE-2026-47701
OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth
CVE-2026-11401
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
CVE-2026-45062
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
CVE-2026-46612
Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives
CVE-2026-47253
Anyquery has Path Traversal through `clear_plugin_cache`, Allowing Arbitrary Directory Deletion
CVE-2026-49396
Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents
CVE-2024-8063
Ollama Divide by Zero Vulnerability
CVE-2025-1975
Ollama Server Vulnerable to Denial of Service (DoS) Attack
GHSA-7qjx-gp9h-65qj
Dex: Token-exchange endpoint is missing AllowedConnectors enforcement
CVE-2025-52903
filebrowser Allows Shell Commands to Spawn Other Commands
CVE-2026-35585
File Browser has a Command Injection via Hook Runner
CVE-2026-52880
klever-go: REST API slow-header connection exhaustion via Gin Engine.Run
CVE-2026-52878
Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt
CVE-2026-52879
klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS
CVE-2026-41567
Docker: `PUT /containers/{id}/archive` executes container binary on the host
CVE-2026-45327
TinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized stream injection
CVE-2026-45686
OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI
CVE-2025-52904
File Browser: Command Execution not Limited to Scope
CVE-2026-47201
authentik's XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user
CVE-2026-45685
OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
CVE-2026-45678
OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads
CVE-2026-39386
Neko has a Self-service Privilege Escalation for Authenticated Users
CVE-2026-46385
iskorotkov/avro: CPU Exhaustion in Decoder
CVE-2026-45627
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover
CVE-2026-46384
iskorotkov/avro: Integer Overflow in Decoder
CVE-2026-47125
Arcane: Missing admin authorization on global variables endpoint
CVE-2026-47179
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives
CVE-2026-48501
GitHub CLI has an incorrect authorization header in API requests to TUF repository mirrors via `gh attestation`, `gh release verify`, and `gh release verify-asset` commands
CVE-2026-41145
MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer Uploads
CVE-2026-44850
Portainer has a bind-mount restriction bypass via HostConfig.Mounts
CVE-2026-44849
Portainer has an endpoint security bypass via Swarm service create/update
CVE-2026-44848
Portainer missing authorization on Docker plugin endpoints, which allows host RCE
CVE-2026-44973
go-billy has path traversal vulnerabilities
CVE-2026-44882
Portainer's Kubernetes middleware continues after token validation failure, bypassing endpoint authorization
CVE-2026-44883
Portainer: JWT accepted in URL query leaks tokens to logs and referers
CVE-2026-44543
Local Path Provisioner Vulnerable to HelperPod Template Injection
CVE-2026-44594
esm.sh: Path Traversal via package.json browser field allows reading arbitrary server files
CVE-2026-44316
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference
CVE-2026-44320
free5GC's NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing path
CVE-2026-44319
free5GC's NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri)
CVE-2026-45152
uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution
CVE-2026-44473
Ella Core Vulnerable to UE Downlink Redirection via Forged PDUSessionResourceSetupResponse
CVE-2026-45089
Dalfox Server Mode has an Unauthenticated Arbitrary File Create/Append via `output` Option
CVE-2026-42459
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information
CVE-2026-44321
free5GC's SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf)
CVE-2026-42083
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI
CVE-2026-45047
Bird-lg-go has a Fatal Out-of-Memory (OOM) Denial of Service via Unbounded JSON Decoding
CVE-2026-45088
Dalfox Server Mode has an Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file`
CVE-2026-44328
free5GC's SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutating
GHSA-m38g-vww2-mvgx
Talos Linux has a local privilege escalation from untrusted workloads
CVE-2026-44322
free5GC's NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereference
CVE-2026-44325
free5GC NRF: type-confusion panic in POST /oauth2/token structured-form parser via Reflect.Set on incompatible types
CVE-2026-45298
Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)
CVE-2026-23998
Fleet has a Windows MDM management endpoint authentication bypass
CVE-2026-24899
Fleet Windows MDM Azure AD JWT Authentication Bypass
CVE-2026-45090
Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode)
Ready to move
Start Securing
Free, no credit card | First findings in minutes