Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2025-71261
Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
CVE-2026-39829
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS
CVE-2026-7461
Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure
CVE-2026-52800
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover
CVE-2026-45152
uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution
CVE-2025-54286
Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI
CVE-2025-53513
Juju zip slip vulnerability via authenticated endpoint
CVE-2024-5154
malicious container creates symlink "mtab" on the host External
CVE-2023-22648
Rancher's Azure AD permission changes are not reflected on active sessions
CVE-2023-25307
mrpack-install vulnerable to path traversal with dependency
CVE-2024-6984
Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm
CVE-2023-49568
Maliciously crafted Git server replies can cause DoS on go-git clients
CVE-2024-1485
registry-support: decompress can delete files outside scope via relative paths
GHSA-vfvf-6gx5-mqv6
Incorrect Authorization in ORY Oathkeeper
CVE-2022-25856
Insecure path traversal in Git Trigger Source can lead to arbitrary file read
CVE-2020-7711
goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures
CVE-2020-7667
github.com/sassoftware/go-rpmutils Arbitrary File Write via Archive Extraction (Zip Slip)
CVE-2020-26160
Authorization bypass in github.com/dgrijalva/jwt-go
CVE-2022-21221
Path traversal in github.com/valyala/fasthttp
CVE-2020-28466
Denial of service in github.com/nats-io/nats-server/server
CVE-2022-25891
Shoutrrr util package DoS via sending 2000, 4000, or 6000 character messages
CVE-2022-1025
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level
CVE-2022-2529
Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package
CVE-2021-21404
Crash due to malformed relay protocol message
CVE-2022-24348
Path traversal and dereference of symlinks in Argo CD
CVE-2022-27649
Podman's default inheritable capabilities for linux container not empty
CVE-2021-39226
Authentication bypass for viewing and deletions of snapshots
CVE-2021-22538
Privilege escalation in rbac
CVE-2024-1394
Memory leaks in code encrypting and verifying RSA payloads
CVE-2021-21272
Zip slip directory exploit in github.com/deislabs/oras
CVE-2020-8918
TPM 1.2 key authorization values vulnerable to TPM transport eavesdropper in go-tpm
CVE-2021-21403
Authentication Bypass by Primary Weakness in github.com/kongchuanhujiao/server
CVE-2021-43839
Drainage of FeeCollector's Block Transaction Fees in cronos
CVE-2021-21237
Git LFS can execute a Git binary from the current directory on Windows
CVE-2021-41088
Elvish vulnerable to remote code execution via the web UI backend
CVE-2020-15222
Token reuse in Ory fosite
CVE-2022-43760
Rancher UI has multiple Cross-Site Scripting (XSS) issues
CVE-2022-47633
kyverno verifyImages rule bypass possible with malicious proxy/registry
CVE-2021-43816
Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux
CVE-2021-29499
Predictable SIF UUID Identifiers in github.com/sylabs/sif
CVE-2021-3910
NUL character in ROA causes OctoRPKI to crash
CVE-2022-1708
Node DOS by way of memory exhaustion through ExecSync request in CRI-O
CVE-2021-41232
Improper Neutralization of Special Elements used in an LDAP Query in stevenweathers/thunderdome-planning-poker
CVE-2021-21432
Reject unauthorized access with GitHub PATs
CVE-2021-43798
Grafana path traversal
GO-2022-0406
Possible bypass of token claim validation when OAuth2 Introspection caching is enabled
CVE-2023-34758
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability
CVE-2020-13846
"Verify All" Returns Success Despite Validation Failures in Singularity
CVE-2021-3761
OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values
CVE-2022-0811
Code Injection in CRI-O
CVE-2021-29482
github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)
CVE-2021-32783
ExternalName Services can be used to gain access to Envoy's admin interface
CVE-2021-27098
Legacy Node API Allows Impersonation in github.com/spiffe/spire/pkg/server/endpoints/node
CVE-2023-1314
cloudflared's Installer has Local Privilege Escalation Vulnerability
CVE-2021-39183
Unsafe inline XSS in pasting DOM element into chat
CVE-2021-41254
Privilege escalation to cluster admin on multi-tenant environments
CVE-2021-39156
Istio Fragments in Path May Lead to Authorization Policy Bypass
CVE-2021-39155
Authorization Policy Bypass Due to Case Insensitive Host Comparison
Ready to move
Start Securing
Free, no credit card | First findings in minutes