Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2024-22261
SQL Injection in Harbor scan log API
CVE-2021-41190
Clarify Content-Type handling
CVE-2020-5303
Denial of service in Tendermint
CVE-2020-15184
Aliases are never checked in helm
CVE-2020-15186
Improper Sanitizing of plugin names in helm
CVE-2020-15185
Repository index file allows for duplicates of the same chart entry in helm
CVE-2021-41089
`docker cp` allows unexpected chmod of host files in Moby Docker Engine
CVE-2020-15187
plugin.yaml file allows for duplicate entries in helm
CVE-2020-4053
Plugin archive directory traversal in Helm
CVE-2020-15106
Panic due to malformed WALs in go.etcd.io/etcd
CVE-2026-41579
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
GO-2026-5865
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries
CVE-2026-49245
SFTPGo has stored XSS via inline parameter on public shares and user file download
GO-2024-3059
CosmWasm wasmd has large address count in ValidateBasic
CVE-2025-30163
Cilium node based network policies may incorrectly allow workload traffic
CVE-2024-6219
lxd has a restricted TLS certificate privilege escalation when in PKI mode
GO-2026-5441
OpenTofu has unbounded memory usage, high CPU usage, or deadlock in "tofu init" with maliciously-crafted dependency responses
GO-2026-5614
arnika is affected by medium-severity issues in UDP rotation, PQC handling, and KMS TLS
GO-2026-5558
OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server
CVE-2026-29051
melange has Path Traversal via .PKGINFO in --persist-lint-results
CVE-2026-6334
Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow
CVE-2026-4053
Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields
CVE-2026-21388
Mattermost MS Teams plugin doesn't limit the request body size on the /lifecycle webhook endpoint
CVE-2026-3495
Mattermost doesn't escape some variables that could contain malicious content during error page composition
CVE-2026-40263
Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel
CVE-2026-27769
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace
CVE-2026-4273
Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation
CVE-2026-40109
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering
CVE-2026-44474
Ella Core has handover failures during concurrent Security Mode Command
CVE-2026-39396
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVE-2026-42082
Free5GC AMF has Missing Concurrent NAS SMC Validation During NGAP Handover
CVE-2026-6333
Mattermost doesn't validate the Host header when constructing response URLs for custom slash command
CVE-2026-34762
Ella Core Has Audit Log Falsification via Path/Body IMSI Mismatch in UpdateSubscriber
CVE-2026-5468
Casdoor vulnerable to Stored XSS via Application formCss / formSideHtml
CVE-2026-4286
Mattermost doesn't check if {{team_id}} was being changed when updating playbooks
CVE-2026-41263
Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middleware
CVE-2026-45803
GitHub CLI: GitHub Actions log output in `gh run view` allows terminal escape sequence injection
CVE-2026-39388
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
CVE-2026-40243
Incus has an OVN TLS Verification that Accepts Peer-Supplied Roots
CVE-2026-40097
Step CA affected by an index out of bounds panic in TPM attestation EKU validation
CVE-2026-34454
OAuth2 Proxy's session cookies are not cleared when rendering sign-in page
CVE-2026-48709
OliveTin: ValidateArgumentType API Endpoint's Missing Authentication Allows Action and Argument Enumeration
CVE-2026-45723
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic
CVE-2026-45683
OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure
CVE-2026-8275
bettercap Has an Integer Coercion Error in the ippReadChunkedBody Function
CVE-2026-52796
Gogs has DoS in rendering issue index pattern
CVE-2026-55866
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected
CVE-2026-40077
Beszel has an IDOR in hub API endpoints that read system ID from URL parameter
CVE-2026-24513
ingress-nginx has Improper Check for Unusual or Exceptional Conditions
CVE-2024-7598
Kubernetes kube-apiserver Vulnerable to Race Condition
CVE-2026-30963
Capsule Namespace Hijacking via subresource
CVE-2026-24122
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped
CVE-2020-8562
Potential proxy IP restriction bypass in Kubernetes
CVE-2021-25740
Confused Deputy in Kubernetes
CVE-2023-30464
CoreDNS Cache Poisoning via a birthday attack
CVE-2026-45781
MCP Registry: OCI validator skips ownership check on upstream rate limits
CVE-2026-8276
bettercap Has an Integer Coercion Error in modules/mysql_server/mysql_server.go
GO-2024-2703
Kopia: Storage connection credentials written to console on "repository status" CLI command with JSON output
CVE-2020-8912
In-band key negotiation issue in AWS S3 Crypto SDK for golang
CVE-2026-33762
go-git missing validation decoding Index v4 files leads to panic
Ready to move
Start Securing
Free, no credit card | First findings in minutes