Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2025-71424
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points
CVE-2026-100837
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries
CVE-2026-79783
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
CVE-2026-79782
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
CVE-2026-79777
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
CVE-2026-77637
Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope
CVE-2026-84298
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher
CVE-2026-8823
Mattermost has an Incorrect Authorization issue
CVE-2026-88013
rclone: http backend forwards custom/auth headers to a different host on redirect
CVE-2025-24978
LF Edge eKuiper: Self-XSS in External Service Creation
CVE-2026-8074
Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
GO-2026-6265
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
GO-2026-6262
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers
CVE-2026-54787
sigstore-go fails to check signature timestamps against a signing key's validity period
CVE-2026-10722
ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader
CVE-2026-41579
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
CVE-2026-45781
MCP Registry: OCI validator skips ownership check on upstream rate limits
CVE-2026-39396
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVE-2026-74797
OpenTofu has High CPU usage in "tofu init" with maliciously-crafted module packages in .zip format
CVE-2025-27538
Mattermost Missing Authentication for Critical Function
CVE-2025-24839
Mattermost Incorrect Authorization vulnerability
CVE-2025-46327
Go Snowflake Driver has race condition when checking access to Easy Logging configuration file
CVE-2025-22445
Mattermost has Improper Check for Unusual or Exceptional Conditions
GO-2026-5558
OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server
CVE-2026-39388
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
CVE-2026-33762
go-git missing validation decoding Index v4 files leads to panic
CVE-2026-24122
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped
CVE-2026-24513
ingress-nginx has Improper Check for Unusual or Exceptional Conditions
CVE-2025-67860
NeuVector scanner insecurely handles passwords as command arguments
GO-2025-4101
OpenTofu affected denials of service in "tofu init" with maliciously-crafted module package responses
CVE-2025-65942
VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM
CVE-2025-6011
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users
CVE-2025-54410
Moby firewalld reload removes bridge network isolation
CVE-2025-4563
kubernetes allows nodes to bypass dynamic resource allocation authorization checks
CVE-2025-4656
Vault Community Edition rekey and recovery key operations can cause denial of service
CVE-2025-1088
Grafana long dashboard title or panel name causes unresponsives
CVE-2025-52996
File Browser's password protection of links is bypassable
CVE-2025-8556
CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
CVE-2025-41423
Mattermost Playbooks fails to properly validate permissions
CVE-2025-31363
Mattermost doesn't restrict domains LLM can request to contact upstream
CVE-2024-7598
Kubernetes kube-apiserver Vulnerable to Race Condition
CVE-2025-29923
go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment
CVE-2025-22449
Mattermost Incorrect Authorization vulnerability
CVE-2024-51491
notation-go has an OS error when setting CRL cache leads to denial of signature verification
CVE-2024-51744
Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations
CVE-2024-10214
Mattermost incorrectly issues two sessions when using desktop SSO
CVE-2024-10452
Grafana org admin can delete pending invites in different org
CVE-2024-45395
sigstore-go has an unbounded loop over untrusted input can lead to endless data attack
CVE-2024-45310
runc can be confused to create empty files/directories on the host
CVE-2023-30464
CoreDNS Cache Poisoning via a birthday attack
CVE-2021-41089
`docker cp` allows unexpected chmod of host files in Moby Docker Engine
CVE-2024-32873
evmos allows transferring unvested tokens after delegations
CVE-2024-38361
SpiceDB exclusions can result in no permission returned when permission expected
CVE-2024-34713
sshproxy vulnerable to SSH option injection
CVE-2024-34079
octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usage
CVE-2024-21848
Mattermost Server Improper Access Control
CVE-2024-3177
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin
CVE-2024-32001
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used
CVE-2024-35232
github.com/huandu/facebook may expose access_token in error message.
GO-2024-2703
Kopia: Storage connection credentials written to console on "repository status" CLI command with JSON output
Ready to move
Start Securing
Free, no credit card | First findings in minutes