Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-6815
Casdoor: Arbitrary file write possible through Local File System storage provider
CVE-2026-54685
FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel
CVE-2026-39835
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
CVE-2026-39828
golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions
CVE-2026-39882
opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies
CVE-2026-41282
Nuclei: Environment variable disclosure via Response-Derived DSL Expressions
CVE-2026-12681
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
CVE-2025-54288
Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
CVE-2025-54287
Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns
CVE-2025-54289
Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
CVE-2025-26260
Plenti - Code Injection - Denial of Services
CVE-2024-3250
Pebble service manager's file pull API allows access by any user
CVE-2024-5138
CVE-2024-5138: snapd snapctl auth bypass
CVE-2025-54293
Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function
CVE-2026-40922
SiYuan has incomplete fix for CVE-2026-33066: XSS
CVE-2023-6152
Email Validation Bypass And Preventing Sign Up From Email's Owner
CVE-2023-20902
Harbor timing attack risk
CVE-2020-15111
CRLF vulnerability in Fiber
CVE-2024-22244
Open Redirect URL in Harbor
CVE-2025-11065
go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data
CVE-2021-23351
github.com/pires/go-proxyproto denial of service vulnerability
CVE-2021-23347
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd/v2
CVE-2021-41087
Improperly Implemented path matching for in-toto-golang
CVE-2021-41173
Geth Node Vulnerable to DoS via maliciously crafted p2p message
CVE-2022-26652
Arbitrary file write in nats-server
CVE-2021-39137
Ethereum Contains Consensus Flaw During Block Processing
CVE-2021-21405
BLS Signature "Malleability"
CVE-2021-32813
Header dropping in traefik
CVE-2021-3911
Misconfigured IP address field in ROA leads to OctoRPKI crash
CVE-2020-15091
Denial of Service in TenderMint
CVE-2021-29652
pomerium_signature is not verified in middleware in github.com/pomerium/pomerium
CVE-2022-41354
Argo CD authenticated but unauthorized users may enumerate Application names via the API
CVE-2022-3616
OctoRPKI crashes when max iterations is reached
CVE-2023-1410
Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip
CVE-2022-31677
Pinniped Supervisor Insufficient Session Expiration vulnerability
CVE-2021-41230
OIDC claims not updated from Identity Provider in Pomerium
CVE-2021-29136
Improper input validation in umoci
CVE-2021-29651
JWT leak via Open Redirect in Programmatic access
CVE-2021-41090
Instance config inline secret exposure in Grafana
CVE-2021-32721
Open Redirect in github.com/AndrewBurian/powermux
CVE-2020-4037
Open Redirect in OAuth2 Proxy
CVE-2021-41135
Authz Module Non-Determinism
CVE-2021-29622
Arbitrary redirects under /new endpoint
CVE-2020-15129
Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header
CVE-2022-27652
Incorrect Default Permissions in CRI-O
CVE-2020-5300
Authentication Bypass in hydra
CVE-2021-43815
Grafana directory traversal for .cvs files
CVE-2021-3912
OctoRPKI crashes when processing GZIP bomb returned via malicious repository
CVE-2021-32635
Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint
CVE-2022-31683
Team scope authorization bypass when Post/Put request with :team_name in body, allows HTTP parameter pollution
CVE-2021-21411
OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0
CVE-2021-3908
Infinite certificate chain depth results in OctoRPKI running forever
CVE-2021-3909
Infinite open connection causes OctoRPKI to hang forever
CVE-2021-28681
In github.com/pion/webrtc, failed DTLS certificate verification doesn't stop data channel communication
CVE-2021-21303
Improper Neutralization of Special Elements in Output in helm.sh/helm/v3
CVE-2021-32699
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings
CVE-2021-22565
Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server
CVE-2022-21951
Rancher's weave CNI password is not configured when a cluster is created from an RKE template
CVE-2021-41278
Broken encryption in EdgeX Foundry
CVE-2021-29456
Authelia allows open redirects on the logout endpoint
Ready to move
Start Securing
Free, no credit card | First findings in minutes