Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

MEDIUM 5.9
Go

CVE-2026-6815

Casdoor: Arbitrary file write possible through Local File System storage provider

MEDIUM 5.3
Go

CVE-2026-54685

FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel

MEDIUM 5.3
Go

CVE-2026-39835

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

MEDIUM 6.3
Go

CVE-2026-39828

golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions

MEDIUM 5.3
Go

CVE-2026-39882

opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies

MEDIUM 5.3
Go

CVE-2026-41282

Nuclei: Environment variable disclosure via Response-Derived DSL Expressions

MEDIUM 6.8
Go

CVE-2026-12681

Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()

MEDIUM 4.1
Go

CVE-2025-54288

Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server

MEDIUM 6.5
Go

CVE-2025-54287

Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns

MEDIUM 6.8
Go

CVE-2025-54289

Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API

MEDIUM 6.5
Go

CVE-2025-26260

Plenti - Code Injection - Denial of Services

MEDIUM 6.5
Go

CVE-2024-3250

Pebble service manager's file pull API allows access by any user

MEDIUM 4.0
Go

CVE-2024-5138

CVE-2024-5138: snapd snapctl auth bypass

MEDIUM 6.5
Go

CVE-2025-54293

Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function

MEDIUM 5.4
Go

CVE-2026-40922

SiYuan has incomplete fix for CVE-2026-33066: XSS

MEDIUM 5.4
Go

CVE-2023-6152

Email Validation Bypass And Preventing Sign Up From Email's Owner

MEDIUM 5.9
Go

CVE-2023-20902

Harbor timing attack risk

MEDIUM 4.2
Go

CVE-2020-15111

CRLF vulnerability in Fiber

MEDIUM 4.3
Go

CVE-2024-22244

Open Redirect URL in Harbor

MEDIUM 5.3
Go

CVE-2025-11065

go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data

MEDIUM 4.9
Go

CVE-2021-23351

github.com/pires/go-proxyproto denial of service vulnerability

MEDIUM 4.7
Go

CVE-2021-23347

Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd/v2

MEDIUM 5.6
Go

CVE-2021-41087

Improperly Implemented path matching for in-toto-golang

MEDIUM 5.7
Go

CVE-2021-41173

Geth Node Vulnerable to DoS via maliciously crafted p2p message

MEDIUM 6.5
Go

CVE-2022-26652

Arbitrary file write in nats-server

MEDIUM 6.5
Go

CVE-2021-39137

Ethereum Contains Consensus Flaw During Block Processing

MEDIUM 5.9
Go

CVE-2021-21405

BLS Signature "Malleability"

MEDIUM 4.8
Go

CVE-2021-32813

Header dropping in traefik

MEDIUM 4.2
Go

CVE-2021-3911

Misconfigured IP address field in ROA leads to OctoRPKI crash

MEDIUM 6.5
Go

CVE-2020-15091

Denial of Service in TenderMint

MEDIUM 6.1
Go

CVE-2021-29652

pomerium_signature is not verified in middleware in github.com/pomerium/pomerium

MEDIUM 5.3
Go

CVE-2022-41354

Argo CD authenticated but unauthorized users may enumerate Application names via the API

MEDIUM 5.4
Go

CVE-2022-3616

OctoRPKI crashes when max iterations is reached

MEDIUM 6.2
Go

CVE-2023-1410

Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip

MEDIUM 4.9
Go

CVE-2022-31677

Pinniped Supervisor Insufficient Session Expiration vulnerability

MEDIUM 5.3
Go

CVE-2021-41230

OIDC claims not updated from Identity Provider in Pomerium

MEDIUM 5.5
Go

CVE-2021-29136

Improper input validation in umoci

MEDIUM 6.3
Go

CVE-2021-29651

JWT leak via Open Redirect in Programmatic access

MEDIUM 6.5
Go

CVE-2021-41090

Instance config inline secret exposure in Grafana

MEDIUM 4.7
Go

CVE-2021-32721

Open Redirect in github.com/AndrewBurian/powermux

MEDIUM 4.3
Go

CVE-2020-4037

Open Redirect in OAuth2 Proxy

MEDIUM 6.5
Go

CVE-2021-41135

Authz Module Non-Determinism

MEDIUM 6.1
Go

CVE-2021-29622

Arbitrary redirects under /new endpoint

MEDIUM 6.1
Go

CVE-2020-15129

Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header

MEDIUM 4.8
Go

CVE-2022-27652

Incorrect Default Permissions in CRI-O

MEDIUM 5.8
Go

CVE-2020-5300

Authentication Bypass in hydra

MEDIUM 4.3
Go

CVE-2021-43815

Grafana directory traversal for .cvs files

MEDIUM 4.2
Go

CVE-2021-3912

OctoRPKI crashes when processing GZIP bomb returned via malicious repository

MEDIUM 6.3
Go

CVE-2021-32635

Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint

MEDIUM 5.4
Go

CVE-2022-31683

Team scope authorization bypass when Post/Put request with :team_name in body, allows HTTP parameter pollution

MEDIUM 5.5
Go

CVE-2021-21411

OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0

MEDIUM 5.9
Go

CVE-2021-3908

Infinite certificate chain depth results in OctoRPKI running forever

MEDIUM 4.4
Go

CVE-2021-3909

Infinite open connection causes OctoRPKI to hang forever

MEDIUM 5.3
Go

CVE-2021-28681

In github.com/pion/webrtc, failed DTLS certificate verification doesn't stop data channel communication

MEDIUM 6.5
Go

CVE-2021-21303

Improper Neutralization of Special Elements in Output in helm.sh/helm/v3

MEDIUM 6.5
Go

CVE-2021-32699

Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings

MEDIUM 6.5
Go

CVE-2021-22565

Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server

MEDIUM 6.8
Go

CVE-2022-21951

Rancher's weave CNI password is not configured when a cluster is created from an RKE template

MEDIUM 5.4
Go

CVE-2021-41278

Broken encryption in EdgeX Foundry

MEDIUM 5.4
Go

CVE-2021-29456

Authelia allows open redirects on the logout endpoint

Ready to move

Start Securing

Free, no credit card | First findings in minutes