Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2020-13932
Cross-site Scripting (XSS) in Apache ActiveMQ Artemis
CVE-2026-53441
Jenkins: Stored XSS vulnerability in node offline cause description
CVE-2026-48006
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
CVE-2026-48059
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
CVE-2026-41731
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
CVE-2026-41726
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
GHSA-ch3q-cw5r-f4hg
ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation
GHSA-vc8p-8pxg-rfwg
ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing
CVE-2023-45648
Apache Tomcat Improper Input Validation vulnerability
CVE-2023-42795
Apache Tomcat Incomplete Cleanup vulnerability
CVE-2025-66614
Apache Tomcat - Client certificate verification bypass
CVE-2026-45536
Netty: Unix-socket fd receive leaks descriptors when peer sends two at once
CVE-2026-45416
Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
CVE-2026-45673
Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
CVE-2026-44893
Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length
CVE-2026-44894
Netty's Default QUIC token handler accepts any client-supplied token
CVE-2026-46340
Netty: SCTP reassembly nests buffers without bound
CVE-2026-47244
Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
CVE-2026-45674
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
CVE-2026-47691
Netty has Insufficient Bailiwick Validation for NS Records
CVE-2026-48043
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
CVE-2026-44892
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
CVE-2026-44250
Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
CVE-2026-44890
Netty has Unbounded Direct Memory Consumption in its RedisDecoder
CVE-2026-44249
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
GHSA-j9gf-vw2f-9hrw
Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation
GHSA-9wcp-79g5-5c3c
Appsmith Super User Creation Race Condition Allows Multiple Instance Administrators
CVE-2025-58175
GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
CVE-2025-52465
GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
CVE-2025-27511
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
CVE-2026-9087
Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromise
CVE-2026-40982
Spring Cloud Config vulnerable to Path Traversal
CVE-2026-40981
Spring Cloud Config has an Authorization Bypass Through User-Controlled Key
CVE-2020-13935
Infinite Loop in Apache Tomcat
CVE-2020-11996
Uncontrolled Resource Consumption in Apache Tomcat
CVE-2026-42568
Yamcs Vulnerable to LDAP Injection in LdapAuthModule
CVE-2026-48040
netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access
CVE-2026-28367
Undertow is Vulnerable to HTTP Request/Response Smuggling
CVE-2026-8922
Keycloak: Revoked Tokens Can Remain Active When Both Realm-Level and Client-Level `notBefore` Revocation Policies are Configured
CVE-2026-8830
Keycloak: Policy bypass during WebAuthn credential registration via client-side JavaScript manipulation
CVE-2026-28369
Undertow is Vulnerable to HTTP Request/Response Smuggling
CVE-2026-28368
Undertow is Vulnerable to HTTP Request/Response Smuggling
CVE-2026-7500
Keycloak has a Forced Browsing issue
CVE-2025-53114
Acknowledgement extension out of memory
CVE-2026-34237
MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)
CVE-2026-45581
fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode
CVE-2026-46481
OpenMetadata: TEST_CONNECTION workflow leaks ingestion-bot JWT and database password to regular users
CVE-2022-33891
Apache Spark UI can allow impersonation if ACLs enabled
CVE-2023-32007
Apache Spark UI vulnerable to Command Injection
CVE-2022-43766
Apache IoTDB subject to ReDOS with Java 8
CVE-2026-0707
Keycloak has Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
CVE-2026-45300
async-http-client: Cookie header not stripped on cross-origin redirect
CVE-2026-41207
netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures
CVE-2026-33728
dd-trace-java: Unsafe deserialization in RMI instrumentation may lead to remote code execution
CVE-2026-45609
Spring AI MCP Security: Unvalidated URL Fetching (SSRF)
CVE-2021-44832
Improper Input Validation and Injection in Apache Log4j2
CVE-2020-9488
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender
CVE-2024-55875
http4k has a potential XXE (XML External Entity Injection) vulnerability
CVE-2021-45105
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
CVE-2019-17571
Deserialization of Untrusted Data in Log4j
Ready to move
Start Securing
Free, no credit card | First findings in minutes