Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

HIGH 8.6
Maven

CVE-2026-54609

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

UNKNOWN
Maven

CVE-2026-44503

Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect

MEDIUM 6.5
Maven

CVE-2026-49463

NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries

HIGH 8.1
Maven

CVE-2026-49464

NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak

MEDIUM 5.5
Maven

CVE-2026-49833

DSpace: Path Traversal is possible through LDN message generation

MEDIUM 4.4
Maven

CVE-2026-49830

DSpace: ORE resource URI does not validate scheme for non-web resources

UNKNOWN
Maven

CVE-2026-10532

Logback vulnerable to Object Injection through HardenedObjectInputStream modules

HIGH 8.0
Maven

CVE-2026-49832

DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN

MEDIUM 5.5
Maven

CVE-2026-49831

DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path

MEDIUM 5.3
Maven

CVE-2026-49328

Apache Fesod is vulnerable to Server-Side Request Forgery through its UrlImageConverter component

HIGH 7.5
Maven

CVE-2026-49361

Apache Fluss: Unauthenticated remote attackers can exhaust JVM heap memory using crafted frame headers via TabletServer/CoordinatorServer

MEDIUM 6.5
Maven

CVE-2024-52980

Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

MEDIUM 6.5
Maven

CVE-2025-48977

Apache Ignite REST API Has a Relative Path Traversal Vulnerability

UNKNOWN
Maven

CVE-2026-54697

ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing

UNKNOWN
Maven

CVE-2026-54700

ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation

MEDIUM 6.1
Maven

CVE-2022-35278

HTML Injection in ActiveMQ Artemis Web Console

HIGH 7.5
Maven

CVE-2022-23913

Apache ActiveMQ Artemis Uncontrolled Resource Consumption (DoS)

UNKNOWN
Maven

CVE-2026-8149

Bouncy Castle LTS native GCM chunking can cause bad-tag exception on decryption

CRITICAL 9.6
Maven

CVE-2026-56784

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

MEDIUM 6.5
Maven

CVE-2024-34517

Neo4j Cypher component mishandles IMMUTABLE privileges

UNKNOWN
Maven

CVE-2024-23688

Discovery uses the same AES/GCM Nonce throughout the session

HIGH 8.2
Maven

CVE-2024-23683

Trust Boundary Violation due to Incomplete Blacklist in Test Failure Processing in Ares

UNKNOWN
Maven

CVE-2024-23680

Improper Verification of Cryptographic Signature in aws-encryption-sdk-java

CRITICAL 9.3
Maven

CVE-2024-1143

Central Dogma Authentication Bypass Vulnerability via Session Leakage

MEDIUM 4.8
Maven

CVE-2024-23689

ClickHouse vulnerable to client certificate password exposure in client exception

HIGH 8.2
Maven

CVE-2024-23682

Class Loading Vulnerability in Artemis

CRITICAL 9.1
Maven

CVE-2023-24057

MITM based Zip Slip in `org.hl7.fhir.publisher:org.hl7.fhir.publisher`

HIGH 7.5
Maven

CVE-2024-23684

Denial of service in CBOR library

HIGH 7.6
Maven

CVE-2023-45859

Missing permission checks on Hazelcast client protocol

MEDIUM 6.5
Maven

CVE-2023-45860

Hazelcast Platform permission checking in CSV File Source connector

MEDIUM 6.5
Maven

CVE-2021-26920

Druid ingestion system Authenticated users can read data from other sources than intended

CRITICAL 9.1
Maven

CVE-2024-1735

Armeria SAML authentication bypass due to missing validation on unsigned SAML messages

CRITICAL 9.8
Maven

CVE-2024-23679

com.enonic.xp:lib-auth vulnerable to Session Fixation

MEDIUM 6.1
Maven

CVE-2024-0758

JavaScript execution via malicious molfiles (XSS)

UNKNOWN
Maven

CVE-2020-16164

Vulnerability in RPKI manifest validation

CRITICAL 9.8
Maven

CVE-2020-7611

Micronaut's HTTP client is vulnerable to HTTP Request Header Injection

HIGH 8.1
Maven

CVE-2022-25845

Unsafe deserialization in com.alibaba:fastjson

MEDIUM 5.3
Maven

CVE-2024-23686

Insertion of Sensitive Information into Log File in OWASP DependencyCheck

LOW 3.3
Maven

CVE-2020-8908

Information Disclosure in Guava

HIGH 8.1
Maven

CVE-2021-23463

Improper Restriction of XML External Entity Reference in com.h2database:h2.

HIGH 7.7
Maven

CVE-2022-25647

Deserialization of Untrusted Data in Gson

UNKNOWN
Maven

CVE-2021-29441

Authentication bypass for specific endpoint

MEDIUM 6.5
Maven

CVE-2021-23339

HTTP Request Smuggling in akka-http-core

MEDIUM 6.1
Maven

CVE-2021-21028

Reflected Cross-site Scripting (XSS) in ACS Commons

CRITICAL 9.1
Maven

CVE-2023-50422

Improper JWT Signature Validation in SAP Security Services Library

MEDIUM 6.9
Maven

CVE-2022-25842

Path Traversal in com.alibaba.oneagent:one-java-agent-plugin

MEDIUM 5.4
Maven

CVE-2021-23408

Prototype Pollution in GraphHopper

HIGH 7.4
Maven

CVE-2020-7692

Improper Authorization in Google OAuth Client

CRITICAL 9.1
Maven

CVE-2022-36437

Hazelcast connection caching

HIGH 7.5
Maven

CVE-2021-29620

XXE vulnerability on Launch import with externally-defined DTD file

HIGH 7.5
Maven

CVE-2022-2048

Jetty vulnerable to Invalid HTTP/2 requests that can lead to denial of service

UNKNOWN
Maven

CVE-2022-37423

Neo4j Graph apoc plugins Partial Path Traversal Vulnerability

MEDIUM 5.3
Maven

CVE-2024-23685

Hard-coded System User Credentials in Folio Data Export Spring module

HIGH 8.1
Maven

CVE-2021-3827

ECP SAML binding bypasses authentication flows

HIGH 8.5
Maven

CVE-2021-39148

XStream is vulnerable to an Arbitrary Code Execution attack

MEDIUM 5.3
Maven

CVE-2021-21344

XStream is vulnerable to an Arbitrary Code Execution attack

Ready to move

Start Securing

Free, no credit card | First findings in minutes