Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

UNKNOWN
Maven

CVE-2026-12986

Payara Server Full has a Cross-Site Request Forgery vulnerability

MEDIUM 5.4
Maven

CVE-2026-57305

Jenkins Assembla Plugin has a cross-site request forgery (CSRF) vulnerability

MEDIUM 4.2
Maven

CVE-2026-57306

Jenkins Zowe zDevOps Plugin has a CSRF vulnerability

MEDIUM 4.2
Maven

CVE-2026-57307

Jenkins Zowe zDevOps Plugin has a missing permission check

MEDIUM 5.4
Maven

CVE-2026-57304

Jenkins Assembla Plugin has a missing permission check

HIGH 7.1
Maven

CVE-2026-57303

Jenkins Assembla Plugin has an XXE vulnerability

MEDIUM 4.3
Maven

CVE-2026-57302

Jenkins FitNesse Plugin stores passwords unencrypted

MEDIUM 4.3
Maven

CVE-2026-57299

Jenkins Contrast Continuous Application Security Plugin missing permission checks

MEDIUM 4.3
Maven

CVE-2026-57300

Jenkins MCP Server Plugin missing a permission check

MEDIUM 5.4
Maven

CVE-2026-57298

Jenkins Contrast Continuous Application Security Plugin has a CSRF vulnerability

MEDIUM 5.4
Maven

CVE-2026-57291

Jenkins Gitee Plugin missing permission checks

HIGH 8.8
Maven

CVE-2026-57301

Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE

MEDIUM 5.4
Maven

CVE-2026-57292

Jenkins Gitee Plugin has a cross-site request forgery vulnerability

MEDIUM 4.8
Maven

CVE-2026-57289

Jenkins Bitbucket Push and Pull Request Plugin unconditionally disables SSL/TLS certificate validation

MEDIUM 4.3
Maven

CVE-2026-57290

Jenkins Priority Sorter Plugin has a CSRF vulnerability

HIGH 8.8
Maven

CVE-2026-57296

Jenkins External Workspace Manager Plugin has a path traversal vulnerability

MEDIUM 4.3
Maven

CVE-2026-57297

Jenkins Contrast Continuous Application Security Plugin has a missing permission check

MEDIUM 5.4
Maven

CVE-2026-57294

Jenkins EC2 Fleet Plugin has a missing permission check

MEDIUM 5.4
Maven

CVE-2026-57295

Jenkins EC2 Fleet Plugin has a cross-site request forgery (CSRF) vulnerability

MEDIUM 4.3
Maven

CVE-2026-57293

Jenkins Gitee Plugin has an incorrect permission check that allows enumerating credentials IDs

LOW 3.7
Maven

CVE-2026-57288

Jenkins Active Directory Plugin has an LDAP injection vulnerability

MEDIUM 5.0
Maven

CVE-2026-57282

Jenkins Git client Plugin has an OS command injection vulnerability on agents

HIGH 7.5
Maven

CVE-2026-57281

Jenkins Script Security Plugin has a script security bypass vulnerability

MEDIUM 4.3
Maven

CVE-2026-57285

Jenkins GitHub Branch Source Plugin has missing permission check that allows enumerating GitHub Enterprise server URLs

MEDIUM 4.3
Maven

CVE-2026-57284

Jenkins Pipeline: Groovy Plugin vulnerable to unrestricted instantiation of types

MEDIUM 4.3
Maven

CVE-2026-57286

Jenkins Git Parameter Plugin has a missing permission check that allows listing SCM branch and tag names

MEDIUM 4.3
Maven

CVE-2026-57287

Jenkins Job Configuration History Plugin doesn't redact encrypted values of secrets in job and agent configurations

HIGH 8.8
Maven

CVE-2026-57280

Jenkins Script Security Plugin sandbox bypass vulnerability

MEDIUM 4.3
Maven

CVE-2026-57283

Jenkins Pipeline: Groovy Plugin has a CSRF vulnerability

MEDIUM 6.8
Maven

CVE-2025-37731

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

MEDIUM 6.5
Maven

CVE-2024-52980

Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

CRITICAL 9.3
Maven

CVE-2026-61741

http4s-scala-xml has an XML External Entity (XXE) processing issue

HIGH 8.8
Maven

CVE-2026-41862

Spring Statemachine's Kryo-based persistence backends deserialize persisted state-machine contexts without enforcing a class allowlist

CRITICAL 9.1
Maven

CVE-2026-84939

Apache FreeMarker template loading mechanism vulnerable to path traversal

CRITICAL 9.6
Maven

CVE-2026-56120

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

HIGH 8.1
Maven

GHSA-vjr9-f93j-mjr7

Duplicate Advisory: OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

HIGH 7.5
Maven

CVE-2025-14813

Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks

UNKNOWN
Maven

GHSA-jrpc-7vxp-69p6

http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact`

HIGH 8.1
Maven

CVE-2026-54148

http4k: `DigestAuthProvider.verify` did not bind to request URI

CRITICAL 9.6
Maven

CVE-2026-85724

Moquette: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bug

HIGH 7.5
Maven

CVE-2026-61814

Jawn: Quadratic parsing effort in AsyncParser

HIGH 7.5
Maven

CVE-2026-59990

Jawn: Uncontrolled nesting depth in JSON parser

HIGH 7.5
Maven

CVE-2026-77422

JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping

MEDIUM 6.5
Maven

CVE-2026-77421

JLine: ReDoS in Nano Editor Regex Search Mode

MEDIUM 5.5
Maven

CVE-2026-77420

JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable

MEDIUM 6.3
Maven

CVE-2026-69190

Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards

HIGH 7.5
Maven

CVE-2026-61570

MPXJ: XXE Vulnerability in MerlinReader

HIGH 7.5
Maven

CVE-2026-85058

io.moquette:moquette-broker has a Missing Authorization issue

UNKNOWN
Maven

CVE-2026-13505

Bouncy Castle: Zeroisation of sensitive key material on garbage collection relies on finalization.

CRITICAL 9.1
Maven

CVE-2026-8763

Bouncy Castle: Name Constraints bypass via trailing dot in rfc822Name and URI

HIGH 7.5
Maven

CVE-2026-13506

Bouncy Castle: Lazy ASN.1 sequence forcing resets nesting-depth guard

UNKNOWN
Maven

CVE-2026-8798

Bouncy Castle: the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound

HIGH 7.5
Maven

CVE-2026-48059

Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion

HIGH 7.5
Maven

CVE-2026-48006

Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator

HIGH 8.7
Maven

CVE-2026-45674

Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records

HIGH 8.7
Maven

CVE-2026-47691

Netty has Insufficient Bailiwick Validation for NS Records

MEDIUM 5.3
Maven

CVE-2026-48043

netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion

CRITICAL 9.9
Maven

CVE-2025-53837

org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue

HIGH 8.7
Maven

CVE-2026-77615

Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text

HIGH 7.5
Maven

CVE-2026-81876

HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service

Ready to move

Start Securing

Free, no credit card | First findings in minutes