Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-54609
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
CVE-2026-44503
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
CVE-2026-49463
NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries
CVE-2026-49464
NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
CVE-2026-49833
DSpace: Path Traversal is possible through LDN message generation
CVE-2026-49830
DSpace: ORE resource URI does not validate scheme for non-web resources
CVE-2026-10532
Logback vulnerable to Object Injection through HardenedObjectInputStream modules
CVE-2026-49832
DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN
CVE-2026-49831
DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path
CVE-2026-49328
Apache Fesod is vulnerable to Server-Side Request Forgery through its UrlImageConverter component
CVE-2026-49361
Apache Fluss: Unauthenticated remote attackers can exhaust JVM heap memory using crafted frame headers via TabletServer/CoordinatorServer
CVE-2024-52980
Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
CVE-2025-48977
Apache Ignite REST API Has a Relative Path Traversal Vulnerability
CVE-2026-54697
ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing
CVE-2026-54700
ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation
CVE-2022-35278
HTML Injection in ActiveMQ Artemis Web Console
CVE-2022-23913
Apache ActiveMQ Artemis Uncontrolled Resource Consumption (DoS)
CVE-2026-8149
Bouncy Castle LTS native GCM chunking can cause bad-tag exception on decryption
CVE-2026-56784
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
CVE-2024-34517
Neo4j Cypher component mishandles IMMUTABLE privileges
CVE-2024-23688
Discovery uses the same AES/GCM Nonce throughout the session
CVE-2024-23683
Trust Boundary Violation due to Incomplete Blacklist in Test Failure Processing in Ares
CVE-2024-23680
Improper Verification of Cryptographic Signature in aws-encryption-sdk-java
CVE-2024-1143
Central Dogma Authentication Bypass Vulnerability via Session Leakage
CVE-2024-23689
ClickHouse vulnerable to client certificate password exposure in client exception
CVE-2024-23682
Class Loading Vulnerability in Artemis
CVE-2023-24057
MITM based Zip Slip in `org.hl7.fhir.publisher:org.hl7.fhir.publisher`
CVE-2024-23684
Denial of service in CBOR library
CVE-2023-45859
Missing permission checks on Hazelcast client protocol
CVE-2023-45860
Hazelcast Platform permission checking in CSV File Source connector
CVE-2021-26920
Druid ingestion system Authenticated users can read data from other sources than intended
CVE-2024-1735
Armeria SAML authentication bypass due to missing validation on unsigned SAML messages
CVE-2024-23679
com.enonic.xp:lib-auth vulnerable to Session Fixation
CVE-2024-0758
JavaScript execution via malicious molfiles (XSS)
CVE-2020-16164
Vulnerability in RPKI manifest validation
CVE-2020-7611
Micronaut's HTTP client is vulnerable to HTTP Request Header Injection
CVE-2022-25845
Unsafe deserialization in com.alibaba:fastjson
CVE-2024-23686
Insertion of Sensitive Information into Log File in OWASP DependencyCheck
CVE-2020-8908
Information Disclosure in Guava
CVE-2021-23463
Improper Restriction of XML External Entity Reference in com.h2database:h2.
CVE-2022-25647
Deserialization of Untrusted Data in Gson
CVE-2021-29441
Authentication bypass for specific endpoint
CVE-2021-23339
HTTP Request Smuggling in akka-http-core
CVE-2021-21028
Reflected Cross-site Scripting (XSS) in ACS Commons
CVE-2023-50422
Improper JWT Signature Validation in SAP Security Services Library
CVE-2022-25842
Path Traversal in com.alibaba.oneagent:one-java-agent-plugin
CVE-2021-23408
Prototype Pollution in GraphHopper
CVE-2020-7692
Improper Authorization in Google OAuth Client
CVE-2022-36437
Hazelcast connection caching
CVE-2021-29620
XXE vulnerability on Launch import with externally-defined DTD file
CVE-2022-2048
Jetty vulnerable to Invalid HTTP/2 requests that can lead to denial of service
CVE-2022-37423
Neo4j Graph apoc plugins Partial Path Traversal Vulnerability
CVE-2024-23685
Hard-coded System User Credentials in Folio Data Export Spring module
CVE-2021-3827
ECP SAML binding bypasses authentication flows
CVE-2021-39148
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21344
XStream is vulnerable to an Arbitrary Code Execution attack
Ready to move
Start Securing
Free, no credit card | First findings in minutes