Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

CRITICAL 9.3
Maven

CVE-2026-61741

http4s-scala-xml has an XML External Entity (XXE) processing issue

CRITICAL 9.1
Maven

CVE-2026-84939

Apache FreeMarker template loading mechanism vulnerable to path traversal

CRITICAL 9.6
Maven

CVE-2026-56120

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

CRITICAL 9.6
Maven

CVE-2026-85724

Moquette: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bug

CRITICAL 9.1
Maven

CVE-2026-8763

Bouncy Castle: Name Constraints bypass via trailing dot in rfc822Name and URI

CRITICAL 9.9
Maven

CVE-2025-53837

org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue

CRITICAL 9.8
Maven

CVE-2026-65905

Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability

CRITICAL 9.1
Maven

CVE-2025-66614

Apache Tomcat - Client certificate verification bypass

CRITICAL 9.1
Maven

CVE-2026-65182

Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability

CRITICAL 9.1
Maven

CVE-2026-68525

Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability

CRITICAL 9.8
Maven

CVE-2026-43512

Apache Tomcat - Digest authenticator will authenticate any unknown user

CRITICAL 9.1
Maven

CVE-2026-43515

Apache Tomcat - Security constraints not correctly applied

CRITICAL 9.0
Maven

CVE-2026-16723

fastjson has a remote code execution (RCE) vulnerability

CRITICAL 9.8
Maven

CVE-2026-47065

Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass

CRITICAL 9.1
Maven

CVE-2026-33117

Security feature bypass vulnerability in Azure Key Vault Keys library for Java

CRITICAL 9.8
Maven

CVE-2026-42778

Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41409 Incomplete Fix)

CRITICAL 9.1
Maven

CVE-2026-2586

GlassFish's Administration Console is Vulnerable to RCE

CRITICAL 9.9
Maven

CVE-2026-32604

Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths

CRITICAL 9.1
Maven

CVE-2026-29145

Apache Tomcat: CLIENT_CERT authentication does not fail as expected

CRITICAL 9.1
Maven

CVE-2026-40976

Spring Boot's default security filter chain has no authorization rule with Actuator but without Health

CRITICAL 9.8
Maven

CVE-2026-41635

Apache MINA vulnerable to Deserialization of Untrusted Data

CRITICAL 9.9
Maven

CVE-2025-53836

XWiki Rendering is vulnerable to RCE attacks when processing nested macros

CRITICAL 9.8
Maven

CVE-2024-52046

Apache MINA Deserialization RCE Vulnerability

CRITICAL 9.8
Maven

CVE-2026-41293

Apache Tomcat - HTTP/2 request headers not validated

CRITICAL 9.8
Maven

CVE-2026-42779

Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41635 Incomplete Fix)

CRITICAL 9.1
Maven

CVE-2026-42555

Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin users

CRITICAL 9.1
Maven

CVE-2026-40682

Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing

CRITICAL 9.6
Maven

CVE-2026-2587

GlassFish's gadget handler is vulnerable to RCE

CRITICAL 9.9
Maven

CVE-2026-40453

Apache Camel has an incomplete fix for CVE-2025-27636

CRITICAL 9.8
Maven

CVE-2026-41409

Apache MINA Vulnerable to Deserialization of Untrusted Data (CVE-2024-52046 Incomplete Fix)

CRITICAL 9.9
Maven

CVE-2026-32613

Spinnaker: RCE via expression parsing due to unrestricted context handling

CRITICAL 9.1
Maven

CVE-2026-33557

Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation

CRITICAL 9.1
Maven

CVE-2026-22732

Spring Security HTTP Headers Are not Written Under Some Conditions

CRITICAL 9.8
Maven

CVE-2026-27446

Apache Artemis and Apache ActiveMQ Artemis are Missing Authentication for Critical Functions

CRITICAL 9.8
Maven

CVE-2025-59059

Apache Ranger has a Code Injection vulnerability

CRITICAL 9.8
Maven

CVE-2026-25526

JinJava Bypass through ForTag leads to Arbitrary Java Execution

CRITICAL 9.6
Maven

CVE-2025-12543

Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests

CRITICAL 9.6
Maven

CVE-2025-55754

Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences

CRITICAL 9.1
Maven

CVE-2025-58059

Valtimo scripting engine can be used to gain access to sensitive data or resources

CRITICAL 9.8
Maven

CVE-2025-54988

Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF

CRITICAL 9.0
Maven

CVE-2025-53835

XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax

CRITICAL 9.8
Maven

CVE-2025-26074

Conductor vulnerable to OS command injection through unrestricted access to Java classes

CRITICAL 9.8
Maven KEV

CVE-2025-24813

Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

CRITICAL 9.1
Maven

CVE-2025-27603

com.xwiki.confluencepro:application-confluence-migrator-pro-ui Remote Code Execution via unescaped translations

CRITICAL 9.0
Maven

CVE-2024-52577

Apache Ignite: Possible RCE when deserializing incoming messages by the server node

CRITICAL 9.8
Maven

CVE-2025-0851

Deep Java Library path traversal issue

CRITICAL 9.8
Maven

CVE-2024-50379

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability

CRITICAL 9.8
Maven

GHSA-wpvf-5mc3-hv6m

Duplicate Advisory: Querydsl SQL/HQL injection

CRITICAL 9.8
Maven

CVE-2024-47561

Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)

CRITICAL 9.1
Maven

CVE-2024-38821

Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications

CRITICAL 9.8
Maven

CVE-2024-46983

SOFA Hessian Remote Command Execution (RCE) Vulnerability

CRITICAL 10.0
Maven

CVE-2024-37902

DeepJavaLibrary API absolute path traversal

CRITICAL 9.9
Maven

CVE-2024-38369

XWiki programming rights may be inherited by inclusion

CRITICAL 9.0
Maven

CVE-2024-37899

XWiki Platform allows remote code execution from user account

CRITICAL 10.0
Maven

CVE-2024-32888

Amazon JDBC Driver for Redshift SQL Injection via line comment generation

CRITICAL 9.9
Maven

CVE-2024-31983

XWiki Platform: Remote code execution from edit in multilingual wikis via translations

CRITICAL 9.9
Maven

CVE-2024-31984

XWiki Platform: Remote code execution through space title and Solr space facet

CRITICAL 9.6
Maven

CVE-2024-31988

XWiki Platform CSRF remote code execution through the realtime HTML Converter API

CRITICAL 10.0
Maven

CVE-2024-31996

XWiki Commons missing escaping of `{` in Velocity escapetool allows remote code execution

CRITICAL 9.9
Maven

CVE-2024-31987

XWiki Platform remote code execution from account via custom skins support

Ready to move

Start Securing

Free, no credit card | First findings in minutes