Launch Week Day 1: Announcing Security Design Review

Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

CRITICAL 9.1
Maven

CVE-2025-66614

Apache Tomcat - Client certificate verification bypass

CRITICAL 9.1
Maven

CVE-2026-40982

Spring Cloud Config vulnerable to Path Traversal

CRITICAL 9.8
Maven

CVE-2026-33728

dd-trace-java: Unsafe deserialization in RMI instrumentation may lead to remote code execution

CRITICAL 9.8
Maven

CVE-2024-55875

http4k has a potential XXE (XML External Entity Injection) vulnerability

CRITICAL 9.8
Maven

CVE-2019-17571

Deserialization of Untrusted Data in Log4j

CRITICAL 9.8
Maven

CVE-2026-45083

Goobi viewer - Core: Unauthenticated Solr Streaming Expression Proxy

CRITICAL 9.8
Maven

CVE-2009-3555

Apache Tomcat affected by vulnerability in TLS and SSL protocol

CRITICAL 9.8
Maven

CVE-2022-23305

SQL Injection in Log4j 1.2.x

CRITICAL 9.6
Maven

CVE-2026-2587

GlassFish's gadget handler is vulnerable to RCE

CRITICAL 9.1
Maven

CVE-2026-2586

GlassFish's Administration Console is Vulnerable to RCE

CRITICAL 9.8
Maven

CVE-2026-47323

Camel-CXF and Camel-Knative Message Header are Vulnerable to Injection via Missing Inbound Filtering

CRITICAL 9.1
Maven

CVE-2026-33117

Security feature bypass vulnerability in Azure Key Vault Keys library for Java

CRITICAL 9.8
Maven

CVE-2026-46562

Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm override

CRITICAL 9.1
Maven

CVE-2026-46621

Yamcs Vulnerable to Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection

CRITICAL 9.1
Maven

CVE-2026-44632

Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`

CRITICAL 9.9
Maven

CVE-2026-40453

Apache Camel has an incomplete fix for CVE-2025-27636

CRITICAL 9.1
Maven

CVE-2026-43515

Apache Tomcat - Security constraints not correctly applied

CRITICAL 9.8
Maven

CVE-2026-27446

Apache Artemis and Apache ActiveMQ Artemis are Missing Authentication for Critical Functions

CRITICAL 9.1
Maven

CVE-2026-29145

Apache Tomcat: CLIENT_CERT authentication does not fail as expected

CRITICAL 9.8
Maven

CVE-2026-41293

Apache Tomcat - HTTP/2 request headers not validated

CRITICAL 9.8
Maven

CVE-2026-43512

Apache Tomcat - Digest authenticator will authenticate any unknown user

CRITICAL 9.8
Maven KEV

CVE-2020-1938

Improper Privilege Management in Tomcat

CRITICAL 9.1
Maven

CVE-2026-41258

OpenMRS has Stored Velocity SSTI to RCE via ConceptReferenceRange

CRITICAL 9.1
Maven

CVE-2026-42555

Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin users

CRITICAL 9.1
Maven

CVE-2026-40976

Spring Boot's default security filter chain has no authorization rule with Actuator but without Health

CRITICAL 9.8
Maven

CVE-2026-41635

Apache MINA vulnerable to Deserialization of Untrusted Data

CRITICAL 9.0
Maven

CVE-2026-41901

Sandboxed Thymeleaf expressions vulnerable to improper recognition of unauthorized syntax patterns

CRITICAL 9.0
Maven

CVE-2026-44221

ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases

CRITICAL 9.6
Maven

CVE-2025-55754

Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences

CRITICAL 9.8
Maven

CVE-2026-22738

Spring AI: SpEL injection is triggered when a user-supplied value is used as a filter expression key

CRITICAL 9.1
Maven

CVE-2026-27478

Unity Catalog has a JWT Issuer Validation Bypass tht Allows Complete User Impersonation

CRITICAL 10.0
Maven

CVE-2026-7411

Eclipse BaSyx Java Server SDK vulnerable to Path Traversal

CRITICAL 9.1
Maven

CVE-2026-40010

Apache Wicket has a Session Fixation issue

CRITICAL 9.1
Maven

CVE-2026-40682

Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing

CRITICAL 9.8
Maven

CVE-2026-42027

Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest

CRITICAL 9.9
Maven

CVE-2026-42812

Apache Polaris has an Improper Input Validation issue

CRITICAL 9.9
Maven

CVE-2026-42810

Apache Polaris has an Improper Input Validation Issue

CRITICAL 9.9
Maven

CVE-2026-42811

Apache Polaris has an Improper Input Validation issue

CRITICAL 9.9
Maven

CVE-2026-42809

Apache Polaris has an Improper Input Validation Issue

CRITICAL 9.8
Maven

CVE-2026-42779

Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41635 Incomplete Fix)

CRITICAL 9.8
Maven

CVE-2026-42778

Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41409 Incomplete Fix)

CRITICAL 10.0
Maven

CVE-2026-36767

Shopizer has a path traversal issue

CRITICAL 9.8
Maven

CVE-2026-41409

Apache MINA Vulnerable to Deserialization of Untrusted Data (CVE-2024-52046 Incomplete Fix)

CRITICAL 9.0
Maven

CVE-2026-42523

Jenkins GitHub Plugin has an XSS vulnerability

CRITICAL 9.8
Maven

CVE-2020-9546

jackson-databind mishandles the interaction between serialization gadgets and typing

CRITICAL 9.4
Maven

CVE-2026-33454

Apache Camel's Camel-Mail component is vulnerable to Camel message header injection

CRITICAL 9.0
Maven

CVE-2026-40478

Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf

CRITICAL 9.9
Maven

CVE-2026-32604

Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths

CRITICAL 9.0
Maven

CVE-2026-40477

Improper restriction of the scope of accessible objects in Thymeleaf expressions

CRITICAL 9.9
Maven

CVE-2026-39842

Expression Injection in OpenRemote

CRITICAL 9.9
Maven

CVE-2026-32613

Spinnaker: RCE via expression parsing due to unrestricted context handling

CRITICAL 10.0
Maven

CVE-2026-33453

Apache camel-coap allows header injection that can lead to remote code execution

CRITICAL 9.8
Maven KEV

CVE-2012-0391

Apache Struts Remote Java Code Execution

CRITICAL 9.0
Maven

CVE-2025-66024

XWiki Blog Application home page vulnerable to Stored XSS via Post Title

CRITICAL 9.8
Maven

CVE-2024-26579

Apache Inlong Deserialization of Untrusted Data vulnerability

CRITICAL 9.1
Maven

CVE-2026-33557

Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation

CRITICAL 9.8
Maven

CVE-2024-46983

SOFA Hessian Remote Command Execution (RCE) Vulnerability

CRITICAL 9.8
Maven

CVE-2022-0239

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

CRITICAL 9.1
Maven

CVE-2021-26291

Origin Validation Error in Apache Maven

CRITICAL 9.1
Maven

CVE-2026-35580

Emissary has GitHub Actions Shell Injection via Workflow Inputs

Ready to move

Start Securing

Free, no credit card | First findings in minutes