Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-56784
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
CVE-2024-1143
Central Dogma Authentication Bypass Vulnerability via Session Leakage
CVE-2023-24057
MITM based Zip Slip in `org.hl7.fhir.publisher:org.hl7.fhir.publisher`
CVE-2024-1735
Armeria SAML authentication bypass due to missing validation on unsigned SAML messages
CVE-2024-23679
com.enonic.xp:lib-auth vulnerable to Session Fixation
CVE-2020-7611
Micronaut's HTTP client is vulnerable to HTTP Request Header Injection
CVE-2023-50422
Improper JWT Signature Validation in SAP Security Services Library
CVE-2022-36437
Hazelcast connection caching
CVE-2021-43821
Files Accessible to External Parties in Opencast
CVE-2024-23687
Hard-coded System User Credentials in Folio Data Export Spring module
CVE-2021-29459
XSS Cross Site Scripting
CVE-2021-42392
RCE in H2 Console
CVE-2020-7622
Improper Neutralization of CRLF Sequences in HTTP Headers in Jooby ('HTTP Response Splitting)
CVE-2021-29451
Missing validation of JWT signature in `ManyDesigns/Portofino`
CVE-2020-15231
XSS in Mapfish Print relating to JSONP support
CVE-2021-41269
Critical vulnerability found in cron-utils
CVE-2021-39185
Default CORS config allows any origin with credentials
CVE-2022-35912
Grails framework Remote Code Execution via Data Binding
CVE-2021-29485
Remote Code Execution Vulnerability in Session Storage
CVE-2021-42767
Neo4j Graph Database vulnerable to Path Traversal
CVE-2021-21428
Creation of Temporary File in Directory with Insecure Permissions in the OpenAPI-Generator online generator
CVE-2021-41193
Use of Externally-Controlled Format String in wire-avs
CVE-2024-1597
org.postgresql:postgresql vulnerable to SQL Injection via line comment generation
CVE-2021-21363
Generator Web Application: Local Privilege Escalation Vulnerability via System Temp Directory
CVE-2022-46337
Apache Derby: LDAP injection vulnerability in authenticator
CVE-2016-4000
Deserialization of Untrusted Data in Jython
CVE-2026-54617
LaunchServer FileServerHandler has an unauthenticated path traversal issue
CVE-2015-1778
Opendaylight will authenticate any username and password combination
CVE-2023-35042
GeoServer RCE due to improper control of generation of code in jai-ext`Jiffle` map algebra language
CVE-2026-44930
Apache CXF has an LDAP injection vulnerability
CVE-2024-5986
H2O has an External Control of File Name or Path vulnerability
CVE-2024-45758
H2O.ai H2O vulnerable to deserialization attacks via a JDBC Connection URL
CVE-2025-6544
H2O affected by a deserialization vulnerability
CVE-2026-44203
OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)
CVE-2026-44179
xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro
CVE-2026-32966
Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
CVE-2026-32967
Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
CVE-2025-66614
Apache Tomcat - Client certificate verification bypass
CVE-2026-40982
Spring Cloud Config vulnerable to Path Traversal
CVE-2026-33728
dd-trace-java: Unsafe deserialization in RMI instrumentation may lead to remote code execution
CVE-2024-55875
http4k has a potential XXE (XML External Entity Injection) vulnerability
CVE-2019-17571
Deserialization of Untrusted Data in Log4j
CVE-2026-45083
Goobi viewer - Core: Unauthenticated Solr Streaming Expression Proxy
CVE-2009-3555
Apache Tomcat affected by vulnerability in TLS and SSL protocol
CVE-2022-23305
SQL Injection in Log4j 1.2.x
CVE-2026-2587
GlassFish's gadget handler is vulnerable to RCE
CVE-2026-2586
GlassFish's Administration Console is Vulnerable to RCE
CVE-2026-47323
Camel-CXF and Camel-Knative Message Header are Vulnerable to Injection via Missing Inbound Filtering
CVE-2026-33117
Security feature bypass vulnerability in Azure Key Vault Keys library for Java
CVE-2026-46562
Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm override
CVE-2026-46621
Yamcs Vulnerable to Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
CVE-2026-44632
Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
CVE-2026-40453
Apache Camel has an incomplete fix for CVE-2025-27636
CVE-2026-43515
Apache Tomcat - Security constraints not correctly applied
CVE-2026-27446
Apache Artemis and Apache ActiveMQ Artemis are Missing Authentication for Critical Functions
CVE-2026-29145
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
CVE-2026-41293
Apache Tomcat - HTTP/2 request headers not validated
CVE-2026-43512
Apache Tomcat - Digest authenticator will authenticate any unknown user
CVE-2020-1938
Improper Privilege Management in Tomcat
Ready to move
Start Securing
Free, no credit card | First findings in minutes