Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

CRITICAL 9.6
Maven

CVE-2026-56784

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

CRITICAL 9.3
Maven

CVE-2024-1143

Central Dogma Authentication Bypass Vulnerability via Session Leakage

CRITICAL 9.1
Maven

CVE-2023-24057

MITM based Zip Slip in `org.hl7.fhir.publisher:org.hl7.fhir.publisher`

CRITICAL 9.1
Maven

CVE-2024-1735

Armeria SAML authentication bypass due to missing validation on unsigned SAML messages

CRITICAL 9.8
Maven

CVE-2024-23679

com.enonic.xp:lib-auth vulnerable to Session Fixation

CRITICAL 9.8
Maven

CVE-2020-7611

Micronaut's HTTP client is vulnerable to HTTP Request Header Injection

CRITICAL 9.1
Maven

CVE-2023-50422

Improper JWT Signature Validation in SAP Security Services Library

CRITICAL 9.1
Maven

CVE-2022-36437

Hazelcast connection caching

CRITICAL 9.9
Maven

CVE-2021-43821

Files Accessible to External Parties in Opencast

CRITICAL 10.0
Maven

CVE-2024-23687

Hard-coded System User Credentials in Folio Data Export Spring module

CRITICAL 9.6
Maven

CVE-2021-29459

XSS Cross Site Scripting

CRITICAL 9.8
Maven

CVE-2021-42392

RCE in H2 Console

CRITICAL 9.8
Maven

CVE-2020-7622

Improper Neutralization of CRLF Sequences in HTTP Headers in Jooby ('HTTP Response Splitting)

CRITICAL 9.1
Maven

CVE-2021-29451

Missing validation of JWT signature in `ManyDesigns/Portofino`

CRITICAL 9.3
Maven

CVE-2020-15231

XSS in Mapfish Print relating to JSONP support

CRITICAL 10.0
Maven

CVE-2021-41269

Critical vulnerability found in cron-utils

CRITICAL 9.1
Maven

CVE-2021-39185

Default CORS config allows any origin with credentials

CRITICAL 9.8
Maven

CVE-2022-35912

Grails framework Remote Code Execution via Data Binding

CRITICAL 9.9
Maven

CVE-2021-29485

Remote Code Execution Vulnerability in Session Storage

CRITICAL 9.1
Maven

CVE-2021-42767

Neo4j Graph Database vulnerable to Path Traversal

CRITICAL 9.3
Maven

CVE-2021-21428

Creation of Temporary File in Directory with Insecure Permissions in the OpenAPI-Generator online generator

CRITICAL 9.8
Maven

CVE-2021-41193

Use of Externally-Controlled Format String in wire-avs

CRITICAL 10.0
Maven

CVE-2024-1597

org.postgresql:postgresql vulnerable to SQL Injection via line comment generation

CRITICAL 9.3
Maven

CVE-2021-21363

Generator Web Application: Local Privilege Escalation Vulnerability via System Temp Directory

CRITICAL 9.8
Maven

CVE-2022-46337

Apache Derby: LDAP injection vulnerability in authenticator

CRITICAL 9.8
Maven

CVE-2016-4000

Deserialization of Untrusted Data in Jython

CRITICAL 9.8
Maven

CVE-2026-54617

LaunchServer FileServerHandler has an unauthenticated path traversal issue

CRITICAL 9.8
Maven

CVE-2015-1778

Opendaylight will authenticate any username and password combination

CRITICAL 9.8
Maven

CVE-2023-35042

GeoServer RCE due to improper control of generation of code in jai-ext`Jiffle` map algebra language

CRITICAL 9.8
Maven

CVE-2026-44930

Apache CXF has an LDAP injection vulnerability

CRITICAL 9.1
Maven

CVE-2024-5986

H2O has an External Control of File Name or Path vulnerability

CRITICAL 9.1
Maven

CVE-2024-45758

H2O.ai H2O vulnerable to deserialization attacks via a JDBC Connection URL

CRITICAL 9.8
Maven

CVE-2025-6544

H2O affected by a deserialization vulnerability

CRITICAL 9.3
Maven

CVE-2026-44203

OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)

CRITICAL 9.9
Maven

CVE-2026-44179

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

CRITICAL 9.8
Maven

CVE-2026-32966

Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure

CRITICAL 9.1
Maven

CVE-2026-32967

Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks

CRITICAL 9.1
Maven

CVE-2025-66614

Apache Tomcat - Client certificate verification bypass

CRITICAL 9.1
Maven

CVE-2026-40982

Spring Cloud Config vulnerable to Path Traversal

CRITICAL 9.8
Maven

CVE-2026-33728

dd-trace-java: Unsafe deserialization in RMI instrumentation may lead to remote code execution

CRITICAL 9.8
Maven

CVE-2024-55875

http4k has a potential XXE (XML External Entity Injection) vulnerability

CRITICAL 9.8
Maven

CVE-2019-17571

Deserialization of Untrusted Data in Log4j

CRITICAL 9.8
Maven

CVE-2026-45083

Goobi viewer - Core: Unauthenticated Solr Streaming Expression Proxy

CRITICAL 9.8
Maven

CVE-2009-3555

Apache Tomcat affected by vulnerability in TLS and SSL protocol

CRITICAL 9.8
Maven

CVE-2022-23305

SQL Injection in Log4j 1.2.x

CRITICAL 9.6
Maven

CVE-2026-2587

GlassFish's gadget handler is vulnerable to RCE

CRITICAL 9.1
Maven

CVE-2026-2586

GlassFish's Administration Console is Vulnerable to RCE

CRITICAL 9.8
Maven

CVE-2026-47323

Camel-CXF and Camel-Knative Message Header are Vulnerable to Injection via Missing Inbound Filtering

CRITICAL 9.1
Maven

CVE-2026-33117

Security feature bypass vulnerability in Azure Key Vault Keys library for Java

CRITICAL 9.8
Maven

CVE-2026-46562

Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm override

CRITICAL 9.1
Maven

CVE-2026-46621

Yamcs Vulnerable to Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection

CRITICAL 9.1
Maven

CVE-2026-44632

Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`

CRITICAL 9.9
Maven

CVE-2026-40453

Apache Camel has an incomplete fix for CVE-2025-27636

CRITICAL 9.1
Maven

CVE-2026-43515

Apache Tomcat - Security constraints not correctly applied

CRITICAL 9.8
Maven

CVE-2026-27446

Apache Artemis and Apache ActiveMQ Artemis are Missing Authentication for Critical Functions

CRITICAL 9.1
Maven

CVE-2026-29145

Apache Tomcat: CLIENT_CERT authentication does not fail as expected

CRITICAL 9.8
Maven

CVE-2026-41293

Apache Tomcat - HTTP/2 request headers not validated

CRITICAL 9.8
Maven

CVE-2026-43512

Apache Tomcat - Digest authenticator will authenticate any unknown user

CRITICAL 9.8
Maven KEV

CVE-2020-1938

Improper Privilege Management in Tomcat

Ready to move

Start Securing

Free, no credit card | First findings in minutes