Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-54609
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
CVE-2026-49464
NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
CVE-2026-49832
DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN
CVE-2026-49361
Apache Fluss: Unauthenticated remote attackers can exhaust JVM heap memory using crafted frame headers via TabletServer/CoordinatorServer
CVE-2022-23913
Apache ActiveMQ Artemis Uncontrolled Resource Consumption (DoS)
CVE-2024-23683
Trust Boundary Violation due to Incomplete Blacklist in Test Failure Processing in Ares
CVE-2024-23682
Class Loading Vulnerability in Artemis
CVE-2024-23684
Denial of service in CBOR library
CVE-2023-45859
Missing permission checks on Hazelcast client protocol
CVE-2022-25845
Unsafe deserialization in com.alibaba:fastjson
CVE-2021-23463
Improper Restriction of XML External Entity Reference in com.h2database:h2.
CVE-2022-25647
Deserialization of Untrusted Data in Gson
CVE-2020-7692
Improper Authorization in Google OAuth Client
CVE-2021-29620
XXE vulnerability on Launch import with externally-defined DTD file
CVE-2022-2048
Jetty vulnerable to Invalid HTTP/2 requests that can lead to denial of service
CVE-2021-3827
ECP SAML binding bypasses authentication flows
CVE-2021-39148
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21361
Sensitive information disclosure via log in com.bmuschko:gradle-vagrant-plugin
CVE-2022-27772
Temporary Directory Hijacking to Local Privilege Escalation Vulnerability in org.springframework.boot:spring-boot
CVE-2021-37136
Bzip2Decoder doesn't allow setting size restrictions for decompressed data
CVE-2020-26238
Template injection in cron-utils
CVE-2022-41828
com.amazon.redshift:redshift-jdbc42 vulnerable to remote command execution
CVE-2023-1108
Undertow denial of service vulnerability
CVE-2021-21341
XStream can cause a Denial of Service.
CVE-2021-32623
Billion laughs attack (XML bomb)
CVE-2021-29479
Cached redirect poisoning via X-Forwarded-Host header
CVE-2021-39141
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-43807
HTTP Method Spoofing
CVE-2021-32621
Script injection without script or programming rights through Gadget titles
CVE-2023-28465
HL7 FHIR Partial Path Zip Slip due to bypass of CVE-2023-24057
CVE-2021-43859
Denial of Service by injecting highly recursive collections or maps in XStream
CVE-2021-39150
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2022-29546
OutOfMemory Exception by specifically crafted processing instruction in NekoHtml Parser
CVE-2020-15087
Privilege escalation in Presto
CVE-2021-39146
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39147
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39145
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2020-15252
RCE in XWiki
CVE-2020-28191
Togglz console missing cross-site request forgery (CSRF) protection
CVE-2021-32769
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in micronaut-core
CVE-2021-43795
Path Traversal in com.linecorp.armeria:armeria
CVE-2021-29505
XStream is vulnerable to a Remote Command Execution attack
CVE-2021-39151
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39153
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-32620
XWiki users registered with email verification can self re-activate their disabled accounts
CVE-2021-39133
Cross-Site Request Forgery (CSRF) can run untrusted code on Rundeck server
CVE-2021-39139
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39149
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-37137
SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary way
CVE-2021-39154
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-41189
Communities and collections administrators can escalate their privilege up to system administrator
CVE-2021-32732
Cross-Site Request Forgery in xwiki-platform
CVE-2022-2191
Jetty SslConnection does not release pooled ByteBuffers in case of errors
CVE-2021-41084
Response Splitting from unsanitized headers
CVE-2021-39132
YAML deserialization can run untrusted code
CVE-2021-28165
Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resources
CVE-2024-23681
Arbitrary code execution in de.tum.in.ase:artemis-java-test-sandbox
CVE-2021-39144
XStream is vulnerable to a Remote Command Execution attack
CVE-2020-5245
Remote Code Execution (RCE) vulnerability in dropwizard-validation
CVE-2021-39152
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
Ready to move
Start Securing
Free, no credit card | First findings in minutes