Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

HIGH 8.6
Maven

CVE-2026-54609

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

HIGH 8.1
Maven

CVE-2026-49464

NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak

HIGH 8.0
Maven

CVE-2026-49832

DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN

HIGH 7.5
Maven

CVE-2026-49361

Apache Fluss: Unauthenticated remote attackers can exhaust JVM heap memory using crafted frame headers via TabletServer/CoordinatorServer

HIGH 7.5
Maven

CVE-2022-23913

Apache ActiveMQ Artemis Uncontrolled Resource Consumption (DoS)

HIGH 8.2
Maven

CVE-2024-23683

Trust Boundary Violation due to Incomplete Blacklist in Test Failure Processing in Ares

HIGH 8.2
Maven

CVE-2024-23682

Class Loading Vulnerability in Artemis

HIGH 7.5
Maven

CVE-2024-23684

Denial of service in CBOR library

HIGH 7.6
Maven

CVE-2023-45859

Missing permission checks on Hazelcast client protocol

HIGH 8.1
Maven

CVE-2022-25845

Unsafe deserialization in com.alibaba:fastjson

HIGH 8.1
Maven

CVE-2021-23463

Improper Restriction of XML External Entity Reference in com.h2database:h2.

HIGH 7.7
Maven

CVE-2022-25647

Deserialization of Untrusted Data in Gson

HIGH 7.4
Maven

CVE-2020-7692

Improper Authorization in Google OAuth Client

HIGH 7.5
Maven

CVE-2021-29620

XXE vulnerability on Launch import with externally-defined DTD file

HIGH 7.5
Maven

CVE-2022-2048

Jetty vulnerable to Invalid HTTP/2 requests that can lead to denial of service

HIGH 8.1
Maven

CVE-2021-3827

ECP SAML binding bypasses authentication flows

HIGH 8.5
Maven

CVE-2021-39148

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 7.4
Maven

CVE-2021-21361

Sensitive information disclosure via log in com.bmuschko:gradle-vagrant-plugin

HIGH 7.8
Maven

CVE-2022-27772

Temporary Directory Hijacking to Local Privilege Escalation Vulnerability in org.springframework.boot:spring-boot

HIGH 7.5
Maven

CVE-2021-37136

Bzip2Decoder doesn't allow setting size restrictions for decompressed data

HIGH 7.9
Maven

CVE-2020-26238

Template injection in cron-utils

HIGH 7.1
Maven

CVE-2022-41828

com.amazon.redshift:redshift-jdbc42 vulnerable to remote command execution

HIGH 7.5
Maven

CVE-2023-1108

Undertow denial of service vulnerability

HIGH 7.5
Maven

CVE-2021-21341

XStream can cause a Denial of Service.

HIGH 8.1
Maven

CVE-2021-32623

Billion laughs attack (XML bomb)

HIGH 7.0
Maven

CVE-2021-29479

Cached redirect poisoning via X-Forwarded-Host header

HIGH 8.5
Maven

CVE-2021-39141

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 7.5
Maven

CVE-2021-43807

HTTP Method Spoofing

HIGH 8.8
Maven

CVE-2021-32621

Script injection without script or programming rights through Gadget titles

HIGH 7.5
Maven

CVE-2023-28465

HL7 FHIR Partial Path Zip Slip due to bypass of CVE-2023-24057

HIGH 7.5
Maven

CVE-2021-43859

Denial of Service by injecting highly recursive collections or maps in XStream

HIGH 8.5
Maven

CVE-2021-39150

A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host

HIGH 7.5
Maven

CVE-2022-29546

OutOfMemory Exception by specifically crafted processing instruction in NekoHtml Parser

HIGH 7.4
Maven

CVE-2020-15087

Privilege escalation in Presto

HIGH 8.5
Maven

CVE-2021-39146

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 8.5
Maven

CVE-2021-39147

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 8.5
Maven

CVE-2021-39145

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 8.5
Maven

CVE-2020-15252

RCE in XWiki

HIGH 8.8
Maven

CVE-2020-28191

Togglz console missing cross-site request forgery (CSRF) protection

HIGH 7.5
Maven

CVE-2021-32769

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in micronaut-core

HIGH 7.5
Maven

CVE-2021-43795

Path Traversal in com.linecorp.armeria:armeria

HIGH 7.5
Maven

CVE-2021-29505

XStream is vulnerable to a Remote Command Execution attack

HIGH 8.5
Maven

CVE-2021-39151

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 8.5
Maven

CVE-2021-39153

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 8.1
Maven

CVE-2021-32620

XWiki users registered with email verification can self re-activate their disabled accounts

HIGH 7.2
Maven

CVE-2021-39133

Cross-Site Request Forgery (CSRF) can run untrusted code on Rundeck server

HIGH 8.5
Maven

CVE-2021-39139

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 8.5
Maven

CVE-2021-39149

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 7.5
Maven

CVE-2021-37137

SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary way

HIGH 8.5
Maven

CVE-2021-39154

XStream is vulnerable to an Arbitrary Code Execution attack

HIGH 7.2
Maven

CVE-2021-41189

Communities and collections administrators can escalate their privilege up to system administrator

HIGH 7.5
Maven

CVE-2021-32732

Cross-Site Request Forgery in xwiki-platform

HIGH 7.5
Maven

CVE-2022-2191

Jetty SslConnection does not release pooled ByteBuffers in case of errors

HIGH 8.7
Maven

CVE-2021-41084

Response Splitting from unsanitized headers

HIGH 8.8
Maven

CVE-2021-39132

YAML deserialization can run untrusted code

HIGH 7.5
Maven

CVE-2021-28165

Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resources

HIGH 8.2
Maven

CVE-2024-23681

Arbitrary code execution in de.tum.in.ase:artemis-java-test-sandbox

HIGH 8.5
Maven KEV

CVE-2021-39144

XStream is vulnerable to a Remote Command Execution attack

HIGH 7.9
Maven

CVE-2020-5245

Remote Code Execution (RCE) vulnerability in dropwizard-validation

HIGH 8.5
Maven

CVE-2021-39152

A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host

Ready to move

Start Securing

Free, no credit card | First findings in minutes