Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-57288
Jenkins Active Directory Plugin has an LDAP injection vulnerability
CVE-2026-85716
AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses
CVE-2026-61700
MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests
CVE-2026-86071
Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root
CVE-2026-43514
Apache Tomcat - AJP secret compared in non-constant time
CVE-2026-22741
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
CVE-2026-22746
Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
CVE-2026-22735
Spring MVC and WebFlux has Server Sent Event stream corruption
CVE-2026-41852
Spring Framework Arbitrary Method Invocation in SpEL Expressions
CVE-2026-41848
Spring Framework Denial of Service via AntPathMatcher
CVE-2026-3911
Keycloak: Information disclosure of disabled user attributes via administrative endpoint
CVE-2025-11143
org.eclipse.jetty:jetty-http has different parsing of invalid URIs
CVE-2026-4633
Keycloak's identity-first login flow exposes user information
CVE-2026-4874
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
CVE-2026-2733
Keycloak: Missing Check on Disabled Client for Docker Registry Protocol
CVE-2025-10939
Keycloak unable to restrict access to the admin console
CVE-2025-67639
Jenkins has a CSRF vulnerability on the login form
CVE-2025-1396
WSO2's Input Validation Management Service contains Observable Discrepancy when Multi-Attribute Login is enabled
CVE-2025-22233
Spring Framework DataBinder Case Sensitive Match Exception
CVE-2025-32971
Solr script service doesn't take dropped programming right into account
CVE-2024-38829
Spring LDAP data exposure vulnerability
CVE-2024-10492
Keycloak Path Traversal Vulnerability Due to External Control of File Name or Path
CVE-2024-6763
Eclipse Jetty URI parsing of invalid authority
CVE-2024-23454
Apache Hadoop: Temporary File Local Information Disclosure
CVE-2024-45384
druid-pac4j, Apache Druid extension, has Padding Oracle vulnerability
GHSA-gmrm-8fx4-66x7
Duplicate Advisory: Keycloak: Leak of configured LDAP bind credentials
CVE-2024-38364
DSpace Cross Site Scripting (XSS) via a deposited HTML/XML document
CVE-2024-5967
Keycloak leaks configured LDAP bind credentials through the Keycloak admin console
CVE-2023-0657
Keycloak vulnerable to impersonation via logout token exchange
CVE-2024-1979
In Quarkus, git credentials could be inadvertently published
GHSA-58qw-p7qm-5rvh
Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations
CVE-2024-20925
Vulnerability affecting the org.openjfx:javafx-media maven component of the OpenJFX project
CVE-2023-5384
Infinispan caches credentials in clear text
CVE-2023-36479
Jetty vulnerable to errant command quoting in CGI Servlet
CVE-2023-41900
Jetty's OpenId Revoked authentication allows one request
CVE-2023-26049
Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookies
CVE-2023-41329
Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes
CVE-2023-29203
Unauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm
CVE-2026-1190
Keycloak's missing timestamp validation allows attackers to extend SAML response validity periods
CVE-2025-27496
Snowflake JDBC Driver client-side encryption key in DEBUG logs
CVE-2024-4028
Keycloak allows cross-site scripting (XSS)
CVE-2022-2047
Jetty invalid URI parsing may produce invalid HttpURI.authority
CVE-2023-41041
Graylog user session is still usable after logout
CVE-2023-41044
Graylog server has partial path traversal vulnerability in Support Bundle feature
CVE-2020-8908
Information Disclosure in Guava
CVE-2019-1003063
Jenkins Amazon SNS Build Notifier Plugin stores credentials in plain text
CVE-2026-46584
Apache Camel-Mail: The mail producer applied attacker-supplied mail.smtp.* / mail.smtps.* message headers as JavaMail session properties
CVE-2025-12150
Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
CVE-2026-41000
Spring Web Services: WSS4J validation does not use configured replay cache
CVE-2026-41694
Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads
CVE-2023-27903
Incorrect Authorization in Jenkins Core
CVE-2023-27904
Information disclosure through error stack traces related to agents
CVE-2024-39458
Exposure of secrets through system log in Jenkins Structs Plugin
CVE-2026-9088
Keycloak: Information disclosure due to user profile permission bypass
CVE-2026-37977
Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claim
CVE-2024-23686
nvdApiKey is logged in debug mode
CVE-2021-34428
SessionListener can prevent a session from being invalidated breaking logout
CVE-2021-28163
Directory exposure in jetty
CVE-2021-32729
A user without PR can reset user authentication failures information
CVE-2021-21331
Local Information Disclosure Vulnerability
Ready to move
Start Securing
Free, no credit card | First findings in minutes