Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

LOW 3.7
Maven

CVE-2026-57288

Jenkins Active Directory Plugin has an LDAP injection vulnerability

LOW 3.7
Maven

CVE-2026-85716

AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses

LOW 3.7
Maven

CVE-2026-61700

MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests

LOW 3.7
Maven

CVE-2026-86071

Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root

LOW 3.7
Maven

CVE-2026-43514

Apache Tomcat - AJP secret compared in non-constant time

LOW 3.1
Maven

CVE-2026-22741

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

LOW 3.7
Maven

CVE-2026-22746

Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider

LOW 2.6
Maven

CVE-2026-22735

Spring MVC and WebFlux has Server Sent Event stream corruption

LOW 3.7
Maven

CVE-2026-41852

Spring Framework Arbitrary Method Invocation in SpEL Expressions

LOW 3.7
Maven

CVE-2026-41848

Spring Framework Denial of Service via AntPathMatcher

LOW 2.7
Maven

CVE-2026-3911

Keycloak: Information disclosure of disabled user attributes via administrative endpoint

LOW 3.7
Maven

CVE-2025-11143

org.eclipse.jetty:jetty-http has different parsing of invalid URIs

LOW 3.7
Maven

CVE-2026-4633

Keycloak's identity-first login flow exposes user information

LOW 3.1
Maven

CVE-2026-4874

Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation

LOW 3.8
Maven

CVE-2026-2733

Keycloak: Missing Check on Disabled Client for Docker Registry Protocol

LOW 3.7
Maven

CVE-2025-10939

Keycloak unable to restrict access to the admin console

LOW 3.5
Maven

CVE-2025-67639

Jenkins has a CSRF vulnerability on the login form

LOW 3.7
Maven

CVE-2025-1396

WSO2's Input Validation Management Service contains Observable Discrepancy when Multi-Attribute Login is enabled

LOW 3.1
Maven

CVE-2025-22233

Spring Framework DataBinder Case Sensitive Match Exception

LOW 3.8
Maven

CVE-2025-32971

Solr script service doesn't take dropped programming right into account

LOW 3.7
Maven

CVE-2024-38829

Spring LDAP data exposure vulnerability

LOW 2.7
Maven

CVE-2024-10492

Keycloak Path Traversal Vulnerability Due to External Control of File Name or Path

LOW 3.7
Maven

CVE-2024-6763

Eclipse Jetty URI parsing of invalid authority

LOW 3.3
Maven

CVE-2024-23454

Apache Hadoop: Temporary File Local Information Disclosure

LOW 3.7
Maven

CVE-2024-45384

druid-pac4j, Apache Druid extension, has Padding Oracle vulnerability

LOW 2.7
Maven

GHSA-gmrm-8fx4-66x7

Duplicate Advisory: Keycloak: Leak of configured LDAP bind credentials

LOW 2.6
Maven

CVE-2024-38364

DSpace Cross Site Scripting (XSS) via a deposited HTML/XML document

LOW 2.7
Maven

CVE-2024-5967

Keycloak leaks configured LDAP bind credentials through the Keycloak admin console

LOW 3.4
Maven

CVE-2023-0657

Keycloak vulnerable to impersonation via logout token exchange

LOW 3.5
Maven

CVE-2024-1979

In Quarkus, git credentials could be inadvertently published

LOW 3.9
Maven

GHSA-58qw-p7qm-5rvh

Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations

LOW 3.1
Maven

CVE-2024-20925

Vulnerability affecting the org.openjfx:javafx-media maven component of the OpenJFX project

LOW 2.7
Maven

CVE-2023-5384

Infinispan caches credentials in clear text

LOW 3.5
Maven

CVE-2023-36479

Jetty vulnerable to errant command quoting in CGI Servlet

LOW 3.5
Maven

CVE-2023-41900

Jetty's OpenId Revoked authentication allows one request

LOW 2.4
Maven

CVE-2023-26049

Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookies

LOW 3.9
Maven

CVE-2023-41329

Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes

LOW 3.7
Maven

CVE-2023-29203

Unauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm

LOW 3.1
Maven

CVE-2026-1190

Keycloak's missing timestamp validation allows attackers to extend SAML response validity periods

LOW 3.3
Maven

CVE-2025-27496

Snowflake JDBC Driver client-side encryption key in DEBUG logs

LOW 3.8
Maven

CVE-2024-4028

Keycloak allows cross-site scripting (XSS)

LOW 2.7
Maven

CVE-2022-2047

Jetty invalid URI parsing may produce invalid HttpURI.authority

LOW 2.6
Maven

CVE-2023-41041

Graylog user session is still usable after logout

LOW 3.3
Maven

CVE-2023-41044

Graylog server has partial path traversal vulnerability in Support Bundle feature

LOW 3.3
Maven

CVE-2020-8908

Information Disclosure in Guava

LOW 3.3
Maven

CVE-2019-1003063

Jenkins Amazon SNS Build Notifier Plugin stores credentials in plain text

LOW 3.7
Maven

CVE-2026-46584

Apache Camel-Mail: The mail producer applied attacker-supplied mail.smtp.* / mail.smtps.* message headers as JavaMail session properties

LOW 3.1
Maven

CVE-2025-12150

Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass

LOW 3.7
Maven

CVE-2026-41000

Spring Web Services: WSS4J validation does not use configured replay cache

LOW 3.7
Maven

CVE-2026-41694

Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads

LOW 3.6
Maven

CVE-2023-27903

Incorrect Authorization in Jenkins Core

LOW 3.1
Maven

CVE-2023-27904

Information disclosure through error stack traces related to agents

LOW 3.1
Maven

CVE-2024-39458

Exposure of secrets through system log in Jenkins Structs Plugin

LOW 2.7
Maven

CVE-2026-9088

Keycloak: Information disclosure due to user profile permission bypass

LOW 3.7
Maven

CVE-2026-37977

Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claim

LOW 3.3
Maven

CVE-2024-23686

nvdApiKey is logged in debug mode

LOW 3.5
Maven

CVE-2021-34428

SessionListener can prevent a session from being invalidated breaking logout

LOW 2.7
Maven

CVE-2021-28163

Directory exposure in jetty

LOW 2.0
Maven

CVE-2021-32729

A user without PR can reset user authentication failures information

LOW 3.0
Maven

CVE-2021-21331

Local Information Disclosure Vulnerability

Ready to move

Start Securing

Free, no credit card | First findings in minutes