Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

MEDIUM 5.4
Maven

CVE-2026-57305

Jenkins Assembla Plugin has a cross-site request forgery (CSRF) vulnerability

MEDIUM 4.2
Maven

CVE-2026-57306

Jenkins Zowe zDevOps Plugin has a CSRF vulnerability

MEDIUM 4.2
Maven

CVE-2026-57307

Jenkins Zowe zDevOps Plugin has a missing permission check

MEDIUM 5.4
Maven

CVE-2026-57304

Jenkins Assembla Plugin has a missing permission check

MEDIUM 4.3
Maven

CVE-2026-57302

Jenkins FitNesse Plugin stores passwords unencrypted

MEDIUM 4.3
Maven

CVE-2026-57299

Jenkins Contrast Continuous Application Security Plugin missing permission checks

MEDIUM 4.3
Maven

CVE-2026-57300

Jenkins MCP Server Plugin missing a permission check

MEDIUM 5.4
Maven

CVE-2026-57298

Jenkins Contrast Continuous Application Security Plugin has a CSRF vulnerability

MEDIUM 5.4
Maven

CVE-2026-57291

Jenkins Gitee Plugin missing permission checks

MEDIUM 5.4
Maven

CVE-2026-57292

Jenkins Gitee Plugin has a cross-site request forgery vulnerability

MEDIUM 4.8
Maven

CVE-2026-57289

Jenkins Bitbucket Push and Pull Request Plugin unconditionally disables SSL/TLS certificate validation

MEDIUM 4.3
Maven

CVE-2026-57290

Jenkins Priority Sorter Plugin has a CSRF vulnerability

MEDIUM 4.3
Maven

CVE-2026-57297

Jenkins Contrast Continuous Application Security Plugin has a missing permission check

MEDIUM 5.4
Maven

CVE-2026-57294

Jenkins EC2 Fleet Plugin has a missing permission check

MEDIUM 5.4
Maven

CVE-2026-57295

Jenkins EC2 Fleet Plugin has a cross-site request forgery (CSRF) vulnerability

MEDIUM 4.3
Maven

CVE-2026-57293

Jenkins Gitee Plugin has an incorrect permission check that allows enumerating credentials IDs

MEDIUM 5.0
Maven

CVE-2026-57282

Jenkins Git client Plugin has an OS command injection vulnerability on agents

MEDIUM 4.3
Maven

CVE-2026-57285

Jenkins GitHub Branch Source Plugin has missing permission check that allows enumerating GitHub Enterprise server URLs

MEDIUM 4.3
Maven

CVE-2026-57284

Jenkins Pipeline: Groovy Plugin vulnerable to unrestricted instantiation of types

MEDIUM 4.3
Maven

CVE-2026-57286

Jenkins Git Parameter Plugin has a missing permission check that allows listing SCM branch and tag names

MEDIUM 4.3
Maven

CVE-2026-57287

Jenkins Job Configuration History Plugin doesn't redact encrypted values of secrets in job and agent configurations

MEDIUM 4.3
Maven

CVE-2026-57283

Jenkins Pipeline: Groovy Plugin has a CSRF vulnerability

MEDIUM 6.8
Maven

CVE-2025-37731

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

MEDIUM 6.5
Maven

CVE-2024-52980

Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

MEDIUM 6.5
Maven

CVE-2026-77421

JLine: ReDoS in Nano Editor Regex Search Mode

MEDIUM 5.5
Maven

CVE-2026-77420

JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable

MEDIUM 6.3
Maven

CVE-2026-69190

Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards

MEDIUM 5.3
Maven

CVE-2026-48043

netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion

MEDIUM 6.8
Maven

CVE-2026-85717

AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target

MEDIUM 5.9
Maven

CVE-2026-85720

AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request

MEDIUM 6.5
Maven

CVE-2026-73245

Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth

MEDIUM 6.8
Maven

CVE-2026-69215

Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin

MEDIUM 5.9
Maven

CVE-2026-69201

Http4s: ResourceService and Webjar Service path escape via percent-encoded separators

MEDIUM 6.8
Maven

CVE-2026-69214

Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain

MEDIUM 5.4
Maven

CVE-2026-69216

Http4s: Ember chunk parser lenience (TE.TE request smuggling)

MEDIUM 5.9
Maven

CVE-2026-69206

Http4s: DigestAuth allows replay of captured requests

MEDIUM 5.4
Maven

CVE-2025-62198

Apache Atlas UI: Authenticated User XSS

MEDIUM 5.3
Maven

CVE-2026-54665

Apache NiFi fails to validate proxy host headers when constructing qualified URLs

MEDIUM 6.1
Maven

CVE-2026-25854

Apache Tomcat has an Open Redirect vulnerability

MEDIUM 5.9
Maven

CVE-2026-55858

org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context

MEDIUM 4.0
Maven

CVE-2026-55688

AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore

MEDIUM 6.5
Maven

CVE-2026-59903

Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite

MEDIUM 6.5
Maven

CVE-2026-59949

LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges

MEDIUM 5.5
Maven

CVE-2026-59919

Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address

MEDIUM 5.3
Maven

CVE-2026-8384

Eclipse Jetty: Path parameter traversal

MEDIUM 6.8
Maven

GHSA-q6gh-6v2r-hjv3

Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers

MEDIUM 5.3
Maven

CVE-2026-6790

Eclipse Jetty: HTTP Authority/Host mismatch

MEDIUM 6.5
Maven

CVE-2026-59889

jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization

MEDIUM 6.5
Maven

CVE-2026-56746

Netty: Security Control Bypass via CORS Short-Circuit Failure

MEDIUM 6.5
Maven

CVE-2026-59888

jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy

MEDIUM 6.5
Maven

CVE-2026-59920

Netty: STOMP CONNECT Frame Header Injection in Netty

MEDIUM 6.8
Maven

CVE-2026-45673

Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port

MEDIUM 5.9
Maven

CVE-2026-41841

Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux

MEDIUM 4.3
Maven

CVE-2026-53438

Jenkins: Missing permission check allows unauthorized cancellation of queue items

MEDIUM 5.3
Maven

CVE-2026-53442

Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations

MEDIUM 5.3
Maven

CVE-2026-41001

Spring Boot: Predictable Temp Directory in Artemis Auto-configuration

MEDIUM 5.3
Maven

CVE-2026-41853

Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux

MEDIUM 4.8
Maven

CVE-2026-50009

Netty: QUIC stateless reset token material exposed through header-visible connection IDs

MEDIUM 6.5
Maven

CVE-2026-46718

Apache Calcite is Vulnerable to Use of Externally-Controlled Input to Select Classes

MEDIUM 5.9
Maven

CVE-2026-41840

Spring Framework Denial of Service via Multipart Requests in WebFlux

Ready to move

Start Securing

Free, no credit card | First findings in minutes