Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

MEDIUM 6.5
Maven

CVE-2026-49463

NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries

MEDIUM 5.5
Maven

CVE-2026-49833

DSpace: Path Traversal is possible through LDN message generation

MEDIUM 4.4
Maven

CVE-2026-49830

DSpace: ORE resource URI does not validate scheme for non-web resources

MEDIUM 5.5
Maven

CVE-2026-49831

DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path

MEDIUM 5.3
Maven

CVE-2026-49328

Apache Fesod is vulnerable to Server-Side Request Forgery through its UrlImageConverter component

MEDIUM 6.5
Maven

CVE-2024-52980

Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

MEDIUM 6.5
Maven

CVE-2025-48977

Apache Ignite REST API Has a Relative Path Traversal Vulnerability

MEDIUM 6.1
Maven

CVE-2022-35278

HTML Injection in ActiveMQ Artemis Web Console

MEDIUM 6.5
Maven

CVE-2024-34517

Neo4j Cypher component mishandles IMMUTABLE privileges

MEDIUM 4.8
Maven

CVE-2024-23689

ClickHouse vulnerable to client certificate password exposure in client exception

MEDIUM 6.5
Maven

CVE-2023-45860

Hazelcast Platform permission checking in CSV File Source connector

MEDIUM 6.5
Maven

CVE-2021-26920

Druid ingestion system Authenticated users can read data from other sources than intended

MEDIUM 6.1
Maven

CVE-2024-0758

JavaScript execution via malicious molfiles (XSS)

MEDIUM 5.3
Maven

CVE-2024-23686

Insertion of Sensitive Information into Log File in OWASP DependencyCheck

MEDIUM 6.5
Maven

CVE-2021-23339

HTTP Request Smuggling in akka-http-core

MEDIUM 6.1
Maven

CVE-2021-21028

Reflected Cross-site Scripting (XSS) in ACS Commons

MEDIUM 6.9
Maven

CVE-2022-25842

Path Traversal in com.alibaba.oneagent:one-java-agent-plugin

MEDIUM 5.4
Maven

CVE-2021-23408

Prototype Pollution in GraphHopper

MEDIUM 5.3
Maven

CVE-2024-23685

Hard-coded System User Credentials in Folio Data Export Spring module

MEDIUM 5.3
Maven

CVE-2021-21344

XStream is vulnerable to an Arbitrary Code Execution attack

MEDIUM 5.7
Maven

CVE-2021-32730

No CSRF protection on the password change form

MEDIUM 4.0
Maven

CVE-2021-21429

Creation of Temporary File in Directory with Insecure Permissions in the OpenAPI Generator Maven plugin

MEDIUM 6.1
Maven

CVE-2021-21349

A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host

MEDIUM 5.3
Maven

CVE-2021-21343

XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights

MEDIUM 6.1
Maven

CVE-2021-21346

XStream is vulnerable to an Arbitrary Code Execution attack

MEDIUM 5.3
Maven

CVE-2021-28164

Authorization Before Parsing and Canonicalization in jetty

MEDIUM 6.5
Maven

CVE-2021-29506

Navigate endpoint is vulnerable to regex injection that may lead to Denial of Service.

MEDIUM 4.3
Maven

CVE-2021-3503

Metrics exposure in Wildfly

MEDIUM 4.8
Maven

CVE-2020-26234

Disabled Hostname Verification in Opencast

MEDIUM 6.1
Maven

CVE-2021-21347

XStream is vulnerable to an Arbitrary Code Execution attack

MEDIUM 4.4
Maven

CVE-2021-29480

Ratpack's default client side session signing key is highly predictable

MEDIUM 6.2
Maven

CVE-2021-21364

Generated Code Contains Local Information Disclosure Vulnerability

MEDIUM 5.4
Maven

CVE-2022-35697

AEM WCM Core Components CVG Image vulnerable to Reflected Cross-site Scripting

MEDIUM 4.3
Maven

CVE-2021-39194

Improper Handling of Missing Values in kaml

MEDIUM 5.3
Maven

CVE-2021-21342

A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host

MEDIUM 5.8
Maven

CVE-2021-21345

XStream is vulnerable to a Remote Command Execution attack

MEDIUM 6.7
Maven

CVE-2021-4178

fabric8 kubernetes-client vulnerable

MEDIUM 6.2
Maven

CVE-2021-21430

Creation of Temporary File in Directory with Insecure Permissions in auto-generated Java, Scala code

MEDIUM 5.8
Maven

CVE-2021-32643

StaticFile.fromUrl can leak presence of a directory

MEDIUM 5.3
Maven

CVE-2021-32731

The reset password form reveal users email address

MEDIUM 5.3
Maven

CVE-2021-21350

XStream is vulnerable to an Arbitrary Code Execution attack

MEDIUM 5.4
Maven

CVE-2021-21351

XStream is vulnerable to an Arbitrary Code Execution attack

MEDIUM 6.5
Maven

CVE-2021-39140

XStream can cause a Denial of Service

MEDIUM 6.5
Maven

CVE-2021-29481

Unencrypted storage of client side sessions

MEDIUM 6.1
Maven

CVE-2022-28820

Page Compare Reflected Cross-site Scripting (XSS) vulnerability

MEDIUM 4.1
Maven

CVE-2021-43841

Cross-site Scripting by SVG upload in xwiki-platform

MEDIUM 5.3
Maven

CVE-2021-21348

XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)

MEDIUM 5.7
Maven

CVE-2022-3171

protobuf-java has a potential Denial of Service issue

MEDIUM 6.2
Maven

CVE-2021-21290

Local Information Disclosure Vulnerability in Netty on Unix-Like systems

MEDIUM 6.5
Maven

CVE-2021-43797

HTTP request smuggling in netty

MEDIUM 6.2
Maven

CVE-2021-28168

Local information disclosure via system temporary directory

MEDIUM 4.4
Maven

CVE-2020-15250

TemporaryFolder on unix-like systems does not limit access to created files

MEDIUM 6.5
Maven

CVE-2020-6858

HTTP Response Splitting in Styx

MEDIUM 4.8
Maven

CVE-2020-27218

Buffer not correctly recycled in Gzip Request inflation

MEDIUM 6.5
Maven

CVE-2020-11007

Negative charge in shopping cart in Shopizer

MEDIUM 5.3
Maven

CVE-2020-27223

DOS vulnerability for Quoted Quality CSV headers

MEDIUM 6.6
Maven

CVE-2020-15171

Users with SCRIPT right can execute arbitrary code in XWiki

MEDIUM 5.3
Maven

CVE-2020-8929

Ciphertext Malleability Issue in Tink Java

MEDIUM 5.4
Maven

CVE-2020-5207

Request smuggling is possible when both chunked TE and content length specified

MEDIUM 6.5
Maven

CVE-2019-16771

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') in Armeria

Ready to move

Start Securing

Free, no credit card | First findings in minutes