Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-49463
NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries
CVE-2026-49833
DSpace: Path Traversal is possible through LDN message generation
CVE-2026-49830
DSpace: ORE resource URI does not validate scheme for non-web resources
CVE-2026-49831
DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path
CVE-2026-49328
Apache Fesod is vulnerable to Server-Side Request Forgery through its UrlImageConverter component
CVE-2024-52980
Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
CVE-2025-48977
Apache Ignite REST API Has a Relative Path Traversal Vulnerability
CVE-2022-35278
HTML Injection in ActiveMQ Artemis Web Console
CVE-2024-34517
Neo4j Cypher component mishandles IMMUTABLE privileges
CVE-2024-23689
ClickHouse vulnerable to client certificate password exposure in client exception
CVE-2023-45860
Hazelcast Platform permission checking in CSV File Source connector
CVE-2021-26920
Druid ingestion system Authenticated users can read data from other sources than intended
CVE-2024-0758
JavaScript execution via malicious molfiles (XSS)
CVE-2024-23686
Insertion of Sensitive Information into Log File in OWASP DependencyCheck
CVE-2021-23339
HTTP Request Smuggling in akka-http-core
CVE-2021-21028
Reflected Cross-site Scripting (XSS) in ACS Commons
CVE-2022-25842
Path Traversal in com.alibaba.oneagent:one-java-agent-plugin
CVE-2021-23408
Prototype Pollution in GraphHopper
CVE-2024-23685
Hard-coded System User Credentials in Folio Data Export Spring module
CVE-2021-21344
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-32730
No CSRF protection on the password change form
CVE-2021-21429
Creation of Temporary File in Directory with Insecure Permissions in the OpenAPI Generator Maven plugin
CVE-2021-21349
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2021-21343
XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights
CVE-2021-21346
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-28164
Authorization Before Parsing and Canonicalization in jetty
CVE-2021-29506
Navigate endpoint is vulnerable to regex injection that may lead to Denial of Service.
CVE-2021-3503
Metrics exposure in Wildfly
CVE-2020-26234
Disabled Hostname Verification in Opencast
CVE-2021-21347
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-29480
Ratpack's default client side session signing key is highly predictable
CVE-2021-21364
Generated Code Contains Local Information Disclosure Vulnerability
CVE-2022-35697
AEM WCM Core Components CVG Image vulnerable to Reflected Cross-site Scripting
CVE-2021-39194
Improper Handling of Missing Values in kaml
CVE-2021-21342
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2021-21345
XStream is vulnerable to a Remote Command Execution attack
CVE-2021-4178
fabric8 kubernetes-client vulnerable
CVE-2021-21430
Creation of Temporary File in Directory with Insecure Permissions in auto-generated Java, Scala code
CVE-2021-32643
StaticFile.fromUrl can leak presence of a directory
CVE-2021-32731
The reset password form reveal users email address
CVE-2021-21350
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21351
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39140
XStream can cause a Denial of Service
CVE-2021-29481
Unencrypted storage of client side sessions
CVE-2022-28820
Page Compare Reflected Cross-site Scripting (XSS) vulnerability
CVE-2021-43841
Cross-site Scripting by SVG upload in xwiki-platform
CVE-2021-21348
XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)
CVE-2022-3171
protobuf-java has a potential Denial of Service issue
CVE-2021-21290
Local Information Disclosure Vulnerability in Netty on Unix-Like systems
CVE-2021-43797
HTTP request smuggling in netty
CVE-2021-28168
Local information disclosure via system temporary directory
CVE-2020-15250
TemporaryFolder on unix-like systems does not limit access to created files
CVE-2020-6858
HTTP Response Splitting in Styx
CVE-2020-27218
Buffer not correctly recycled in Gzip Request inflation
CVE-2020-11007
Negative charge in shopping cart in Shopizer
CVE-2020-27223
DOS vulnerability for Quoted Quality CSV headers
CVE-2020-15171
Users with SCRIPT right can execute arbitrary code in XWiki
CVE-2020-8929
Ciphertext Malleability Issue in Tink Java
CVE-2020-5207
Request smuggling is possible when both chunked TE and content length specified
CVE-2019-16771
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') in Armeria
Ready to move
Start Securing
Free, no credit card | First findings in minutes