Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

13,844 vulnerabilities

MEDIUM 6.5
PyPI

GHSA-8pcw-h6w9-h46g

plone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length

MEDIUM 6.5
PyPI

CVE-2026-57576

plone.app.dexterity has a Denial of Service due to excessive title or description length

CRITICAL 9.8
PyPI

CVE-2026-56315

PickleScan has multiple stdlib modules with direct RCE not in blocklist

CRITICAL 9.8
PyPI

GHSA-g7vj-qw6x-g3p8

Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist

CRITICAL 9.8
PyPI

CVE-2026-56260

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

UNKNOWN
PyPI

MAL-2026-16475

MemoryOS 2.0.34 was published with a credential-stealing binary

UNKNOWN
PyPI

CVE-2026-93421

Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint

HIGH 8.1
PyPI

GHSA-x36p-c636-788x

Duplicate Advisory: Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

HIGH 8.1
PyPI

GHSA-q8qp-8jq6-78mc

Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

HIGH 8.1
PyPI

GHSA-mg57-j93w-g3c7

Duplicate Advisory: Picklescan has a missing detection when calling built-in python profile.Profile.runctx

HIGH 8.1
PyPI

GHSA-gq8p-2329-gh3x

Duplicate Advisory: Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

HIGH 8.1
PyPI

CVE-2025-71365

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

HIGH 8.1
PyPI

CVE-2025-71370

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

HIGH 8.1
PyPI

CVE-2025-71341

Picklescan has a missing detection when calling built-in python profile.Profile.runctx

HIGH 8.1
PyPI

CVE-2025-71376

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

UNKNOWN
PyPI

CVE-2026-61652

Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)

UNKNOWN
PyPI

CVE-2026-61541

Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service

CRITICAL 9.9
PyPI

CVE-2026-57149

plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection

HIGH 8.8
PyPI

CVE-2026-67325

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

HIGH 8.4
PyPI

CVE-2026-78675

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

MEDIUM 6.5
PyPI

CVE-2026-78679

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

UNKNOWN
PyPI

CVE-2026-91130

Home Assistant: XSS in Statistics Graph Card

CRITICAL 10.0
PyPI

CVE-2026-77244

[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token

UNKNOWN
PyPI

CVE-2026-77251

MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)

UNKNOWN
PyPI

CVE-2026-77257

MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths

MEDIUM 5.3
PyPI

CVE-2026-77249

MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup

HIGH 8.6
PyPI

CVE-2026-77262

MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)

HIGH 7.1
PyPI

CVE-2026-85740

lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard

MEDIUM 6.1
PyPI

CVE-2026-86062

lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content

MEDIUM 6.4
PyPI

CVE-2026-83805

Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs

MEDIUM 6.5
PyPI

CVE-2026-77266

MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call

HIGH 7.4
PyPI

CVE-2026-77246

MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path

HIGH 7.1
PyPI

CVE-2026-77253

MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files

UNKNOWN
PyPI

CVE-2026-77274

MCP Atlassian: SSRF Protection Bypass

MEDIUM 5.3
PyPI

CVE-2026-85709

lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses

LOW 2.3
PyPI

CVE-2026-62364

wlc may disclose API tokens to project-configured URLs

MEDIUM 6.1
PyPI

CVE-2026-77250

MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions

UNKNOWN
PyPI

CVE-2026-77267

mcp-atlassian has an incomplete SSRF remediation

MEDIUM 6.5
PyPI

CVE-2026-77270

MCP Atlassian: Arbitrary File Read via Upload Attachment Tools

MEDIUM 5.4
PyPI

CVE-2026-77272

MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler

MEDIUM 5.4
PyPI

CVE-2026-91129

Home Assistant: mDNS Server-Side Request Forgery

HIGH 8.8
PyPI

CVE-2026-77243

MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass

HIGH 7.7
PyPI

CVE-2026-77258

MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()

UNKNOWN
PyPI

CVE-2026-77260

MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)

MEDIUM 5.4
PyPI

CVE-2026-83801

Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text

MEDIUM 5.9
PyPI

CVE-2026-77265

MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow

MEDIUM 5.5
PyPI

CVE-2026-77268

MCP Atlassian: Insecure File Permissions on OAuth Token Storage

HIGH 8.6
PyPI

CVE-2026-77255

MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue

HIGH 7.7
PyPI

CVE-2026-77259

MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials

MEDIUM 5.9
PyPI

CVE-2026-85725

lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function

MEDIUM 6.5
PyPI

CVE-2026-77269

MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)

HIGH 8.6
PyPI

CVE-2026-77248

MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport

HIGH 7.1
PyPI

CVE-2026-77261

MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches

UNKNOWN
PyPI

CVE-2026-77247

MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters

UNKNOWN
PyPI

CVE-2026-77271

MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)

MEDIUM 5.3
PyPI

CVE-2026-77528

Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation

CRITICAL 9.1
PyPI

CVE-2026-85734

lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks

HIGH 7.5
PyPI

CVE-2026-59991

psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry

MEDIUM 6.5
PyPI

CVE-2026-62282

OpenCVE: Server-Side Request Forgery (SSRF) in notifications

MEDIUM 5.5
PyPI

CVE-2026-56074

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

Ready to move

Start Securing

Free, no credit card | First findings in minutes