Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-53598
Prompty: Arbitrary file read via file reference expansion
CVE-2026-47144
Shamefile has an arbitrary file read via shamefile.yaml in shame next
CVE-2026-45134
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
CVE-2026-25528
LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
CVE-2026-54527
jupyterlab-git extension: Stored XSS leading to RCE
CVE-2021-41134
Stored XSS in Jupyter nbdime
CVE-2022-37454
Buffer overflow in sponge queue functions
CVE-2024-12534
Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-35255
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
CVE-2024-10572
H2O Vulnerable to Denial of Service (DoS) and File Write
CVE-2024-10550
H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
CVE-2025-30402
ExecuTorch vulnerable to Heap-based Buffer Overflow attack
CVE-2024-8062
H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request
CVE-2024-6854
H2O Vulnerable to Arbitrary File Overwrite via File Export
CVE-2023-33953
Excessive Iteration in gRPC
CVE-2024-6863
H2O Vulnerable to Execution of Arbitrary Files
CVE-2024-7765
H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing
CVE-2024-46488
Heap-based Buffer Overflow in sqlite-vec
CVE-2024-12537
Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-10549
H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint
CVE-2024-7768
H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint
CVE-2024-8616
H2O Vulnerable to Arbitrary File Overwrite
CVE-2022-44244
Lin CMS vulnerable to Improper Authentication
CVE-2026-49852
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
CVE-2026-42999
OpenStack Keystone has an Authorization Bypass
CVE-2026-42998
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
CVE-2026-44394
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
CVE-2026-4372
HuggingFace transformers vulnerable to remote code execution
CVE-2026-43000
OpenStack Keystone has an Incorrect Authorization issue
CVE-2026-54262
CVE-2026-54262
CVE-2026-54260
CVE-2026-54260
CVE-2026-54261
CVE-2026-54261
CVE-2026-54259
CVE-2026-54259
CVE-2026-54263
CVE-2026-54263
CVE-2025-65896
asyncmy is vulnerable to SQL injection via crafted dict keys
CVE-2026-49360
Recce server has unauthenticated SQL execution that allows local file read/write through DuckDB
CVE-2026-10105
agno contains a SQL injection vulnerability
CVE-2026-10108
xiaomusic contains an unauthenticated path traversal vulnerability
CVE-2026-49292
Kiwi TCMS's /init-db/ page renders and responds to requests after first use
CVE-2022-42966
cleo is vulnerable to Regular Expression Denial of Service (ReDoS)
CVE-2026-52830
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
CVE-2025-68616
WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect
CVE-2026-52817
Linuxfabrik Monitoring Plugins: Sudoers may be able to obtain privilege escalation via /usr/bin/apt-get arguments
CVE-2026-49299
OpenStack Neutron has an Incorrect Authorization issue
CVE-2026-52726
Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload
CVE-2026-50181
Langroid: Path traversal in the file tools allows read/write outside configured current directory
CVE-2026-50180
Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
CVE-2025-51481
CVE-2025-51481
CVE-2026-50027
mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete
CVE-2025-65015
joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads
CVE-2026-4810
Google Agent Development Kit (ADK) has a Code Injection and Missing Authentication vulnerability
CVE-2016-8638
Session Fixation in ipsilon
CVE-2024-47533
cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes
CVE-2026-28370
OpenStack Vitrage: Unauthorized Access to the Host can Lead to Eval Injection
CVE-2024-38824
Salt vulnerable to directory traversal attack in file receiving method
CVE-2023-32321
Ckan remote code execution and private information access via crafted resource ids
Ready to move
Start Securing
Free, no credit card | First findings in minutes