Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-48522
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
CVE-2026-48523
PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys
CVE-2026-48526
PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
CVE-2026-48525
PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
CVE-2026-48524
PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
CVE-2025-3000
PyTorch is vulnerable to memory corruption through its torch.jit.script function
CVE-2020-29367
CVE-2020-29367
CVE-2026-48155
pypdf: Possible large memory usage for large offsets for layout mode text
CVE-2026-48156
pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams
CVE-2026-49854
Tornado has out-of-bounds memory access via C extension
CVE-2026-46373
SQLFluff: Recursive Stack Overflow in Parser
CVE-2026-46374
SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser
CVE-2026-49818
CVE-2026-49818
CVE-2026-48710
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
CVE-2026-46695
BoxLite: Permission Bypass Allows Modification of Read-Only Files
CVE-2026-47157
aiograpi: Unsafe signup challenge path handling
CVE-2026-46703
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
CVE-2026-53954
Bugsink: DOS using large numbers of event tags
CVE-2026-2734
MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks
CVE-2026-25087
Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
CVE-2026-48099
WsgiDAV encoded dot segments can escape filesystem share roots
CVE-2025-51481
CVE-2025-51481
CVE-2026-48053
Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset
CVE-2025-53009
MaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit
CVE-2025-48074
OpenEXR Out-Of-Memory via Unbounded File Header Values
CVE-2026-47712
Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`
CVE-2026-47213
BoxLite has a Timeout Bypass Vulnerability
CVE-2026-47734
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
CVE-2026-42563
Dulwich Vulnerable to Command Injection via Merge Driver Path
CVE-2026-42305
Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows
CVE-2026-46645
SQLAdmin: Authorization Bypass on `ajax_lookup`
CVE-2026-48045
python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood
CVE-2026-48039
Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
CVE-2026-45106
Weblate: Stored HTML injection in editor search preview
CVE-2026-47781
PDM: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing
CVE-2015-5286
OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service
CVE-2026-46439
compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)
CVE-2026-47763
PDM: Project-Local State and Config Writes Follow Symlinks
CVE-2026-47764
PDM wheel installation leads to Path Traversal via overridden write_to_fs
CVE-2012-5571
OpenStack Keystone intended authorization restrictions bypass
CVE-2026-48060
Litestar has HTML Injection Through its CSRF Token
CVE-2026-48061
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
CVE-2025-70960
Tendenci CMS contains a stored Cross-site Scripting (XSS) vulnerability in the Forums module
CVE-2022-33124
Withdrawn: Denial of Service in aiohttp
CVE-2024-3408
Authentication bypass in dtale
CVE-2017-1002153
Koji blacklisted paths workaround
CVE-2013-0212
OpenStack Glance logs user name and password in cleartext
CVE-2023-48054
Missing SSL certificate validation in localstack
CVE-2026-46497
Crawlee for Python: SSRF via sitemap-derived URLs
CVE-2022-25508
Improper Authentication in FreeTAKServer
CVE-2021-31604
furlongm openvpn-monitor allows CSRF to disconnect an arbitrary client
CVE-2021-31606
furlongm openvpn-monitor allows Authorization Bypass to disconnect arbitrary clients
CVE-2020-19002
Mezzanine Cross Site Scripting (XSS) vulnerability
CVE-2020-18699
Lin-CMS-Flask Cross Site Scripting (XSS) vulnerability
CVE-2020-18698
Lin-CMS-Flask vulnerable to Improper Authentication
CVE-2024-11319
django CMS Cross-Site Scripting (XSS)
CVE-2022-42731
django-mfa2 vulnerable to MFA Replay attack
Ready to move
Start Securing
Free, no credit card | First findings in minutes