Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
GHSA-8pcw-h6w9-h46g
plone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length
CVE-2026-57576
plone.app.dexterity has a Denial of Service due to excessive title or description length
CVE-2026-56315
PickleScan has multiple stdlib modules with direct RCE not in blocklist
GHSA-g7vj-qw6x-g3p8
Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist
CVE-2026-56260
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
MAL-2026-16475
MemoryOS 2.0.34 was published with a credential-stealing binary
CVE-2026-93421
Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint
GHSA-x36p-c636-788x
Duplicate Advisory: Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
GHSA-q8qp-8jq6-78mc
Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
GHSA-mg57-j93w-g3c7
Duplicate Advisory: Picklescan has a missing detection when calling built-in python profile.Profile.runctx
GHSA-gq8p-2329-gh3x
Duplicate Advisory: Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
CVE-2025-71365
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
CVE-2025-71370
Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
CVE-2025-71341
Picklescan has a missing detection when calling built-in python profile.Profile.runctx
CVE-2025-71376
Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
CVE-2026-61652
Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)
CVE-2026-61541
Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service
CVE-2026-57149
plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection
CVE-2026-67325
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
CVE-2026-78675
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
CVE-2026-78679
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
CVE-2026-91130
Home Assistant: XSS in Statistics Graph Card
CVE-2026-77244
[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token
CVE-2026-77251
MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)
CVE-2026-77257
MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths
CVE-2026-77249
MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup
CVE-2026-77262
MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)
CVE-2026-85740
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
CVE-2026-86062
lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content
CVE-2026-83805
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs
CVE-2026-77266
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call
CVE-2026-77246
MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path
CVE-2026-77253
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files
CVE-2026-77274
MCP Atlassian: SSRF Protection Bypass
CVE-2026-85709
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses
CVE-2026-62364
wlc may disclose API tokens to project-configured URLs
CVE-2026-77250
MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions
CVE-2026-77267
mcp-atlassian has an incomplete SSRF remediation
CVE-2026-77270
MCP Atlassian: Arbitrary File Read via Upload Attachment Tools
CVE-2026-77272
MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler
CVE-2026-91129
Home Assistant: mDNS Server-Side Request Forgery
CVE-2026-77243
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass
CVE-2026-77258
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()
CVE-2026-77260
MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)
CVE-2026-83801
Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text
CVE-2026-77265
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow
CVE-2026-77268
MCP Atlassian: Insecure File Permissions on OAuth Token Storage
CVE-2026-77255
MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue
CVE-2026-77259
MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials
CVE-2026-85725
lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function
CVE-2026-77269
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)
CVE-2026-77248
MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport
CVE-2026-77261
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches
CVE-2026-77247
MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters
CVE-2026-77271
MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)
CVE-2026-77528
Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation
CVE-2026-85734
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
CVE-2026-59991
psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry
CVE-2026-62282
OpenCVE: Server-Side Request Forgery (SSRF) in notifications
CVE-2026-56074
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
Ready to move
Start Securing
Free, no credit card | First findings in minutes