Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2022-37454
Buffer overflow in sponge queue functions
CVE-2024-46488
Heap-based Buffer Overflow in sqlite-vec
CVE-2025-65896
asyncmy is vulnerable to SQL injection via crafted dict keys
CVE-2026-52830
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
CVE-2026-50027
mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete
CVE-2016-8638
Session Fixation in ipsilon
CVE-2024-47533
cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes
CVE-2026-28370
OpenStack Vitrage: Unauthorized Access to the Host can Lead to Eval Injection
CVE-2024-38824
Salt vulnerable to directory traversal attack in file receiving method
CVE-2023-32321
Ckan remote code execution and private information access via crafted resource ids
CVE-2024-21669
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
CVE-2026-47731
NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)
CVE-2025-49652
BackendAI Missing Authentication for Critical Function
CVE-2026-29090
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
CVE-2026-29080
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
CVE-2025-2000
Qiskit allows arbitrary code execution decoding QPY format versions < 13
CVE-2026-44484
Compromise of PyTorch Lightning PyPi Package Versions
CVE-2015-8914
OpenStack Neutron allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism
CVE-2025-68664
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
CVE-2017-7214
OpenStack Nova logs sensitive context from notification exceptions
CVE-2019-15753
OpenStack os-vif Ageing time of 0 disables linuxbridge MAC learning
CVE-2019-17134
OpenStack Octavia Amphora-Agent not requiring Client-Certificate
CVE-2026-40088
PraisonAI Vulnerable to OS Command Injection
CVE-2026-25879
Langroid has Prompt to SQL Injection, Leading to RCE
CVE-2025-46724
Langroid has a Code Injection vulnerability in TableChatAgent
CVE-2022-34558
CVE-2022-34558
CVE-2026-44336
PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection
CVE-2026-55166
Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise
CVE-2023-40889
Heap-based buffer overflow in ZBar
CVE-2026-43948
wger: cross-tenant password reset and plaintext disclosure via gym=None bypass
CVE-2022-2650
wger vulnerable to brute force attempts
CVE-2018-25082
weixin-python XML External Entity vulnerability
CVE-2025-68398
Weblate is vulnerable to RCE through Git config file overwrite
CVE-2016-3953
web2py remote code execution via hardcoded encryption key in session.connect function
CVE-2016-10321
web2py is vulnerable to password brute-force attack
CVE-2024-9052
vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
CVE-2025-47277
vLLM Allows Remote Code Execution via PyNcclPipe Communication Service
CVE-2024-11041
vLLM Deserialization of Untrusted Data vulnerability
CVE-2026-22778
vLLM has RCE In Video Processing
CVE-2024-5826
vanna vulnerable to remote code execution caused by prompt injection
CVE-2026-45369
utcp-cli Vulnerable to Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol
CVE-2026-30625
Upsonic: remote code execution vulnerability in its MCP server/task creation functionality
CVE-2025-64712
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
CVE-2026-22584
Salesforce Uni2TS has a Code Injection vulnerability
CVE-2019-25101
Header injection in TurboGears
CVE-2023-33175
toui allows user-specific variables to be shared between users
CVE-2024-35198
TorchServe vulnerable to bypass of allowed_urls configuration
CVE-2023-43654
TorchServe Server-Side Request Forgery vulnerability
CVE-2025-55037
TkEasyGUI Vulnerable to OS Command Injection
CVE-2025-61492
terminal-controller-mcp vulnerable to Command Injection
CVE-2023-25668
TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation
CVE-2024-0937
Deserialization of untrusted data in synthcity
CVE-2026-31220
PySyft server-side arbitrary Python execution after code approval
CVE-2012-4406
OpenStack Object Storage (swift) Code Injection vulnerability
CVE-2025-14931
Hugging Face smolagents: Unsafe deserialization in Remote Python Executor leads to RCE
CVE-2025-5120
smolagents has Sandbox Escape Vulnerability in the local_python_executor.py Module
CVE-2022-31558
Tooxie Shiva 0.10.0 allows absolute path traversal because Flask send_file function used unsafely
Ready to move
Start Securing
Free, no credit card | First findings in minutes