Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

CRITICAL 9.8
PyPI

CVE-2026-56315

PickleScan has multiple stdlib modules with direct RCE not in blocklist

CRITICAL 9.8
PyPI

GHSA-g7vj-qw6x-g3p8

Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist

CRITICAL 9.9
PyPI

CVE-2026-57149

plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection

CRITICAL 10.0
PyPI

CVE-2026-77244

[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token

CRITICAL 9.1
PyPI

CVE-2026-85734

lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks

CRITICAL 9.1
PyPI

CVE-2026-59163

Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass

CRITICAL 9.8
PyPI

CVE-2025-66455

LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py

CRITICAL 9.1
PyPI

CVE-2026-61594

djust has an authorization bypass on the WebSocket/SSE mount path

CRITICAL 9.8
PyPI

CVE-2025-59953

LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy

CRITICAL 9.8
PyPI

CVE-2026-56260

Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server

CRITICAL 9.8
PyPI

CVE-2026-59178

ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade

CRITICAL 9.6
PyPI

CVE-2026-59151

Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover

CRITICAL 10.0
PyPI

CVE-2026-59971

MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)

CRITICAL 9.3
PyPI

CVE-2026-74881

CVE-2026-74881

CRITICAL 9.8
PyPI

CVE-2022-0845

Code Injection in PyTorch Lightning

CRITICAL 9.8
PyPI

CVE-2026-44484

Compromise of PyTorch Lightning PyPi Package Versions

CRITICAL 9.1
PyPI

CVE-2024-5980

pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint

CRITICAL 9.8
PyPI

CVE-2024-5452

Remote code execution in pytorch lightning

CRITICAL 9.1
PyPI

CVE-2024-8019

PyTorch Lightning path traversal vulnerability

CRITICAL 9.8
PyPI

CVE-2026-54569

senaite.core Vulnerable to Eval Injection and Missing Authorization

CRITICAL 9.3
PyPI

CVE-2026-71428

unstructured: Server-Side Request Forgery in the URL-based partitioning

CRITICAL 9.8
PyPI

CVE-2026-55546

qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

CRITICAL 9.8
PyPI

CVE-2026-45018

Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution

CRITICAL 9.1
PyPI

CVE-2026-55640

nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )

CRITICAL 9.0
PyPI

CVE-2026-62674

Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE

CRITICAL 9.1
PyPI

CVE-2026-55536

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

CRITICAL 9.1
PyPI

CVE-2026-55247

plone.app.event vulnerable to denial of service via iCalendar import

CRITICAL 10.0
PyPI

CVE-2026-53710

mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server

CRITICAL 9.1
PyPI

CVE-2026-58473

Cognee allows non-superusers to overwrite global LLM configuration

CRITICAL 9.8
PyPI

CVE-2026-37004

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

CRITICAL 10.0
PyPI

CVE-2026-61539

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

CRITICAL 9.1
PyPI

CVE-2026-55248

plone.app.portlets vulnerable to denial of service via RSS feed portlet

CRITICAL 9.8
PyPI

CVE-2026-33264

CVE-2026-33264

CRITICAL 9.1
PyPI

CVE-2026-27197

Sentry: Improper authentication on SAML SSO process allows user identity linking

CRITICAL 9.8
PyPI

CVE-2020-7941

Plone Unauthenticated Write Vulnerability

CRITICAL 9.8
PyPI

CVE-2026-79675

NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)

CRITICAL 9.8
PyPI

GHSA-6v84-v468-3c7f

Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs

CRITICAL 9.6
PyPI

CVE-2026-42557

JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content

Ready to move

Start Securing

Free, no credit card | First findings in minutes