Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CRITICAL 9.8
CVE-2026-56315
PickleScan has multiple stdlib modules with direct RCE not in blocklist
CRITICAL 9.8
GHSA-g7vj-qw6x-g3p8
Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist
CRITICAL 9.9
CVE-2026-57149
plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection
CRITICAL 10.0
CVE-2026-77244
[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token
CRITICAL 9.1
CVE-2026-85734
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
CRITICAL 9.1
CVE-2026-59163
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
CRITICAL 9.8
CVE-2025-66455
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
CRITICAL 9.1
CVE-2026-61594
djust has an authorization bypass on the WebSocket/SSE mount path
CRITICAL 9.8
CVE-2025-59953
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
CRITICAL 9.8
CVE-2026-56260
Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server
CRITICAL 9.8
CVE-2026-59178
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
CRITICAL 9.6
CVE-2026-59151
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
CRITICAL 10.0
CVE-2026-59971
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
CRITICAL 9.3
CVE-2026-74881
CVE-2026-74881
CRITICAL 9.8
CVE-2022-0845
Code Injection in PyTorch Lightning
CRITICAL 9.8
CVE-2026-44484
Compromise of PyTorch Lightning PyPi Package Versions
CRITICAL 9.1
CVE-2024-5980
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
CRITICAL 9.8
CVE-2024-5452
Remote code execution in pytorch lightning
CRITICAL 9.1
CVE-2024-8019
PyTorch Lightning path traversal vulnerability
CRITICAL 9.8
CVE-2026-54569
senaite.core Vulnerable to Eval Injection and Missing Authorization
CRITICAL 9.3
CVE-2026-71428
unstructured: Server-Side Request Forgery in the URL-based partitioning
CRITICAL 9.8
CVE-2026-55546
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
CRITICAL 9.8
CVE-2026-45018
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
CRITICAL 9.1
CVE-2026-55640
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
CRITICAL 9.0
CVE-2026-62674
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
CRITICAL 9.1
CVE-2026-55536
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
CRITICAL 9.1
CVE-2026-55247
plone.app.event vulnerable to denial of service via iCalendar import
CRITICAL 10.0
CVE-2026-53710
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
CRITICAL 9.1
CVE-2026-58473
Cognee allows non-superusers to overwrite global LLM configuration
CRITICAL 9.8
CVE-2026-37004
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
CRITICAL 10.0
CVE-2026-61539
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
CRITICAL 9.1
CVE-2026-55248
plone.app.portlets vulnerable to denial of service via RSS feed portlet
CRITICAL 9.8
CVE-2026-33264
CVE-2026-33264
CRITICAL 9.1
CVE-2026-27197
Sentry: Improper authentication on SAML SSO process allows user identity linking
CRITICAL 9.8
CVE-2020-7941
Plone Unauthenticated Write Vulnerability
CRITICAL 9.8
CVE-2026-79675
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
CRITICAL 9.8
GHSA-6v84-v468-3c7f
Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs
CRITICAL 9.6
CVE-2026-42557
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Ready to move
Start Securing
Free, no credit card | First findings in minutes