Launch Week Day 1: Announcing Security Design Review

Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

HIGH 7.4
PyPI

CVE-2026-48526

PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed

HIGH 7.5
PyPI

CVE-2026-46373

SQLFluff: Recursive Stack Overflow in Parser

HIGH 7.5
PyPI

CVE-2026-46374

SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser

HIGH 7.0
PyPI

CVE-2026-25087

Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering

HIGH 7.1
PyPI

CVE-2026-48099

WsgiDAV encoded dot segments can escape filesystem share roots

HIGH 8.8
PyPI

CVE-2026-42305

Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows

HIGH 7.8
PyPI

CVE-2026-46439

compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)

HIGH 8.1
PyPI

CVE-2026-48060

Litestar has HTML Injection Through its CSRF Token

HIGH 7.5
PyPI

CVE-2017-1002153

Koji blacklisted paths workaround

HIGH 7.4
PyPI

CVE-2023-48054

Missing SSL certificate validation in localstack

HIGH 7.5
PyPI

CVE-2022-25508

Improper Authentication in FreeTAKServer

HIGH 7.5
PyPI

CVE-2021-31606

furlongm openvpn-monitor allows Authorization Bypass to disconnect arbitrary clients

HIGH 7.5
PyPI

CVE-2022-42731

django-mfa2 vulnerable to MFA Replay attack

HIGH 7.8
PyPI

CVE-2020-29367

blosc2 heap-based buffer overflow

HIGH 7.5
PyPI

CVE-2026-22777

ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler

HIGH 7.5
PyPI

CVE-2025-21607

CVE-2025-21607

HIGH 7.5
PyPI

CVE-2025-32021

CVE-2025-32021

HIGH 7.5
PyPI

CVE-2024-39689

CVE-2024-39689

HIGH 7.1
PyPI

CVE-2024-32977

OctoPrint has an Authentication Bypass via X-Forwarded-For Header when autologinLocal is enabled

HIGH 7.5
PyPI

CVE-2024-41672

sniff_csv provides filesystem access even when enable_external_access is disabled in duckdb

HIGH 7.3
PyPI

CVE-2022-36070

Poetry vulnerable to Untrusted Search Path leading to Local Code Execution on Windows

HIGH 7.8
PyPI

CVE-2024-23346

CVE-2024-23346

HIGH 8.1
PyPI

CVE-2022-39327

Improper Control of Generation of Code ('Code Injection') in Azure CLI

HIGH 7.5
PyPI

CVE-2026-43891

changedetection.io has an Arbitrary Local File Read via a crafted backup restore

HIGH 7.5
PyPI

CVE-2024-26134

Potential buffer overflow in CBOR2 decoder

HIGH 7.5
PyPI

CVE-2025-32013

CVE-2025-32013

HIGH 7.5
PyPI

CVE-2024-52581

Litestar allows unbounded resource consumption (DoS vulnerability)

HIGH 7.5
PyPI

CVE-2024-26130

cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override

HIGH 7.5
PyPI

CVE-2024-35178

Jupyter server on Windows discloses Windows user password hash

HIGH 7.5
PyPI

CVE-2023-42261

Withdrawn Advisory: Mobile Security Framework (MobSF) Vulnerable to Insecure Permissions

HIGH 8.8
PyPI

CVE-2023-38759

CVE-2023-38759

HIGH 8.0
PyPI

CVE-2025-6279

CVE-2025-6279

HIGH 8.8
PyPI

CVE-2023-6730

CVE-2023-6730

HIGH 7.8
PyPI

CVE-2023-7018

CVE-2023-7018

HIGH 7.5
PyPI

CVE-2025-2099

CVE-2025-2099

HIGH 8.1
PyPI

CVE-2024-49048

CVE-2024-49048

HIGH 7.5
PyPI

CVE-2025-2148

CVE-2025-2148

HIGH 7.4
PyPI

CVE-2012-0051

CVE-2012-0051

HIGH 8.8
PyPI

CVE-2024-31411

CVE-2024-31411

HIGH 8.8
PyPI

CVE-2023-25617

CVE-2023-25617

HIGH 7.8
PyPI

CVE-2023-20898

CVE-2023-20898

HIGH 7.8
PyPI

CVE-2021-25315

CVE-2021-25315

HIGH 8.8
PyPI

CVE-2021-47935

CVE-2021-47935

HIGH 7.5
PyPI

CVE-2023-47163

CVE-2023-47163

HIGH 7.5
PyPI

CVE-2025-25301

CVE-2025-25301

HIGH 8.8
PyPI

CVE-2024-11392

CVE-2024-11392

HIGH 8.8
PyPI

CVE-2023-5289

CVE-2023-5289

HIGH 7.5
PyPI

CVE-2022-3290

CVE-2022-3290

Ready to move

Start Securing

Free, no credit card | First findings in minutes