Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

HIGH 8.1
PyPI

GHSA-x36p-c636-788x

Duplicate Advisory: Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

HIGH 8.1
PyPI

GHSA-q8qp-8jq6-78mc

Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

HIGH 8.1
PyPI

GHSA-mg57-j93w-g3c7

Duplicate Advisory: Picklescan has a missing detection when calling built-in python profile.Profile.runctx

HIGH 8.1
PyPI

GHSA-gq8p-2329-gh3x

Duplicate Advisory: Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

HIGH 8.1
PyPI

CVE-2025-71365

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

HIGH 8.1
PyPI

CVE-2025-71370

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

HIGH 8.1
PyPI

CVE-2025-71341

Picklescan has a missing detection when calling built-in python profile.Profile.runctx

HIGH 8.1
PyPI

CVE-2025-71376

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

HIGH 8.8
PyPI

CVE-2026-67325

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

HIGH 8.4
PyPI

CVE-2026-78675

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

HIGH 8.6
PyPI

CVE-2026-77262

MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)

HIGH 7.1
PyPI

CVE-2026-85740

lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard

HIGH 7.4
PyPI

CVE-2026-77246

MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path

HIGH 7.1
PyPI

CVE-2026-77253

MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files

HIGH 8.8
PyPI

CVE-2026-77243

MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass

HIGH 7.7
PyPI

CVE-2026-77258

MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()

HIGH 8.6
PyPI

CVE-2026-77255

MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue

HIGH 7.7
PyPI

CVE-2026-77259

MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials

HIGH 8.6
PyPI

CVE-2026-77248

MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport

HIGH 7.1
PyPI

CVE-2026-77261

MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches

HIGH 7.5
PyPI

CVE-2026-59991

psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry

HIGH 7.4
PyPI

CVE-2026-56104

Chainlit contains a session hijacking vulnerability

HIGH 8.8
PyPI

CVE-2026-86792

CVE-2026-86792

HIGH 7.5
PyPI

GHSA-39wr-7q6h-cf68

LMDeploy has an SSRF bypass

HIGH 8.8
PyPI

CVE-2026-33625

LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading

HIGH 7.7
PyPI

CVE-2026-73496

mcp-atlassian: Arbitrary server-side file read via attachment upload

HIGH 7.1
PyPI

CVE-2026-86049

Jupyter Server: 5xx request logging leaks token-bearing Referer header values

HIGH 8.4
PyPI

CVE-2026-76825

RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution

HIGH 7.0
PyPI

CVE-2026-67326

GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath

HIGH 7.0
PyPI

CVE-2026-69097

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

HIGH 7.5
PyPI

CVE-2026-87819

CVE-2026-87819

HIGH 8.1
PyPI

CVE-2026-61591

djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)

HIGH 7.1
PyPI

CVE-2026-61596

djust has broken object-level access control (IDOR)

HIGH 7.4
PyPI

CVE-2026-61592

djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)

HIGH 8.1
PyPI

CVE-2026-61593

djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session

HIGH 7.7
PyPI

CVE-2026-61595

djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data

HIGH 7.4
PyPI

CVE-2026-61590

djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG

HIGH 8.6
PyPI

CVE-2026-57586

agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution

HIGH 7.8
PyPI

CVE-2020-29367

CVE-2020-29367

HIGH 7.8
PyPI

CVE-2026-46517

lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out

HIGH 8.1
PyPI

CVE-2025-66336

Apache Doris MCP Server is vulnerable to SQL Injection via metadata query path

HIGH 8.1
PyPI

CVE-2025-71348

Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config

HIGH 8.1
PyPI

GHSA-qvp4-q2p5-22gg

Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config

HIGH 8.8
PyPI

GHSA-78fp-cf4h-g36p

Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164

HIGH 8.8
PyPI

CVE-2026-56340

vLLM introduced enhanced protection for CVE-2025-62164

HIGH 8.1
PyPI

GHSA-8mc5-7w9m-fqv6

Duplicate Advisory: Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand

HIGH 8.1
PyPI

GHSA-fcqg-3mwf-cfcf

Duplicate Advisory: Picklescan is missing detection when calling built-in Python cProfile.runctx

HIGH 7.5
PyPI

CVE-2026-87011

Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout

HIGH 7.3
PyPI

CVE-2026-12773

LiteLLM: MCP Proxy Has Improper Authentication

HIGH 7.3
PyPI

CVE-2026-12795

LiteLLM: SSO Debug Flow Has Improper Authentication

HIGH 8.1
PyPI

CVE-2026-87016

Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite

HIGH 7.8
PyPI

CVE-2021-4118

pytorch-lightning is vulnerable to Deserialization of Untrusted Data

HIGH 7.8
PyPI

CVE-2026-31221

PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization

HIGH 7.5
PyPI

CVE-2024-8020

PyTorch Lightning denial of service vulnerability

Ready to move

Start Securing

Free, no credit card | First findings in minutes