Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-62364
wlc may disclose API tokens to project-configured URLs
CVE-2026-12372
CVE-2026-12372
CVE-2026-54548
kas Persistently Disables SSH Host Key Checking
CVE-2026-81723
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
CVE-2026-71514
NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure
CVE-2026-55403
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
CVE-2026-48588
Django: cache middleware may expose private responses when unrelated request cookies are present
CVE-2026-7666
Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
CVE-2026-53538
python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
CVE-2026-48156
pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams
CVE-2026-44405
Paramiko rsakey.py allows the SHA-1 algorithm
CVE-2026-4539
Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
GHSA-hqv3-xm29-p9hq
Duplicate Advisory: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
CVE-2026-53540
python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
CVE-2026-53537
python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
CVE-2026-50266
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
CVE-2026-54282
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
CVE-2026-6873
Django: signed cookies are vulnerable to salt namespace collisions
CVE-2026-48524
PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
CVE-2026-49854
Tornado has out-of-bounds memory access via C extension
CVE-2026-48587
Django: has_vary_header may expose cached responses when Vary values contain whitespace
CVE-2026-8404
Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
CVE-2026-8088
OSGeo GDAL vulnerable to out-of-bounds read
CVE-2026-4292
Django vulnerable to privilege abuse in ModelAdmin.list_editable
CVE-2026-25674
Django has a Race Condition vulnerability
CVE-2026-26013
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
CVE-2025-59682
Django vulnerable to partial directory traversal via archives
CVE-2025-3777
Transformers's Improper Input Validation vulnerability can be exploited through username injection
CVE-2025-3730
PyTorch Improper Resource Shutdown or Release vulnerability
CVE-2025-2953
PyTorch susceptible to local Denial of Service
CVE-2024-53861
PyJWT Issuer field partial matches allowed
CVE-2024-45314
Flask-AppBuilder's login form allows browser to cache sensitive fields
CVE-2024-8863
Aim Stored XSS through TEXT EXPLORER
CVE-2023-23611
LTI 1.3 Grade Pass Back Implementation has Missing Authorization Vulnerability
CVE-2024-41124
[PUNCIA] [CWE-319] Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`
CVE-2024-32882
Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`
CVE-2024-34062
tqdm CLI arguments injection attack
CVE-2024-32969
vantage6 collaboration admins can extend their influence by expanding the collaboration
CVE-2024-34715
Fides Webserver Logs Hosted Database Password Partial Exposure Vulnerability
CVE-2024-29199
Unauthenticated views may expose information to anonymous users
CVE-2024-24559
Vyper sha3 codegen bug
CVE-2023-49297
PyDrive2's unsafe YAML deserialization in LoadSettingsFile allows arbitrary code execution
CVE-2023-23934
Incorrect parsing of nameless cookies leads to __Host- cookies bypass
CVE-2025-27145
copyparty renders unsanitized filenames as HTML when user uploads empty files
CVE-2024-24560
Vyper's external calls can overflow return data to return input buffer
CVE-2024-22194
cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code
CVE-2024-22193
vantage6 may create unencrypted tasks in encrypted collaboration
CVE-2023-46126
Fides JavaScript Injection Vulnerability in Privacy Center URL
CVE-2023-41057
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in hyper-bump-it
CVE-2023-42458
Zope vulnerable to Stored Cross Site Scripting with SVG images
CVE-2023-41335
matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes
CVE-2023-2970
MindSpore vulnerable to memory corruption
CVE-2024-23329
changedetection.io API endpoint is not secured with API token
CVE-2023-50263
Unauthenticated db-file-storage views
CVE-2023-44389
Zope management interface vulnerable to stored cross site scripting via the title property
CVE-2023-42453
matrix-synapse vulnerable to improper validation of receipts allows forged read receipts
CVE-2023-26112
configobj ReDoS exploitable by developer using values in a server-side configuration file
Ready to move
Start Securing
Free, no credit card | First findings in minutes