Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
GHSA-8pcw-h6w9-h46g
plone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length
CVE-2026-57576
plone.app.dexterity has a Denial of Service due to excessive title or description length
CVE-2026-78679
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
CVE-2026-77249
MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup
CVE-2026-86062
lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content
CVE-2026-83805
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs
CVE-2026-77266
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call
CVE-2026-85709
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses
CVE-2026-77250
MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions
CVE-2026-77270
MCP Atlassian: Arbitrary File Read via Upload Attachment Tools
CVE-2026-77272
MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler
CVE-2026-91129
Home Assistant: mDNS Server-Side Request Forgery
CVE-2026-83801
Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text
CVE-2026-77265
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow
CVE-2026-77268
MCP Atlassian: Insecure File Permissions on OAuth Token Storage
CVE-2026-85725
lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function
CVE-2026-77269
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)
CVE-2026-77528
Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation
CVE-2026-62282
OpenCVE: Server-Side Request Forgery (SSRF) in notifications
CVE-2026-56074
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
CVE-2025-51481
CVE-2025-51481
CVE-2026-73497
MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)
CVE-2026-86000
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
CVE-2026-85999
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
CVE-2023-41052
incorrect order of evaluation of side effects for some builtins
CVE-2026-69147
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
CVE-2026-77401
Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions
CVE-2026-85078
sanic chunked trailer request smuggling allows hidden second request execution
CVE-2026-62949
AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION
CVE-2026-57173
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
CVE-2026-61589
djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
CVE-2026-61588
djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client
CVE-2024-58384
Tornado has a CRLF injection in CurlAsyncHTTPClient headers
CVE-2024-14029
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado
CVE-2026-91992
Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse
CVE-2026-12797
BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints
CVE-2026-12799
BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
CVE-2026-12798
BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
CVE-2026-12796
BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
GHSA-vfm7-4h43-gp6m
Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service
CVE-2026-23679
CVE-2026-23679
CVE-2026-47104
CVE-2026-47104
CVE-2026-74871
CVE-2026-74871
CVE-2026-88006
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
CVE-2026-87012
Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
CVE-2026-87013
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
CVE-2026-12770
LiteLLM: Admin Key Handler Has Improper Authorization
CVE-2026-87014
Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
CVE-2026-87015
Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication
CVE-2026-12771
LiteLLM: M2M JWT Handler Has Improper Authorization
CVE-2026-12772
LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
CVE-2026-87017
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
CVE-2026-87994
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
CVE-2026-88005
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
CVE-2026-87997
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
CVE-2026-73619
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
CVE-2026-32773
CVE-2026-32773
CVE-2026-73621
GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count
CVE-2026-81680
CVE-2026-81680
CVE-2026-12261
CVE-2026-12261
Ready to move
Start Securing
Free, no credit card | First findings in minutes