Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

MEDIUM 5.5
PyPI

CVE-2026-47144

Shamefile has an arbitrary file read via shamefile.yaml in shame next

MEDIUM 5.8
PyPI

CVE-2026-25528

LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection

MEDIUM 5.5
PyPI

CVE-2024-35255

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

MEDIUM 6.5
PyPI

CVE-2024-6863

H2O Vulnerable to Execution of Arbitrary Files

MEDIUM 6.6
PyPI

CVE-2022-44244

Lin CMS vulnerable to Improper Authentication

MEDIUM 6.0
PyPI

CVE-2026-42999

OpenStack Keystone has an Authorization Bypass

MEDIUM 6.0
PyPI

CVE-2026-42998

OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential

MEDIUM 6.0
PyPI

CVE-2026-44394

OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token

MEDIUM 6.0
PyPI

CVE-2026-43000

OpenStack Keystone has an Incorrect Authorization issue

MEDIUM 4.3
PyPI

CVE-2026-54262

CVE-2026-54262

MEDIUM 6.5
PyPI

CVE-2026-54261

CVE-2026-54261

MEDIUM 4.3
PyPI

CVE-2026-54259

CVE-2026-54259

MEDIUM 5.9
PyPI

CVE-2022-42966

cleo is vulnerable to Regular Expression Denial of Service (ReDoS)

MEDIUM 6.6
PyPI

CVE-2025-51481

CVE-2025-51481

MEDIUM 5.3
PyPI

CVE-2023-24622

CVE-2023-24622

MEDIUM 6.5
PyPI

CVE-2026-22218

CVE-2026-22218

MEDIUM 5.3
PyPI

CVE-2026-48990

joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization

MEDIUM 4.8
PyPI

CVE-2026-12491

vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

MEDIUM 6.5
PyPI

CVE-2026-54233

vLLM: OOM Denial of Service via Audio Decompression Bomb

MEDIUM 6.8
PyPI

CVE-2026-48545

Gradio contains a cookie injection vulnerability

MEDIUM 5.3
PyPI

CVE-2026-42526

Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends

MEDIUM 6.5
PyPI

CVE-2026-56262

CVE-2026-56262

MEDIUM 4.4
PyPI

CVE-2025-11000

Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read)

MEDIUM 5.5
PyPI

CVE-2025-10998

Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines

MEDIUM 5.5
PyPI

CVE-2025-10999

Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt

MEDIUM 5.3
PyPI

GHSA-95gx-jmhp-5p29

Duplicate Advisory: Open Babel has heap buffer overflow in ChemKin ChemKinFormat::CheckSpecies

MEDIUM 5.3
PyPI

GHSA-8qw9-gf7w-42x5

Minor fix to previous patch for CVE-2022-35918

MEDIUM 5.3
PyPI

GHSA-9p6c-jcw8-x98f

Duplicate Advisory: Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles

MEDIUM 5.3
PyPI

GHSA-5gfq-xrq4-34rj

Duplicate Advisory: Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow

MEDIUM 4.3
PyPI

GHSA-fg6r-xgp8-x64r

Duplicate Advisory: Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence

MEDIUM 5.5
PyPI

CVE-2026-2705

Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge

MEDIUM 4.4
PyPI

CVE-2026-2704

Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString

MEDIUM 5.5
PyPI

CVE-2026-3408

Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence

MEDIUM 4.3
PyPI

GHSA-2m54-8m6g-qf93

Duplicate Advisory: Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString

MEDIUM 4.3
PyPI

GHSA-3f56-w4g2-mx64

Duplicate Advisory: Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge

MEDIUM 5.3
PyPI

GHSA-5fgf-q57f-wwqf

Duplicate Advisory: Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule

MEDIUM 5.3
PyPI

CVE-2026-9540

vllm has Improper Resource Shutdown or Release

MEDIUM 5.3
PyPI

CVE-2026-9369

hermes-agent has an Incorrect Comparison

MEDIUM 5.3
PyPI

CVE-2026-46745

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability

MEDIUM 6.1
PyPI

CVE-2011-0697

Cross-site scripting in django

MEDIUM 6.5
PyPI

CVE-2010-4534

Improper query string handling in Django

MEDIUM 6.5
PyPI

CVE-2021-39432

CVE-2021-39432

MEDIUM 6.1
PyPI

CVE-2026-48520

Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read

MEDIUM 6.1
PyPI

CVE-2026-44889

WebOb: Location header normalization during redirect leads to open redirect - again

MEDIUM 5.3
PyPI

CVE-2026-54282

CVE-2026-54282

MEDIUM 6.1
PyPI

GHSA-75mw-h36v-2jv7

Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers

MEDIUM 5.2
PyPI

GHSA-9j7f-3r4p-pwh6

nono-py vulnerable to authorization bypass / policy confusion

MEDIUM 6.4
PyPI

GHSA-72w7-mf9g-733p

nono-py has proxy-only network fallback bypass on older Linux kernels

MEDIUM 5.2
PyPI

GHSA-m8j6-rc5x-wv36

nono-py's policy JSON accepts unknown security fields

MEDIUM 6.8
PyPI

CVE-2026-48782

pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)

MEDIUM 5.1
PyPI

GHSA-gr75-jv2w-4656

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

MEDIUM 6.1
PyPI

CVE-2026-55423

Langflow: Logout button does not clear session

MEDIUM 6.3
PyPI

CVE-2026-55163

Lemur Privilege Escalation: Non-admin role members can rewrite role membership via PUT /api/1/roles/<id>

MEDIUM 4.8
PyPI

CVE-2026-55165

Lemur: JWT verifier honors attacker-supplied alg, enabling ATO

MEDIUM 4.9
PyPI

CVE-2026-55164

Lemur user-update path stores plaintext passwords

MEDIUM 6.3
PyPI

CVE-2026-55162

Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF

Ready to move

Start Securing

Free, no credit card | First findings in minutes