Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-47144
Shamefile has an arbitrary file read via shamefile.yaml in shame next
CVE-2026-25528
LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
CVE-2024-35255
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
CVE-2024-6863
H2O Vulnerable to Execution of Arbitrary Files
CVE-2022-44244
Lin CMS vulnerable to Improper Authentication
CVE-2026-42999
OpenStack Keystone has an Authorization Bypass
CVE-2026-42998
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
CVE-2026-44394
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
CVE-2026-43000
OpenStack Keystone has an Incorrect Authorization issue
CVE-2026-54262
CVE-2026-54262
CVE-2026-54261
CVE-2026-54261
CVE-2026-54259
CVE-2026-54259
CVE-2022-42966
cleo is vulnerable to Regular Expression Denial of Service (ReDoS)
CVE-2025-51481
CVE-2025-51481
CVE-2023-24622
CVE-2023-24622
CVE-2026-22218
CVE-2026-22218
CVE-2026-48990
joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
CVE-2026-12491
vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
CVE-2026-54233
vLLM: OOM Denial of Service via Audio Decompression Bomb
CVE-2026-48545
Gradio contains a cookie injection vulnerability
CVE-2026-42526
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
CVE-2026-56262
CVE-2026-56262
CVE-2025-11000
Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read)
CVE-2025-10998
Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines
CVE-2025-10999
Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt
GHSA-95gx-jmhp-5p29
Duplicate Advisory: Open Babel has heap buffer overflow in ChemKin ChemKinFormat::CheckSpecies
GHSA-8qw9-gf7w-42x5
Minor fix to previous patch for CVE-2022-35918
GHSA-9p6c-jcw8-x98f
Duplicate Advisory: Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles
GHSA-5gfq-xrq4-34rj
Duplicate Advisory: Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow
GHSA-fg6r-xgp8-x64r
Duplicate Advisory: Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence
CVE-2026-2705
Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge
CVE-2026-2704
Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString
CVE-2026-3408
Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence
GHSA-2m54-8m6g-qf93
Duplicate Advisory: Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString
GHSA-3f56-w4g2-mx64
Duplicate Advisory: Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge
GHSA-5fgf-q57f-wwqf
Duplicate Advisory: Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule
CVE-2026-9540
vllm has Improper Resource Shutdown or Release
CVE-2026-9369
hermes-agent has an Incorrect Comparison
CVE-2026-46745
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
CVE-2011-0697
Cross-site scripting in django
CVE-2010-4534
Improper query string handling in Django
CVE-2021-39432
CVE-2021-39432
CVE-2026-48520
Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
CVE-2026-44889
WebOb: Location header normalization during redirect leads to open redirect - again
CVE-2026-54282
CVE-2026-54282
GHSA-75mw-h36v-2jv7
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
GHSA-9j7f-3r4p-pwh6
nono-py vulnerable to authorization bypass / policy confusion
GHSA-72w7-mf9g-733p
nono-py has proxy-only network fallback bypass on older Linux kernels
GHSA-m8j6-rc5x-wv36
nono-py's policy JSON accepts unknown security fields
CVE-2026-48782
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
GHSA-gr75-jv2w-4656
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
CVE-2026-55423
Langflow: Logout button does not clear session
CVE-2026-55163
Lemur Privilege Escalation: Non-admin role members can rewrite role membership via PUT /api/1/roles/<id>
CVE-2026-55165
Lemur: JWT verifier honors attacker-supplied alg, enabling ATO
CVE-2026-55164
Lemur user-update path stores plaintext passwords
CVE-2026-55162
Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF
Ready to move
Start Securing
Free, no credit card | First findings in minutes