Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

UNKNOWN
crates.io

CVE-2025-31477

Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`

HIGH 8.4
crates.io

CVE-2023-46115

Tauri's Updater Private Keys Possibly Leaked via Vite Environment Variables

HIGH 8.8
crates.io KEV

CVE-2023-4863

libwebp: OOB write in BuildHuffmanTable

MEDIUM 5.9
crates.io

CVE-2023-48795

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

MEDIUM 6.5
crates.io

CVE-2020-36846

Integer overflow in the bundled Brotli C library

HIGH 7.4
crates.io

CVE-2026-75912

CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval

HIGH 8.6
crates.io

CVE-2026-75856

CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning

HIGH 7.8
crates.io

CVE-2026-75911

CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository

HIGH 7.5
crates.io

CVE-2026-75859

CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository

HIGH 7.8
crates.io

CVE-2026-75858

CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)

HIGH 7.5
crates.io

CVE-2026-75915

CodeWhale: js_execution leaks parent environment to model context via missing env scrub

CRITICAL 9.3
crates.io

CVE-2026-75913

CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval

HIGH 7.0
crates.io

CVE-2026-75857

CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)

HIGH 7.5
crates.io

CVE-2026-75914

CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes

LOW 3.3
crates.io

CVE-2025-61670

Wasmtime: Memory leak in C API with `externref` and `anyref` types

UNKNOWN
crates.io

CVE-2026-47425

rattler has an entry-point path traversal in noarch:python install (arbitrary file write)

MEDIUM 5.4
crates.io

CVE-2026-53956

Rattler vulnerable to package cache path traversal via conda package build string

HIGH 7.2
crates.io

CVE-2021-32629

Memory access due to code generation flaw in Cranelift module

MEDIUM 6.3
crates.io

CVE-2021-39216

Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime

UNKNOWN
crates.io

CVE-2024-29640

aliyundrive-webdav vulnerable to Command Injection

HIGH 7.5
crates.io

CVE-2026-42559

dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport

UNKNOWN
crates.io

CVE-2026-22696

dcap-qvl has Missing Verification for QE Identity

HIGH 7.4
crates.io

CVE-2026-45310

DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool

CRITICAL 9.6
crates.io

CVE-2026-45311

DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository Without Approval

MEDIUM 4.3
crates.io

GHSA-88q9-cmp2-c2vq

oxidize-pdf: NaN/inf bypass in colour content-stream emission causes PDF rejection (DoS)

CRITICAL 9.8
crates.io

CVE-2022-31053

Signature forgery in Biscuit

MEDIUM 5.3
crates.io

GO-2024-3101

CWA-2023-004: Excessive number of function parameters in compiled Wasm

UNKNOWN
crates.io

GO-2025-3449

wasmvm: Malicious smart contract can slow down block production

HIGH 7.5
crates.io

CVE-2024-43414

Apollo Query Planner and Apollo Gateway may infinitely loop on sufficiently complex queries

CRITICAL 9.8
crates.io

CVE-2018-20998

Potential memory corruption in arrayfire

MEDIUM 4.3
crates.io

RUSTSEC-2024-0361

Gas mispricing in cosmwasm-vm

Ready to move

Start Securing

Free, no credit card | First findings in minutes