Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-33060
SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks
CVE-2026-53509
@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060)
CVE-2026-61612
@aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509
CVE-2026-63628
mppx: Gas Draining with access list
CVE-2026-76909
Unleash: CR-approval email renders user-controlled raw HTML
CVE-2026-77426
Unleash: Missing await on permission check + cross-project IDOR in admin API
CVE-2026-77425
Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log
CVE-2026-63627
mppx: Gas Draining with padding
CVE-2026-75510
Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme
CVE-2026-76910
Unleash: Clone-feature lets a user copy a feature from a project they cannot read
CVE-2026-63116
deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes
CVE-2026-62985
request-filtering-agent: Synchronous throw from createConnection() for literal private-IP hosts bypasses req.on('error'), crashing the Node.js process
CVE-2026-56682
9Router has a Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header
CVE-2026-56681
9Router has an Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header
CVE-2026-58270
Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`
CVE-2026-61647
@roomi-fields/notebooklm-mcp has a path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory
CVE-2026-58272
Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)
CVE-2026-58269
Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`
CVE-2026-58271
@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`
CVE-2026-12866
expr-eval vulnerable to Code Execution
CVE-2025-61686
React Router has Path Traversal in File Session Storage
CVE-2026-56326
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
CVE-2026-91127
File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
CVE-2026-77301
adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
CVE-2026-84992
md-editor-v3: XSS via fenced-code language rendering bypass
CVE-2026-71869
Orval: Import-time RCE via array-items default -> zod module-level template literal
CVE-2026-71868
Orval: Import-time RCE via enum-typed default -> zod module-level template literal
CVE-2026-62681
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)
CVE-2026-62682
Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)
CVE-2026-71864
Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client
CVE-2026-72717
Orval: Import-time RCE via schema default -> zod module-level template literal
CVE-2026-71865
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli
CVE-2026-92963
vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL`
CVE-2026-92961
vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass
CVE-2026-92962
vm2 setup-sandbox.js violates Defense Invariant #11 in stack-trace formatter
CVE-2026-92960
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
CVE-2026-88976
@platejs/core HTML deserialization can trigger browser behavior during parsing
CVE-2026-81176
Svelte devalue: DoS via malformed input
CVE-2026-76969
@sap/cds-mtx: Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)
CVE-2026-86039
libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses
CVE-2026-86038
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
CVE-2026-54546
TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard
CVE-2026-85715
ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion
CVE-2026-63506
Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
CVE-2026-63225
Redocly CLI: Path traversal when using `split` command
CVE-2026-63472
Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification
CVE-2026-63459
Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions
CVE-2026-61793
Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter
CVE-2026-63461
Vendure: Shop API list queries can return non-public entities when filterOperator is OR
CVE-2026-71538
@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows
CVE-2026-77360
oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass
CVE-2026-63460
Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends
CVE-2026-92596
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
CVE-2026-92597
Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
CVE-2026-92595
Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
CVE-2026-92598
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
CVE-2026-68921
DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
CVE-2026-58201
Lokka: Azure Resource Manager URL path validation issue
CVE-2026-63671
@nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration
CVE-2026-59879
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
Ready to move
Start Securing
Free, no credit card | First findings in minutes