Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-70597
Electron: Parent process code-sign check is spoofable
CVE-2026-69207
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
CVE-2026-53949
Ghost Content API filter bypass reveals private fields
CVE-2026-70595
Ghost: Server-Side Request Forgery Mitigation Issue
CVE-2026-70596
Ghost: Cross-Site Scripting in Feature Image Captions
CVE-2026-53950
XSS in Ghost's ActivityPub client
GHSA-gj2h-2fpw-fhv9
@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration
CVE-2026-59817
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
CVE-2026-53947
Ghost: Member existence leak via magic link sign-in response
CVE-2026-70594
Ghost: Session Fixation in Ghost Admin
CVE-2026-70593
Ghost: Theme Upload Path Traversal
CVE-2026-70592
Ghost: Database Backup Path Traversal
CVE-2026-70590
Ghost: Blind Password Hash Disclosure in Ghost Admin API
CVE-2026-70591
Ghost: Server-Side Request Forgery in Image Fetching
CVE-2026-53944
Ghost: Private IP filtering bypass to make server-side requests to internal services
CVE-2026-53946
Ghost: Mobiledoc image-size fetch SSRF
CVE-2026-53945
Ghost: Server-side request forgery via DNS rebinding in external request handling
CVE-2026-40181
React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation
CVE-2026-69198
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
CVE-2026-69152
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
GHSA-2p49-hgcm-8545
SVGO removeScripts plugin leaves some executable scripts intact
CVE-2026-18446
fast-uri vulnerable to host confusion via backslash authority introducer
CVE-2026-13697
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
CVE-2026-69153
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
CVE-2026-16729
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
CVE-2026-54272
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
CVE-2026-16728
undici vulnerable to downstream response desynchronization via retry interceptor
CVE-2026-15157
undici vulnerable to CRLF Injection via blob-like body 'type' property
CVE-2026-69192
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
CVE-2026-14643
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
CVE-2026-70588
Ghost: Cross-Site Scripting in Universal Import
CVE-2026-53948
Ghost: File Upload Content-Type Spoofing
CVE-2026-70589
Ghost: Archived Offers can be Redeemed
CVE-2026-54658
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
CVE-2026-70478
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
CVE-2026-70477
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
GHSA-8gj2-2cvc-6xx7
Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
CVE-2026-70475
Flowise: Missing Authorization on Execution Update Endpoint
CVE-2026-70476
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
CVE-2026-70474
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
CVE-2026-69256
Flowise: Remote Code Execution Vulnerability in CSVAgent
CVE-2026-70471
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
GHSA-88pr-878c-24wf
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
GHSA-rwrp-9823-p2xq
Flowise: Incomplete Credential Redaction Exposes Secrets via API
CVE-2026-70472
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
CVE-2026-70473
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
CVE-2026-69264
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
CVE-2026-70470
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
CVE-2026-69263
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
CVE-2026-69262
Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
CVE-2026-69259
Flowise RCE via SQLite Record Manager Node
CVE-2026-69257
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
CVE-2026-69258
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
CVE-2026-69254
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
CVE-2026-69255
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
CVE-2026-69253
Flowise Sandbox Escape to RCE
CVE-2026-69252
Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
CVE-2026-69251
Flowise RCE via TypeORM DataSource
CVE-2026-69250
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
GHSA-2364-jh4q-m9vm
Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
Ready to move
Start Securing
Free, no credit card | First findings in minutes