Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-12866
expr-eval vulnerable to Code Execution
CVE-2025-61686
React Router has Path Traversal in File Session Storage
CVE-2026-92960
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
CVE-2026-76969
@sap/cds-mtx: Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)
CVE-2026-63472
Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification
CVE-2026-61560
@zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover
CVE-2026-61559
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
CVE-2026-61568
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
GHSA-5w6g-rc45-wvv9
Duplicate Advisory: Flowise OverrideConfig security vulnerability
CVE-2026-12537
Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
CVE-2026-61534
yayson: Prototype pollution in Store/LegacyStore deserialization
CVE-2026-73653
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
GHSA-jpvj-wpmj-h7rv
Supply chain compromise via malicious @cap-js/openapi
CVE-2026-47428
Vitest browser mode serves unsanitized otelCarrier query parameter as inline script
CVE-2026-45618
LiquidJS is Vulnerable to Remote Code Execution
CVE-2026-45321
Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
CVE-2026-43898
SandboxJS has a sandbox escape via Function.caller leakage of internal call op
CVE-2026-25244
WebdriverIO BrowserStack Service has a Command Injection issue
CVE-2026-45772
Turbo: Unexpected local code execution during Yarn Berry detection
CVE-2026-6951
simple-git is vulnerable to Remote Code Execution
CVE-2026-49252
deepstream is vulnerable to prototype pollution
CVE-2026-48150
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
CVE-2026-47429
When Vitest UI server is listening, arbitrary file can be read and executed
CVE-2026-46412
Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm
GHSA-27f5-xjrr-q9ff
Malware in @opensearch-project/opensearch
CVE-2026-41242
Arbitrary code execution in protobufjs
CVE-2026-33808
@fastify/express has a middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)
CVE-2026-29063
Immutable is vulnerable to Prototype Pollution
CVE-2026-31938
jsPDF has HTML Injection in New Window paths
CVE-2026-28292
simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE
CVE-2026-33937
Handlebars.js has JavaScript Injection via AST Type Confusion
CVE-2026-25896
fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
CVE-2026-27597
@enclave-vm/core is vulnerable to Sandbox Escape
CVE-2026-27699
Basic FTP has Path Traversal Vulnerability in its downloadToDir() method
GHSA-9qr9-h5gf-34mp
Next.js is vulnerable to RCE in React flight protocol
CVE-2025-59834
Command Injection in adb-mcp MCP Server
CVE-2025-59046
interactive-git-checkout has a Command Injection vulnerability
CVE-2025-9287
cipher-base is missing type checks, leading to hash rewind and passing on crafted data
CVE-2025-9288
sha.js is missing type checks leading to hash rewind and passing on crafted data
CVE-2025-29927
Authorization Bypass in Next.js Middleware
CVE-2025-1302
JSONPath Plus allows Remote Code Execution
CVE-2024-21534
JSONPath Plus Remote Code Execution (RCE) Vulnerability
CVE-2024-47875
DOMpurify has a nesting-based mXSS
CVE-2024-38999
jrburke requirejs vulnerable to prototype pollution
CVE-2024-39309
ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability
CVE-2024-38993
jsonic was discovered to contain a prototype pollution via the function empty.
CVE-2024-38996
Prototype pollution in ag-grid-community via the _.mergeDeep function
CVE-2024-4146
lunary-ai/lunary allows users unauthorized access to projects
CVE-2024-34706
@valtimo/components exposes access token to form.io
CVE-2024-32962
xml-crypto vulnerable to XML signature verification bypass due improper verification of signature/signature spoofing
CVE-2024-30564
@andrei-tatar/nora-firebase-common Prototype Pollution vulnerability
CVE-2026-53486
Decompress: Archive extraction can create files and links outside of the target directory
CVE-2024-21508
mysql2 Remote Code Execution (RCE) via the readCodeFor function
CVE-2024-21511
MySQL2 for Node Arbitrary Code Injection
CVE-2024-27307
JSONata expression can pollute the "Object" prototype
CVE-2024-29027
Server crashes on invalid Cloud Function or Cloud Job name
CVE-2024-27298
ZDI-CAN-19105: Parse Server literalizeRegexPart SQL Injection
CVE-2023-32314
vm2 Sandbox Escape vulnerability
CVE-2023-26114
code-server vulnerable to Missing Origin Validation in WebSockets
CVE-2024-22206
@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)
Ready to move
Start Securing
Free, no credit card | First findings in minutes