Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-54658
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
CVE-2026-69240
Sequelize: SQL Injection (Oracle DB)
CVE-2026-53609
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
CVE-2026-52887
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
CVE-2026-11393
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
GHSA-vh45-f885-3848
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
GHSA-q6x4-v3qx-85qw
Budibase: SQL Injection via `multipleStatements: true`
GHSA-w28w-gp39-m4p6
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
CVE-2026-59940
seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
GHSA-7gfh-x38p-prh3
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
GHSA-rjg6-39jm-rgg4
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
GHSA-9qr9-h5gf-34mp
Next.js is vulnerable to RCE in React flight protocol
GHSA-p63j-vcc4-9vmv
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
CVE-2025-71324
Flowise has an Arbitrary File Read
CVE-2026-59891
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
CVE-2026-50137
Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials
CVE-2026-4599
jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce Generation
CVE-2026-57138
npm PraisonAI codeMode sandbox escape via Function constructor
CVE-2026-57141
PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool
CVE-2026-57139
npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call
CVE-2026-57140
npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation
CVE-2026-54316
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
CVE-2026-54157
LobeHub: Unauthenticated SSRF in `/webapi/proxy`
CVE-2026-53512
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
CVE-2026-53513
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
CVE-2026-54305
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
CVE-2026-44791
n8n Has an XML Node Prototype Pollution Patch Bypass
CVE-2026-44789
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
CVE-2026-44792
n8n Has a Source Control Pull SQL Injection
CVE-2026-56348
n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass
CVE-2026-54310
n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
CVE-2026-54309
n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
CVE-2023-46233
crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard
CVE-2026-59801
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
CVE-2026-14722
TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution
CVE-2026-54052
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
CVE-2026-53486
Decompress: Archive extraction can create files and links outside of the target directory
CVE-2026-54307
n8n: Credential Exfiltration via Permission Bypass
CVE-2026-48814
Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests
CVE-2026-33807
@fastify/express's middleware path doubling causes authentication bypass in child plugin scopes
CVE-2026-6270
@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes
CVE-2026-47137
vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE
CVE-2023-37903
vm2 Sandbox Escape vulnerability
CVE-2025-50538
Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
CVE-2025-9287
cipher-base is missing type checks, leading to hash rewind and passing on crafted data
CVE-2026-12537
Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
CVE-2026-32922
OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE
CVE-2025-71338
Flowise allows arbitrary file write to RCE
CVE-2025-9288
sha.js is missing type checks leading to hash rewind and passing on crafted data
CVE-2025-71334
Flowise has arbitrary file access due to missing chat flow id validation
CVE-2023-7080
Arbitrary remote code execution within `wrangler dev` Workers sandbox
CVE-2024-1631
agent-js: Insecure Key Generation in `Ed25519KeyIdentity.generate`
GHSA-r5cq-9537-9rpf
Prototype Pollution in mixme
CVE-2022-25352
Prototype Pollution in libnested
CVE-2020-7674
Improper Input Validation in access-policy
CVE-2022-21190
Prototype Pollution in convict
CVE-2022-24437
OS Command Injection in git-pull-or-clone
CVE-2020-7621
OS Command Injection in strong-nginx-controller
CVE-2020-7706
Prototype Pollution in connie-lang
CVE-2021-23448
Prototype Pollution in config-handler
Ready to move
Start Securing
Free, no credit card | First findings in minutes