Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-63116
deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes
CVE-2026-62985
request-filtering-agent: Synchronous throw from createConnection() for literal private-IP hosts bypasses req.on('error'), crashing the Node.js process
CVE-2026-56681
9Router has an Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header
CVE-2026-58269
Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`
CVE-2026-91127
File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
CVE-2026-77301
adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
CVE-2026-92961
vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass
CVE-2026-86039
libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses
CVE-2026-86038
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
CVE-2026-85715
ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion
CVE-2026-63506
Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
CVE-2026-63459
Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions
CVE-2026-63460
Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends
CVE-2026-92596
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
CVE-2026-63671
@nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration
CVE-2026-59879
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
CVE-2026-59965
@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission
CVE-2026-68904
node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustion
CVE-2026-58200
@jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Signing
CVE-2026-58485
SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`
CVE-2026-58483
SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`
GHSA-5648-rgj9-v224
@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
CVE-2021-21278
Risk of code injection
CVE-2026-59973
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
CVE-2026-59148
@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
CVE-2026-13676
fast-uri vulnerable to host confusion via failed IDN canonicalization
CVE-2026-59960
@argos-ci/core: CI Branch Name OS Command Injection
GHSA-x7m8-jrm8-hpvx
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
CVE-2026-73088
Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
CVE-2026-75975
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
CVE-2026-75931
fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
CVE-2026-69152
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
GHSA-h3hj-cmcx-xc66
Duplicate Advisory: Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
GHSA-6hqm-hm2v-3p2p
Duplicate Advisory: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
GHSA-68jp-44vc-2x5h
Duplicate Advisory: Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
CVE-2026-13697
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
GHSA-39j5-w47m-2gmv
Duplicate Advisory: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
CVE-2026-39244
adm-zip: Crafted ZIP file triggers 4GB memory allocation
CVE-2026-73418
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
CVE-2026-50272
dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-59887
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
CVE-2026-16221
fast-uri vulnerable to host confusion via literal backslash authority delimiter
CVE-2026-59725
Socket.IO: Engine.IO Polling Transport Connection Exhaustion
CVE-2026-73566
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
CVE-2026-73643
js-yaml: Exponential parsing time in flow collections leads to denial of service
CVE-2026-59874
node-tar: Negative tar entry size causes infinite loop in archive replace
CVE-2026-50143
Apify Model Context Protocol (MCP) server: Actor MCP path authority injection leaks Apify token
CVE-2026-45623
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
CVE-2026-47759
TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes
CVE-2026-13311
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
CVE-2026-73650
SVGO removeScripts plugin leaves some executable scripts intact
CVE-2026-59873
node-tar: Decompression/parse DoS via unlimited input
CVE-2026-48712
protobufjs: Denial of service through unbounded Any expansion during JSON conversion
CVE-2026-9697
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
CVE-2026-47760
TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs
CVE-2026-82659
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
CVE-2026-56876
extract-zip unvalidated symlink path traversal
CVE-2026-49229
@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens
CVE-2026-46509
@ranfdev/deepobj has a Prototype Pollution vulnerability
CVE-2026-9496
pacote is vulnerable to Denial of Service (DoS) via the addGitSha function
Ready to move
Start Securing
Free, no credit card | First findings in minutes