Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
GHSA-g7r4-m6w7-qqqr
esbuild allows arbitrary file read when running the development server on Windows
CVE-2026-44489
Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
CVE-2026-48051
Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
CVE-2026-46549
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
CVE-2026-3449
@tootallnate/once vulnerable to Incorrect Control Flow Scoping
CVE-2026-44589
nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)
CVE-2026-44582
Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
CVE-2026-44459
Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
CVE-2026-44572
Next.js's Middleware / Proxy redirects can be cache-poisoned
CVE-2026-8026
Flowise: Bcrypt Password Hash Exposure
GHSA-6477-wvjj-47v6
Duplicate Advisory: OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders
CVE-2026-41333
OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting
GHSA-r27j-894h-3w3p
mcp-data-vis vulnerable to denial of service via unsanitized `select` key lookup on `Object.prototype` with `precompile: true`
CVE-2026-42040
Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
CVE-2026-41407
OpenClaw: Shared-secret comparison call sites leaked length information through timing
CVE-2026-41913
OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths
GHSA-w9f5-8q83-qwpx
Duplicate Advisory: OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting
GHSA-qmq6-f8pr-cx5x
Duplicate Advisory: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
CVE-2026-41321
Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4)
CVE-2020-15228
Environment Variable Injection in GitHub Actions
CVE-2020-4066
Command Injection in Limdu
CVE-2026-33877
ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
CVE-2026-39321
Parse Server has a login timing side-channel reveals user existence
CVE-2026-35648
OpenClaw may have stale policy enforcement for queued node actions
CVE-2026-6216
DbGate has cross site scripting via the SVG Icon String Handler component
CVE-2026-34166
LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter
CVE-2026-34781
Electron: Crash in clipboard.readImage() on malformed clipboard image data
CVE-2026-32970
OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode
GHSA-vm29-7mq3-9jrg
Duplicate Advisory: OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode
CVE-2026-34764
Electron: Use-after-free in offscreen shared texture release() callback
CVE-2026-34768
Electron: Unquoted executable path in app.setLoginItemSettings on Windows
CVE-2026-34766
Electron: USB device selection not validated against filtered device list
CVE-2026-2366
Keycloak vulnerable to authorization bypass via the Admin API
GHSA-g86v-f9qv-rh6m
OpenClaw SSRF guard misses four IPv6 special-use ranges
GHSA-442j-39wm-28r2
Handlebars.js has a Property Access Validation Bypass in container.lookup
CVE-2026-32067
OpenClaw has cross-account DM pairing authorization bypass via unscoped pairing store access
CVE-2026-32058
OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows
CVE-2026-33490
h3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes
GHSA-cjq8-m7wj-xmq9
Duplicate Advisory: OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows
GHSA-86jj-29wc-7q2w
Duplicate Advisory: OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checks
GHSA-8mr2-f9wf-hcfq
Duplicate Advisory: OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback
CVE-2026-31991
OpenClaw has Signal group allowlist authorization bypass via DM pairing-store leakage
CVE-2026-32028
OpenClaw: Discord DM reaction ingress missed dmPolicy/allowFrom checks in restricted setups
GHSA-r849-826x-wgqm
Duplicate Advisory: Signal group allowlist authorization bypass via DM pairing-store leakage
CVE-2026-32020
OpenClaw's Control UI Static File Handler Follows Symlinks and Allows Out-of-Root File Read
CVE-2026-31996
OpenClaw safeBins stdin-only bypass via sort output and recursive grep flags
GHSA-ggm6-h3mx-cmmp
Duplicate Advisory: safeBins stdin-only bypass via sort output and recursive grep flags
GHSA-xjj9-2w6f-jg55
Duplicate Advisory: OpenClaw safeBins file-existence oracle information disclosure
CVE-2026-32638
StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens
CVE-2026-2391
qs's arrayLimit bypass in comma parsing allows denial of service
CVE-2020-4051
Cross-site Scripting in dijit editor's LinkDialog plugin
CVE-2021-32696
Passing in a non-string 'html' argument can lead to unsanitized output
CVE-2021-21320
User content sandbox can be confused into opening arbitrary documents
CVE-2019-16772
Cross-Site Scripting in serialize-to-js
CVE-2021-43862
jquery.terminal self XSS on user input
CVE-2021-43838
Regular Expression Denial of Service (ReDoS) in jsx-slack
CVE-2020-15262
Unprotected dynamically loaded chunks
CVE-2020-15168
The `size` option isn't honored after following a redirect in node-fetch
CVE-2026-29184
@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass
CVE-2026-29185
Backstage vulnerable to potential reading of SCM URLs using built in token
Ready to move
Start Securing
Free, no credit card | First findings in minutes