Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-67334
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
CVE-2026-53607
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
GHSA-pc2w-4mq8-32qw
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
GHSA-464c-974j-9xm6
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
CVE-2026-12590
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
GHSA-hp3v-mfqw-h74c
@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
CVE-2022-24719
Forwarding of confidentials headers to third parties in fluture-node
CVE-2026-54327
Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
CVE-2026-46549
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
CVE-2026-54326
Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
CVE-2026-11330
claude-mem: The computeObservationContentHash Function is Vulnerable to Hash Collision
CVE-2026-56349
n8n has a Guardrail Node Bypass
CVE-2026-56764
Hono added timing comparison hardening in basicAuth and bearerAuth
CVE-2026-49356
@babel/core: Arbitrary File Read via sourceMappingURL Comment
CVE-2026-54335
Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__
CVE-2026-49456
Waku has an Open Redirect via `unstable_redirect` Helper
CVE-2026-41361
OpenClaw SSRF guard misses four IPv6 special-use ranges
CVE-2026-53835
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
CVE-2026-2391
qs's arrayLimit bypass in comma parsing allows denial of service
CVE-2021-21320
User content sandbox can be confused into opening arbitrary documents
CVE-2020-15262
Unprotected dynamically loaded chunks
CVE-2021-43862
jquery.terminal self XSS on user input
CVE-2021-32696
Passing in a non-string 'html' argument can lead to unsanitized output
CVE-2021-43838
Regular Expression Denial of Service (ReDoS) in jsx-slack
CVE-2019-16772
Cross-Site Scripting in serialize-to-js
CVE-2020-15168
The `size` option isn't honored after following a redirect in node-fetch
CVE-2020-4051
Cross-site Scripting in dijit editor's LinkDialog plugin
CVE-2026-53809
OpenClaw: Embedded runner policy could be confused by provider aliases
CVE-2026-6733
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
CVE-2026-11525
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
GHSA-9wxg-vf3r-56hc
OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source
CVE-2026-53663
React Router: Potential CSRF via PUT/PATCH/DELETE document requests
CVE-2024-9506
ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function
GHSA-g7r4-m6w7-qqqr
esbuild allows arbitrary file read when running the development server on Windows
CVE-2026-44489
Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
CVE-2026-48051
Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
CVE-2026-3449
@tootallnate/once vulnerable to Incorrect Control Flow Scoping
CVE-2026-44589
nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)
CVE-2026-44582
Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
CVE-2026-44459
Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
CVE-2026-44572
Next.js's Middleware / Proxy redirects can be cache-poisoned
CVE-2026-8026
Flowise: Bcrypt Password Hash Exposure
GHSA-6477-wvjj-47v6
Duplicate Advisory: OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders
CVE-2026-41333
OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting
GHSA-r27j-894h-3w3p
mcp-data-vis vulnerable to denial of service via unsanitized `select` key lookup on `Object.prototype` with `precompile: true`
CVE-2026-42040
Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
CVE-2026-41407
OpenClaw: Shared-secret comparison call sites leaked length information through timing
CVE-2026-41913
OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths
GHSA-w9f5-8q83-qwpx
Duplicate Advisory: OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting
GHSA-qmq6-f8pr-cx5x
Duplicate Advisory: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
CVE-2026-41321
Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4)
CVE-2020-15228
Environment Variable Injection in GitHub Actions
CVE-2020-4066
Command Injection in Limdu
CVE-2026-33877
ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
CVE-2026-39321
Parse Server has a login timing side-channel reveals user existence
CVE-2026-35648
OpenClaw may have stale policy enforcement for queued node actions
CVE-2026-6216
DbGate has cross site scripting via the SVG Icon String Handler component
CVE-2026-34166
LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter
CVE-2026-34781
Electron: Crash in clipboard.readImage() on malformed clipboard image data
CVE-2026-32970
OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode
Ready to move
Start Securing
Free, no credit card | First findings in minutes