Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-40575
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
CVE-2026-84200
Bypassing Kyverno Policies via Double Policy Exceptions
CVE-2026-61741
http4s-scala-xml has an XML External Entity (XXE) processing issue
CVE-2026-84939
Apache FreeMarker template loading mechanism vulnerable to path traversal
CVE-2026-56120
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
CVE-2026-85724
Moquette: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bug
CVE-2026-56315
PickleScan has multiple stdlib modules with direct RCE not in blocklist
GHSA-g7vj-qw6x-g3p8
Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist
CVE-2026-77602
OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites)
CVE-2026-57149
plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection
CVE-2026-77244
[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token
CVE-2026-85734
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
CVE-2026-12866
expr-eval vulnerable to Code Execution
CVE-2026-12249
Canonical ADSys Uses a Less Trusted Source
CVE-2026-53713
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure
CVE-2026-88044
rclone: RC per-server auth-proxy bypass
CVE-2025-61686
React Router has Path Traversal in File Session Storage
CVE-2026-59163
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
CVE-2026-8763
Bouncy Castle: Name Constraints bypass via trailing dot in rfc822Name and URI
CVE-2026-61682
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
CVE-2025-66455
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
CVE-2025-53837
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue
CVE-2026-92960
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
CVE-2026-76969
@sap/cds-mtx: Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)
CVE-2026-88018
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
CVE-2026-71485
Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends
CVE-2026-75513
Marten's LINQ provider has SQL injection via unescaped string literals
CVE-2026-63472
Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification
CVE-2026-61594
djust has an authorization bypass on the WebSocket/SSE mount path
CVE-2025-59953
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
CVE-2026-61560
@zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover
CVE-2026-61559
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
CVE-2026-61568
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
CVE-2026-39830
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
GHSA-24r3-p3x6-cqvx
Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
CVE-2026-56260
Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server
CVE-2026-59178
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
GHSA-5w6g-rc45-wvv9
Duplicate Advisory: Flowise OverrideConfig security vulnerability
CVE-2026-12537
Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
CVE-2026-61534
yayson: Prototype pollution in Store/LegacyStore deserialization
CVE-2026-59151
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
CVE-2026-59971
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
CVE-2026-74881
CVE-2026-74881
CVE-2026-65905
Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability
CVE-2025-66614
Apache Tomcat - Client certificate verification bypass
CVE-2026-65182
Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability
CVE-2026-68525
Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability
CVE-2026-43512
Apache Tomcat - Digest authenticator will authenticate any unknown user
CVE-2026-43515
Apache Tomcat - Security constraints not correctly applied
CVE-2022-0845
Code Injection in PyTorch Lightning
CVE-2026-44484
Compromise of PyTorch Lightning PyPi Package Versions
CVE-2024-5980
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
CVE-2024-5452
Remote code execution in pytorch lightning
Ready to move
Start Securing
Free, no credit card | First findings in minutes